Spacebar Campaigns

HFA-002 Linux auditd Sensitive File Access Log

Source Alias:
AUD-002
발생 위치:
App 서버 host
원본 경로:
/var/log/audit/audit.log
auditd key:
hanguel_sensitive_file
감시 대상:
/etc/passwd, /etc/shadow, /etc/sudoers
주요 event.action:
hanguel_sensitive_file_access
커버 Technique:
T1005, T1003

분석 포인트

KQL

event.action : "hanguel_sensitive_file_access"