Detection rules › Sigma

Chmod Targeting Sensitive Directories

Status
test
Severity
medium
Log source
category process_creation, product linux
Author
Christopher Peacock @SecurePeacock, SCYTHE @scythe_io
Source
github.com/SigmaHQ/sigma

Detects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.

Known false positives

  • Some false positives are to be expected. Apply additional filters as needed before pushing to production.

MITRE ATT&CK coverage

Telemetry coverage

PlatformRecord / event type
LinuxEvent ID 1: Process Create

Rule body

title: Chmod Targeting Sensitive Directories
id: 6419afd1-3742-47a5-a7e6-b50386cd15f8
status: test
description: |
    Detects chmod targeting files in sensitive directory paths on Linux systems.
    Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.
references:
    - https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
author: 'Christopher Peacock @SecurePeacock, SCYTHE @scythe_io'
date: 2022-06-03
modified: 2026-03-18
tags:
    - attack.defense-impairment
    - attack.t1222.002
logsource:
    product: linux
    category: process_creation
detection:
    selection:
        Image|endswith: '/chmod'
        CommandLine|contains:
            - '/tmp/'
            - '/.Library/'
            - '/etc/'
            - '/opt/'
    filter_main_update_shells:
        CommandLine|contains: 'chmod --reference=/etc/shells'
        ParentCommandLine|endswith: '/update-shells'
    filter_main_postinst:
        CommandLine|contains: '/etc/'
        ParentCommandLine|contains|all:
            - '/var/lib/dpkg/info/'
            - '.postinst configure'
    filter_main_apt_key:
        CommandLine|startswith: 'chmod 700 /tmp/apt-key-gpghome.'
    filter_main_mkinitramfs:
        CommandLine|startswith: 'chmod 755 /var/tmp/mkinitramfs'
    filter_main_landscape:
        CommandLine: 'chmod 0775 /etc/landscape/'
    filter_main_ubuntu_apparmor:
        CommandLine: 'chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Some false positives are to be expected. Apply additional filters as needed before pushing to production.
level: medium

Stages and Predicates

Stage 0: condition

selection and not 1 of filter_main_*

Stage 1: selection

selection:
    Image|endswith: '/chmod'
    CommandLine|contains:
        - '/tmp/'
        - '/.Library/'
        - '/etc/'
        - '/opt/'

Stage 2: not filter_main_*

filter_main_update_shells:
    CommandLine|contains: 'chmod --reference=/etc/shells'
    ParentCommandLine|endswith: '/update-shells'
filter_main_postinst:
    CommandLine|contains: '/etc/'
    ParentCommandLine|contains|all:
        - '/var/lib/dpkg/info/'
        - '.postinst configure'
filter_main_apt_key:
    CommandLine|startswith: 'chmod 700 /tmp/apt-key-gpghome.'
filter_main_mkinitramfs:
    CommandLine|startswith: 'chmod 755 /var/tmp/mkinitramfs'
filter_main_landscape:
    CommandLine: 'chmod 0775 /etc/landscape/'
filter_main_ubuntu_apparmor:
    CommandLine: 'chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu'

Exclusions

The rule actively suppresses these predicates.

Indicators

These rows show field, operator, and value matches.

FieldKindValuesSearch
CommandLinematch
  • /.Library/
  • /etc/
  • /opt/
  • /tmp/
field:"CommandLine" kind:match
Imageends_with
  • /chmod
field:"Image" kind:ends_with value:"/chmod"