// soc investigation 2026-06-18
SOC324 Sudoers File Modification Detected
letsdefend High ✓ true positive
mitre/T1110-001mitre/T1078mitre/T1059-004mitre/T1087-001mitre/T1069-001mitre/T1136-001mitre/T1548-003
analyst verdict TRUE POSITIVE
✓

What

A brute force SSH attack from 149[.]88[.]25[.]133 successfully authenticated as local user analyst on host Kristine (172[.]16[.]17[.]129). Following access, the attacker performed post-exploitation recon, created a backdoor local account (letsdefend1), and modified /etc/sudoers via visudo to grant that account unrestricted ALL:ALL sudo privileges. The backdoor account had not yet been used when the host was contained.

When

Timestamp (UTC)Event
2024-09-20 06:33 AMSSH brute force attempt begins; multiple usernames sprayed
2024-09-20 06:33:48Successful login as analyst from 149[.]88[.]25[.]133:64646
2024-09-20 06:33:48whoami — identity recon
2024-09-20 06:34:24sudo useradd -m letsdefend1 — backdoor account created
2024-09-20 06:34:32sudo passwd letsdefend1 — password set
2024-09-20 06:34:57sudo -l — sudo privilege enumeration
2024-09-20 06:35:12sudo cat /etc/sudoers — sudoers read (alert triggered)
2024-09-20 06:35:26sudo visudo — sudoers modified; ALL:ALL granted to letsdefend1
2024-09-20 06:36:03sudo cat /etc/sudoers — modification confirmed
2024-09-20 06:36:13groups letsdefend1 / getent passwd — account enumeration

Where

Who

Why

The attacker brute-forced SSH credentials, gaining access via the analyst account. They immediately conducted local recon (whoami, sudo -l) to assess privileges, then created a new local user and granted it full passwordless sudo access by editing /etc/sudoers. This establishes persistent root-equivalent access that survives password changes on the analyst account. The attack was interrupted prior to the backdoor account being used.

MITRE ATT&CK

Technique IDTacticTechnique
T1110.001Credential AccessBrute Force: Password Guessing
T1078Defense Evasion / PersistenceValid Accounts
T1059.004ExecutionCommand and Scripting Interpreter: Unix Shell
T1087.001DiscoveryAccount Discovery: Local Account
T1069.001DiscoveryPermission Groups Discovery: Local Groups
T1136.001PersistenceCreate Account: Local Account
T1548.003Privilege EscalationAbuse Elevation Control Mechanism: Sudo and Sudo Caching

IOCs

TypeValueNotes
IP Address149[.]88[.]25[.]133SSH brute force source
Usernameletsdefend1Attacker-created backdoor account
File/etc/sudoersModified to grant ALL:ALL to letsdefend1