BIOC
Informational
✕
Suspicious access to /etc/shadow
Attackers may enumerate or modify user accounts by accessing the /etc/shadow file.
- Module:
- Platform Analytics
- Agent event type:
- File
- Category:
- Discovery
- Status:
- Enabled
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: Account Discovery (T1087)
Indicator:
File action type = all AND file path = /etc/shadow Process initiated by = python* , initiated by = cat , ruby , perl , cgo name = python* , cgo name = cat , ruby , perl AND initiated by != cron AND crond AND splunkd AND cgo name != cron AND crond AND splunkd
Preventable: yes