Velvet Ant PAM Stack Tampering and Credential Interception on Linux

This rule monitors for suspicious activities related to Pluggable Authentication Modules (PAM) and authentication daemons. It detects unauthorized modifications to PAM configuration and shared object files, unexpected child processes spawned by sshd, the use of LD_PRELOAD in authentication contexts, and the tracing of authentication binaries (e.g., sshd, login, sudo) via strace.