Skip to content

Improved Linux local account discovery detection and false positives#5843

Open
Aadith1422 wants to merge 5 commits intoSigmaHQ:masterfrom
Aadith1422:improve-linux-account-discovery
Open

Improved Linux local account discovery detection and false positives#5843
Aadith1422 wants to merge 5 commits intoSigmaHQ:masterfrom
Aadith1422:improve-linux-account-discovery

Conversation

@Aadith1422
Copy link

What:

  • Improved Linux local system account discovery rule

Why:

  • Enhances detection coverage for common account enumeration techniques
  • Improves false positive documentation for SOC analysts

How:

  • Added detection for getent, awk, and cut usage against /etc/passwd
  • Updated rule status to experimental

Testing:

  • Reviewed logic against Atomic Red Team T1087.001 examples

@github-actions github-actions bot added Rules Review Needed The PR requires review Linux Pull request add/update linux related rules labels Jan 20, 2026
@Aadith1422 Aadith1422 changed the title Improve Linux local account discovery detection and false positives Improved Linux local account discovery detection and false positives Jan 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Linux Pull request add/update linux related rules Review Needed The PR requires review Rules

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants