Sub-technique of T1222 File and Directory Permissions Modification.View on attack.mitre.org
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).
Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Similar to a standard ACL, DACLs identifies the accounts that are allowed or denied access to a securable object. When an attempt is made to access a securable object, the system checks the access control entries in the DACL in order. If a matching entry is found, access to the object is granted. Otherwise, access is denied.
Adversaries can interact with the DACLs using built-in Windows commands, such as `icacls`, `cacls`, `takeown`, and `attrib`, which can grant adversaries higher permissions on specific files and folders. Further, PowerShell provides cmdlets that can be used to retrieve or modify file and directory DACLs. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.
Rules on DetectionCode tagged with T1222.001.
| Rule | Level | Log source |
|---|---|---|
| AD Object WriteDAC Access | critical | windows / NULL |
| Potentially Suspicious NTFS Symlink Behavior Modification | medium | windows / process_creation |
| Suspicious Recursive Takeown | medium | windows / process_creation |
| Rule | Type | Risk | Data source |
|---|---|---|---|
| Hiding Files And Directories With Attrib exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows AD Dangerous Deny ACL Modification | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Dangerous Group ACL Modification | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Dangerous User ACL Modification | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD DCShadow Privileges ACL Addition | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Domain Root ACL Deletion | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Domain Root ACL Modification | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD GPO New CSE Addition | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Hidden OU Creation | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Object Owner Updated | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Suspicious Attribute Modification | TTP | NULL | Windows Event Log Security 5136 |
| Windows AD Suspicious GPO Modification | TTP | NULL | Windows Event Log Security 5136, Windows Event Log Security 5145 |
| Windows File and Directory Enable ReadOnly Permissions | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows File and Directory Permissions Enable Inheritance | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows File and Directory Permissions Remove Inheritance | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 |
| Windows Files and Dirs Access Rights Modification Via Icacls | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows SubInAcl Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
| Windows Symlink Evaluation Change via Fsutil | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 |
None recorded.
| Used by | Procedure example |
|---|---|
| GroupStorm-1811 | Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments. |
| GroupWizard Spider | Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders. |
| Used by | Procedure example |
|---|---|
| MalwareBitPaymer | BitPaymer can use |
| MalwareBlackByte Ransomware | BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive. |
| MalwareBlackCat | BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks. |
| MalwareCaddyWiper | CaddyWiper can modify ACL entries to take ownership of files. |
| ToolDiskpart | Diskpart can be used to display, set, or clear attributes of a disk or volume. |
| MalwareGrandoreiro | Grandoreiro can modify the binary ACL to prevent security tools from running. |
| MalwareJPIN | JPIN can use the command-line utility cacls.exe to change file permissions. |
| MalwareRyuk | Ryuk can launch |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.