It seems to me that our PAM Sniffer tool could improve an assessment of the situation by indicating which systems make use of privilege escalations and which users escalate most. today we only identify accounts with admin privileges to help customer decide which they should get rid of, but no immediate insight as to which systems to start with or what user accounts to prioritize.

In Linux, we can examine the logs in /var/log/secure or /var/log/auth and just grep for "sudo" to identify these things. I think we could easily automate this in our sniffer tool to add more value from the get go.

Comments

  • nice Idea and same could be applied to IBM AIX agents too.

  • Idea need attention. PM should planned to deliver such an idea on top priority.