Glossary
pam_unix
The standard PAM module for password authentication and session accounting, which writes the pam_unix(service:type) lines in auth.log and secure.
pam_unix is the standard PAM (Pluggable Authentication Modules) module for classic Unix accounts. It checks passwords against /etc/shadow (auth), verifies that the account and password are still valid (account), changes passwords (password) and records the start and end of sessions (session). Almost every program that authenticates users on Linux goes through it: sshd, login, sudo, su, passwd, cron.
Its log lines name the PAM service and the module type in parentheses, pam_unix(service:type). The service is the PAM configuration file used (sshd, sudo, sudo-i, su, su-l, cron, passwd), which tells you how the session was opened. The lines go to the authpriv facility, so they end up in /var/log/auth.log on Debian and Ubuntu, /var/log/secure on the RHEL family, and in the journal.
Why it matters in investigations
pam_unix lines are the backbone of an auth.log timeline. authentication failure lines carry the source address (rhost=) and target account of password guessing. session opened and session closed lines share the PID of the process that opened the session, which pairs each login with its logout. pam_unix(sudo-i:session) marks an interactive root shell, and pam_unix(passwd:chauthtok): password changed is a classic takeover step: the intruder changes the password of the account they came in with.
Example
sshd[2381]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=198.51.100.23 user=svc_backup
sshd[3071]: pam_unix(sshd:session): session opened for user svc_backup(uid=1001) by svc_backup(uid=0)
sudo: pam_unix(sudo-i:session): session opened for user root(uid=0) by svc_backup(uid=1001)
CRON[3402]: pam_unix(cron:session): session opened for user svc_backup(uid=1001) by (uid=0)
The first line is a failed guess, the second an SSH session start, the third sudo -i, the fourth a cron job.
Related terms
- systemd-logind: numbers the same session a few milliseconds later.
- auid: the audit view of that login.
- rsyslog: writes these lines to auth.log or secure.
Linux Log Parser pairs pam_unix session lines by PID. More in auth.log forensics.