Unusual Linux System Owner or User Discovery Activity


Unusual Linux System Owner or User Discovery Activity


Looks for commands related to system user or owner discovery from an unusual user context. This can be due to uncommon troubleshooting activity or due to a compromised account. A compromised account may be used to engage in system owner or user discovery in order to identify currently active or primary users of a system. This may be a precursor to additional discovery, credential dumping or privilege elevation activity.

Rule type: machine_learning

Rule indices: None

Severity: low

Risk score: 21

Runs every: 15m

Searches indices from: now-45m (Date Math format, see also Additional look-back time)

Maximum alerts per execution: 100

References: None


  • Elastic
  • Host
  • Linux
  • Threat Detection
  • ML
  • Machine Learning
  • Discovery

Version: 101

Rule authors:

  • Elastic

Rule license: Elastic License v2