Analytics Medium

Sudoedit Brute force attempt

An unusual amount of sudoedit commands executed in a short period of time. This may indicate an attempt to exploit CVE-2021-3156.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Exploitation for Privilege Escalation (T1068)
Attacker's goals:

The attacker may gain higher privileges via exploitation of sudoedit.

Investigative actions:

Verify that the current version of sudo in not vulnerable to CVE-2021-3156.

Test period:
1 Hour
Deduplication:
1 Day