File and Directory Permissions Modification T1222

Tactic: Defense Impairment

Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).

Events covered

15 catalog events are tagged with this technique by at least one rule.

Authoring guide

These 88 rules share fields, values, and exclusions.

Fields filtered most (67 distinct)

These fields appear most often in rule filters.

FieldRulesHowSample values
process_name32eq 18, in 14, is_not_null 1, wildcard 1icacls.exe, cacls.exe, chmod, xcacls.exe, chattr
CommandLine29contains 14, regex_match 9, in 5, ends_with 1, eq 1, starts_with 1, wildcard 1(?i)\s+-r\s+, (?i)\s\+h\s+, (?i)\s+\/grant\s+everyone, */g *, */grant*
EventID24eq 245136, 1, 4688, 4104, 4103
EventType17eq 12, in 5exec, exec_event, ProcessRollup2, start, changed-file-ownership-of
event.type17eq 16, in 1start, change, creation
process.args14starts_with 6, wildcard 6, eq 5, in 5+x, +*i*, -*i*, /dev/shm/, /f
host.os.type12eq 12
Channel10eq 10, in 10
eventtype10eq 10
Image9ends_with 6, eq 2, contains 1, starts_with 1/bin/chattr, /usr/bin/chattr, /usr/local/bin/chattr, ./, /boot/
ObjectClass7eq 7domaindns, group, grouppolicycontainer, organizationalunit, user
OriginalFileName6eq 6attrib.exe, icacls.exe, cacls.exe, cmd.exe, fsutil.exe
AttributeLDAPDisplayName5eq 4, in 1ntsecuritydescriptor, gpcmachineextensionnames, msds-allowedtoactonbehalfofotheridentity, msds-allowedtodelegateto, mstsinitialprogram
OperationType4eq 4%%14674
Type4eq 4

Top indicator values (489 distinct)

These values appear most often in rule predicates.

FieldKindValueRules (here)Corpus reach
event.typeeq
start
151078
EventIDeq
5136
1245
EventIDeq
1
4241
EventIDeq
4688
4317
EventIDeq
4104
3269
EventTypeeq
exec
8576
process_namein
cacls.exe
88
process_namein
icacls.exe
88
process_namein
xcacls.exe
88
process.argsin
+x
57
process.argsin
777
57
process.argsin
4755
44
process.argsin
755
44
process_nameeq
chmod
511
process_nameeq
takeown.exe
45
EventTypein
exec
4201
EventTypein
exec_event
4149
EventTypein
start
4163
EventTypein
ProcessRollup2
3117
EventTypein
executed
398
EventTypein
process_started
383
OperationTypeeq
%%14674
417
event.outcomeeq
success
4369
AttributeLDAPDisplayNameeq
ntsecuritydescriptor
37
CommandLinein
*/grant*
33
CommandLineregex_match
(?i)\s+-r\s+
33
CommandLineregex_match
(?i)\s\+h\s+
33
ObjectClasseq
domaindns
34
aceAccessRightsin
full control
34
process.argseq
/f
35

Exclusions (255 distinct)

These values appear most often in top-level exclusions.

FieldKindValueRules excluding
new_aceeq
old_values
6
parent_process_namein
sudo
3
parent_process_namein
systemd
2
ParentCommandLineeq
runc init
2
ParentImagein
/opt/puppetlabs/puppet/bin/ruby
2
aceTypein
*denied*
2
aceTypein
d
2
aceTypein
od
2
aceTypein
xd
2
responseStatus.codege
1
2
responseStatus.codege
400
2
responseStatus.codele
16
2
usernamein
aksService
2
usernamein
masterclient
2
usernamestarts_with
system:
2

Rules under this technique

These vendors publish rules tagged with this technique.

Platform (all)
Domain (all)

Sigma 18 rules

Elastic 22 rules

Splunk 40 rules

Kusto 4 rules

Panther 4 rules