Identifies the manual reading of the /etc/shadow file via the commandline using standard system utilities. Threat actors will attempt to read this file, after elevating their privileges to root, in order to gain valid credentials they can utilize to move laterally undetected and access additional resources.
Rule type: eql
Risk score: 47
Runs every: 5m
Maximum alerts per execution: 100
- Threat Detection
- Privilege Escalation
Rule license: Elastic License v2
process where event.type == "start" and event.action == "exec" and user.name == "root" and process.args : "/etc/shadow" and not process.executable: ("/usr/bin/find", "/usr/bin/cmp", "/bin/ls", "/usr/sbin/restorecon", "/usr/bin/uniq") and not process.parent.executable: "/bin/dracut"
Framework: MITRE ATT&CKTM