BIOC Informational

Suspicious access to /etc/shadow

Attackers may enumerate or modify user accounts by accessing the /etc/shadow file.

Module:
Platform Analytics
Agent event type:
File
Category:
Discovery
Status:
Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Indicator:

File action type = all AND file path = /etc/shadow Process initiated by = python* , initiated by = cat , ruby , perl , cgo name = python* , cgo name = cat , ruby , perl AND initiated by != cron AND crond AND splunkd AND cgo name != cron AND crond AND splunkd

Preventable: yes