Modification of PAM
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
Detector Tags
Kubernetes - AGENT, Containers
ATT&CK Tactic
Persistence (TA0003), Credential Access (TA0006), Defense Impairment (TA0112)
ATT&CK Technique
Modify Authentication Process: Pluggable Authentication Modules (T1556.003)
Severity
Informational
Description
Modification of PAM configuration files.
Attacker's Goals
Credential access, defense evasion or persistence.
Investigative actions
Check whether the executing process is benign and if this was a desired behavior as part of its normal execution flow.
Variations
PreviousModification of NTLM restrictions in the Registry
NextModification of the AD FS IdentityServer configuration file
Was this helpful?
