kevmap

TechniquesT1212 › AN0494

AN0494 Analytic 0494

Linux · attack.mitre.org · ATT&CK Enterprise v19.2

<p>Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.</p>
Detects
T1212 Exploitation for Credential Access
Part of
DET0174 Detection Strategy for Exploitation for Credential Access

Log sources and channels

Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.

Log sourceChannelData component
auditd:SYSCALLexecve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login)DC0032 Process Creation
NSM:ConnectionsRepeated failed authentication attempts or replay patternsDC0002 User Account Authentication

Mutable elements

Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.

FieldDescription
AuthServiceListList of monitored authentication services (e.g., sshd, gdm, PAM modules).
FailureThresholdNumber of failed authentications within a window before escalating to replay suspicion.

KEV CVEs whose mapped technique this analytic detects

CVEVendor / productState
CVE-2022-22948VMware vCenter ServerMapped
CVE-2024-53704SonicWall SonicOSMapped
CVE-2025-48927TeleMessage TM SGNLMapped
CVE-2025-48928TeleMessage TM SGNLMapped