heroui logo

Excessive Sudo Authentication Failures via macOS Security Events

Elastic Detection Rules

View Source
Summary
Identifies a high volume of sudo password failures on macOS by aggregating sudo-related authentication messages from the macOS Security Events Authentication data stream. The rule parses messages that indicate multiple incorrect password attempts (formatted as "<user> : <n> incorrect password attempts ; TTY=... ; PWD=... ; USER=... ; COMMAND=...") and sums the attempt counts per host within the rule window. An alert is triggered when the total attempts exceed a defined threshold (Esql.attempt_total >= 10). The alert surfaces extracted values such as the invoking user, target user, TTY, and attempted commands (Esql.user_name_values, Esql.target_user_values, Esql.tty_values, Esql.command_values). This detection aligns with MITRE ATT&CK techniques for Privilege Escalation (T1548.003 Sudo and Sudo Caching) and Brute Force / Password Guessing (T1110 / T1110.001). It relies on data from the macOS Security Events integration, specifically the Authentication data stream, and the corresponding process and event details to identify sudo attempts and associated context.
Categories
  • Endpoint
  • macOS
Data Sources
  • Logon Session
  • Process
  • Application Log
ATT&CK Techniques
  • T1548
  • T1548.003
  • T1110
  • T1110.001
Created: 2026-09-17