1200KM / simulation
T1548.003 Sudo and Sudo Caching — Attack Simulation
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The sudo command "allows a system…
Technique description
Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform commands from terminals with elevated privileges and to control who can perform these commands on the system. The sudo command "allows a system…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Sudo usage
Procedure 150c3a08-ee6e-48a6-aeaf-3659d24ceb4e; elevation required; cleanup not declared. Not executed or individually validated.
- Sudo usage (freebsd)
Procedure 2bf9a018-4664-438a-b435-cc6f8c6f71b1; elevation required; cleanup not declared. Not executed or individually validated.
- Disable tty_tickets for sudo caching (freebsd)
Procedure 4df6a0fe-2bdd-4be8-8618-a6a19654a57a; elevation required; cleanup not declared. Not executed or individually validated.
- Disable tty_tickets for sudo caching
Procedure 91a60b03-fb75-4d24-a42e-2eb8956e8de1; elevation required; cleanup not declared. Not executed or individually validated.
- Unlimited sudo cache timeout
Procedure a7b17659-dd5e-46f7-b7d1-e6792c91d0bc; elevation required; cleanup not declared. Not executed or individually validated.
- Unlimited sudo cache timeout (freebsd)
Procedure a83ad6e8-6f24-4d7f-8f44-75f8ab742991; elevation required; cleanup not declared. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.