File and Directory Permissions Modification: Linux and Mac Permissions T1222.002

Tactic: Defense Impairment

Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).

Events covered

5 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 23 rules share fields, values, and exclusions.

Fields filtered most (25 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name15eq 10, in 5, is_not_null 1, wildcard 1chmod, chattr, chown, bash, busybox
event.type14eq 13, in 1start, change, creation
EventType12eq 8, in 4exec, exec_event, ProcessRollup2, changed-file-ownership-of, fork
process.args10starts_with 6, in 5, wildcard 5, eq 1+x, +*i*, -*i*, /dev/shm/, +*u*
host.os.type9eq 9
CommandLine5contains 4, eq 1, regex_match 1, starts_with 1 -i , root , (?i)(^chmod\s+([-fhvrlp]+\s+)?((([01234567]{1,1})?([1357]..., /.library/, /etc/
Image5ends_with 2, eq 2, starts_with 1/bin/chattr, /usr/bin/chattr, /usr/local/bin/chattr, ./, /boot/
ParentImage3is_not_null 2, starts_with 1./, /dev/shm/, /tmp/
event.category3eq 2, in 1file, process
proctitle3contains 2, eq 1, in 1 -i, * 754 *, * 755 *, * 777 *, *chown *root*
sourcetype3eq 3auditd
TargetFilename2in 1, starts_with 1/dev/shm/, /etc/passwd, /etc/shadow, /etc/sudoers, /run/
a02contains 2chattr, chmod, chown
parent_process_name2starts_with 1, wildcard 1., bash, csh, dash
type2eq 2execve

Top indicator values (242 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
121087
EventTypeeq
exec
8579
process.argsin
+x
57
process.argsin
777
57
process.argsin
4755
44
process.argsin
755
44
process.argsin
0777
34
process.argsin
444
33
process.argsin
a+x
34
process.argsin
000
22
process_nameeq
chmod
511
process_nameeq
chattr
33
EventTypein
exec
4206
EventTypein
exec_event
4150
EventTypein
start
4168
EventTypein
ProcessRollup2
3118
EventTypein
executed
398
EventTypein
process_started
383
process_namein
chmod
34
sourcetypeeq
auditd
358
Imageeq
/bin/chattr
22
Imageeq
/usr/bin/chattr
22
Imageeq
/usr/local/bin/chattr
22
process.argsstarts_with
/dev/shm/
210
process.argswildcard
+*i*
22
process.argswildcard
-*i*
22
process.argswildcard
/etc/cron*
22
process.argswildcard
/etc/init.d/*
23
process.argswildcard
/etc/rc.local
22
process.argswildcard
/usr/local/bin/*
23

Exclusions (219 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
parent_process_namein
sudo
3
parent_process_namein
systemd
2
ParentCommandLineeq
runc init
2
ParentImagein
/opt/puppetlabs/puppet/bin/ruby
2
CommandLinecontains
/etc/
1
CommandLinecontains
chmod --reference=/etc/shells
1
CommandLineeq
/bin/setfacl --restore=-
1
CommandLineeq
chattr +i /usr/local/bin/ems_vm_shell.sh
1
CommandLineeq
chattr -iua /tmp
1
CommandLineeq
chmod +x decompress
1
CommandLineeq
chmod 0775 /etc/landscape/
1
CommandLineeq
chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu
1
CommandLineeq
chmod 777 /dev/shm/check-point
1
CommandLinein
chattr +i /etc/pam.d/common-auth
1
CommandLinein
chattr +i /etc/pam.d/password-auth
1

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 4 rules

Elastic 14 rules

Splunk 5 rules