1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1548.003 Sudo and Sudo Caching — Detection Rules

Detection workspace for T1548.003 Sudo and Sudo Caching: 1 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

Atlas deterministic concepts

No exact concept selected.

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0052 Behavioral Detection Strategy for Abuse of Sudo and Sudo Caching

AN0142 Analytic 0142

Correlate command executions involving 'sudo' with elevated effective user ID (euid=0), especially when tty_tickets is disabled or timestamp_timeout is actively abused.

AN0143 Analytic 0143

Detect sudo activity with NOPASSWD in /etc/sudoers or disabling tty_tickets, followed by immediate privileged commands (e.g., echo 'Defaults !tty_tickets' >> /etc/sudoers).

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1548.003 simulation workspace

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.