The Duality of the Pluggable Authentication Module (PAM)
ID: ad8f2775-3134-539f-b206-8daac091a079
STIX ID: report--ad8f2775-3134-539f-b206-8daac091a079
Feed Name: Group-IB Blog
Threat Score
This report explains how Linux's Pluggable Authentication Module (PAM) framework—specifically the pam_exec module—can be abused to execute malicious scripts during authentication (e.g., SSH), enabling stealthy data exfiltration and persistent privileged access; Group-IB DFIR demonstrates the technique, highlights its forensic stealth, and recommends hardening and monitoring controls such as SELinux/AppArmor, auditd, file integrity tools, and restricted sudo/root access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
