Techniques › T1212 › AN0494
AN0494 Analytic 0494
Linux · attack.mitre.org · ATT&CK Enterprise v19.2
<p>Detects exploitation of authentication daemons or PAM modules. Defender perspective includes failed or anomalous PAM authentications, abnormal segfaults in authentication services, and exploitation attempts followed by successful unauthorized logins. Correlation identifies memory corruption, replay attempts, and privilege escalation tied to credential services.</p>
- Detects
- T1212 Exploitation for Credential Access
- Part of
- DET0174 Detection Strategy for Exploitation for Credential Access
Log sources and channels
Exactly as MITRE states them in x_mitre_log_source_references. Where a channel is vague, it is vague in the source; kevmap does not tidy it.
| Log source | Channel | Data component |
|---|---|---|
| auditd:SYSCALL | execve: Suspicious binaries or scripts interacting with authentication binaries (sshd, gdm, login) | DC0032 Process Creation |
| NSM:Connections | Repeated failed authentication attempts or replay patterns | DC0002 User Account Authentication |
Mutable elements
Parameters MITRE marks as environment-specific. These are the knobs you are expected to tune; they are why an analytic is not a rule.
| Field | Description |
|---|---|
AuthServiceList | List of monitored authentication services (e.g., sshd, gdm, PAM modules). |
FailureThreshold | Number of failed authentications within a window before escalating to replay suspicion. |
KEV CVEs whose mapped technique this analytic detects
| CVE | Vendor / product | State |
|---|---|---|
| CVE-2022-22948 | VMware vCenter Server | Mapped |
| CVE-2024-53704 | SonicWall SonicOS | Mapped |
| CVE-2025-48927 | TeleMessage TM SGNL | Mapped |
| CVE-2025-48928 | TeleMessage TM SGNL | Mapped |