| Curl Download and Bash Execution |
Ingress Tool Transfer |
TTP |
| Linux Add Files In Known Crontab Directories |
Cron |
Anomaly |
| Linux Adding Crontab Using List Parameter |
Cron |
Hunting |
| Linux apt-get Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux APT Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux At Allow Config File Creation |
Cron |
Anomaly |
| Linux At Application Execution |
At |
Anomaly |
| Linux Auditd Add User Account Type |
Local Account |
Anomaly |
| Linux Auditd At Application Execution |
At |
Anomaly |
| Linux Auditd Auditd Service Stop |
Service Stop |
Anomaly |
| Linux Auditd Base64 Decode Files |
Deobfuscate/Decode Files or Information |
Anomaly |
| Linux Auditd Change File Owner To Root |
Linux and Mac File and Directory Permissions Modification |
Anomaly |
| Linux Auditd Clipboard Data Copy |
Clipboard Data |
Anomaly |
| Linux Auditd Data Transfer Size Limits Via Split |
Data Transfer Size Limits |
Anomaly |
| Linux Auditd Data Transfer Size Limits Via Split Syscall |
Data Transfer Size Limits |
Anomaly |
| Linux Auditd Database File And Directory Discovery |
File and Directory Discovery |
Anomaly |
| Linux Auditd Disable Or Modify System Firewall |
Disable or Modify System Firewall |
Anomaly |
| Linux Auditd Edit Cron Table Parameter |
Cron |
Anomaly |
| Linux Auditd File And Directory Discovery |
File and Directory Discovery |
Anomaly |
| Linux Auditd File Permission Modification Via Chmod |
Linux and Mac File and Directory Permissions Modification |
Anomaly |
| Linux Auditd File Permissions Modification Via Chattr |
Linux and Mac File and Directory Permissions Modification |
Anomaly |
| Linux Auditd Find Credentials From Password Managers |
Password Managers |
TTP |
| Linux Auditd Find Credentials From Password Stores |
Password Managers |
TTP |
| Linux Auditd Find Ssh Private Keys |
Private Keys |
Anomaly |
| Linux Auditd Hidden Files And Directories Creation |
File and Directory Discovery |
Anomaly |
| Linux Auditd Kernel Module Using Rmmod Utility |
Kernel Modules and Extensions |
TTP |
| Linux Auditd Osquery Service Stop |
Service Stop |
Anomaly |
| Linux Auditd Possible Access Or Modification Of Sshd Config File |
SSH Authorized Keys |
Anomaly |
| Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File |
Cron |
Hunting |
| Linux Auditd Preload Hijack Via Preload File |
Dynamic Linker Hijacking |
TTP |
| Linux Auditd Private Keys and Certificate Enumeration |
Private Keys |
Anomaly |
| Linux Auditd Service Restarted |
Systemd Timers |
Anomaly |
| Linux Auditd Service Started |
Service Execution |
Anomaly |
| Linux Auditd Setuid Using Chmod Utility |
Setuid and Setgid |
Anomaly |
| Linux Auditd Sysmon Service Stop |
Service Stop |
Anomaly |
| Linux Auditd System Network Configuration Discovery |
System Network Configuration Discovery |
Anomaly |
| Linux Auditd Unix Shell Configuration Modification |
Unix Shell Configuration Modification |
TTP |
| Linux Auditd Unload Module Via Modprobe |
Kernel Modules and Extensions |
TTP |
| Linux Auditd Virtual Disk File And Directory Discovery |
File and Directory Discovery |
Anomaly |
| Linux Auditd Whoami User Discovery |
System Owner/User Discovery |
Anomaly |
| Linux AWK Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Busybox Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux c89 Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux c99 Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Change File Owner To Root |
Linux and Mac File and Directory Permissions Modification |
Anomaly |
| Linux Clipboard Data Copy |
Clipboard Data |
Anomaly |
| Linux Common Process For Elevation Control |
Setuid and Setgid |
Hunting |
| Linux Composer Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Cpulimit Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Csvtool Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Curl Upload File |
Ingress Tool Transfer |
TTP |
| Linux Decode Base64 to Shell |
Obfuscated Files or Information, Unix Shell |
TTP |
| Linux Docker Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Edit Cron Table Parameter |
Cron |
Hunting |
| Linux Emacs Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Find Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux GDB Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Gem Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux GNU Awk Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Ingress Tool Transfer Hunting |
Ingress Tool Transfer |
Hunting |
| Linux Ingress Tool Transfer with Curl |
Ingress Tool Transfer |
Anomaly |
| Linux Make Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux MySQL Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Node Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Obfuscated Files or Information Base64 Decode |
Obfuscated Files or Information |
Anomaly |
| Linux Octave Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux OpenVPN Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux PHP Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux pkexec Privilege Escalation |
Exploitation for Privilege Escalation |
TTP |
| Linux Possible Access Or Modification Of sshd Config File |
SSH Authorized Keys |
Anomaly |
| Linux Possible Append Cronjob Entry on Existing Cronjob File |
Cron |
Hunting |
| Linux Possible Cronjob Modification With Editor |
Cron |
Hunting |
| Linux Possible Ssh Key File Creation |
SSH Authorized Keys |
Anomaly |
| Linux Proxy Socks Curl |
Proxy, Non-Application Layer Protocol |
TTP |
| Linux Puppet Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux RPM Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Ruby Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux Service File Created In Systemd Directory |
Systemd Timers |
Anomaly |
| Linux Service Restarted |
Systemd Timers |
Anomaly |
| Linux Service Started Or Enabled |
Systemd Timers |
Anomaly |
| Linux Setuid Using Chmod Utility |
Setuid and Setgid |
Anomaly |
| Linux Sqlite3 Privilege Escalation |
Sudo and Sudo Caching |
Anomaly |
| Linux SSH Authorized Keys Modification |
SSH Authorized Keys |
Anomaly |
| Linux SSH Remote Services Script Execute |
SSH |
TTP |
| Suspicious Curl Network Connection |
Ingress Tool Transfer |
TTP |