// MITRE ATT&CK

T1548.003 · Sudo and Sudo Caching

🎯 Privilege Escalation LinuxmacOS Sub-technique

Sub-technique of T1548 · Abuse Elevation Control Mechanism.

Adversaries may perform sudo caching and/or use the sudoers file to elevate privileges. Adversaries may do this to execute commands as other users or spawn processes with higher privileges. Within Linux and MacOS systems, sudo (sometimes referred to as "superuser do") allows users to perform comman...

How to detect & mitigate it

Detecting Sudo and Sudo Caching starts with your SIEM/EDR telemetry. Write a detection rule with the Sigma generator, analyze suspicious logs in the log analyzer, and place the technique on your coverage with the ATT&CK matrix.

Related techniques

Source: MITRE ATT&CK®. ATT&CK is a registered trademark of The MITRE Corporation. Content for educational purposes.