im trying to figure out an effective way to detect...
# general
c
im trying to figure out an effective way to detect this type of attack using osquery: http://seclist.us/sudo-backdoor-wrapper-to-sudo-for-stealing-user-password.html is there any way to use osquery to see what the result of the command $(which sudo) are or something similar?