Technique with 2 sub-techniques.View on attack.mitre.org
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).
Modifications may include changing specific access rights, which may require taking ownership of a file or directory and/or elevated permissions depending on the file or directory’s existing permissions. This may enable malicious activity such as modifying, replacing, or deleting specific files or directories. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, Unix Shell Configuration Modification, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.
Adversaries may also change permissions of symbolic links. For example, malware (particularly ransomware) may modify symbolic links and associated settings to enable access to files from local shortcuts with remote paths.
Rules on DetectionCode tagged with T1222 or one of its sub-techniques.
| Rule | Level | Log source | Technique |
|---|---|---|---|
| AD Object WriteDAC Access | critical | windows / NULL | T1222.001 |
| PowerShell Set-Acl On Windows Folder - PsScript | high | windows / ps_script | T1222 |
| Chmod Targeting Sensitive Directories | medium | linux / process_creation | T1222.002 |
| Potentially Suspicious NTFS Symlink Behavior Modification | medium | windows / process_creation | T1222.001 |
| Remove Immutable File Attribute | medium | linux / process_creation | T1222.002 |
| Remove Immutable File Attribute - Auditd | medium | linux / NULL | T1222.002 |
| Suspicious Recursive Takeown | medium | windows / process_creation | T1222.001 |
| File or Folder Permissions Change | low | linux / NULL | T1222.002 |
| PowerShell Script Change Permission Via Set-Acl - PsScript | low | windows / ps_script | T1222 |
| Rule | Type | Risk | Data source | Technique |
|---|---|---|---|---|
| Excessive Usage Of Cacls App | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| Hiding Files And Directories With Attrib exe | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222.001 |
| Icacls Deny Command | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| ICACLS Grant Command | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| Linux Auditd Change File Owner To Root | Anomaly | NULL | Linux Auditd Proctitle | T1222.002 |
| Linux Auditd File Permission Modification Via Chmod | Anomaly | NULL | Linux Auditd Proctitle | T1222.002 |
| Linux Auditd File Permissions Modification Via Chattr | Anomaly | NULL | Linux Auditd Execve | T1222.002 |
| Linux Change File Owner To Root | Anomaly | NULL | Sysmon for Linux EventID 1 | T1222.002 |
| Modify ACL permission To Files Or Folder | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| Permission Modification using Takeown App | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| Windows AD Dangerous Deny ACL Modification | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Dangerous Group ACL Modification | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Dangerous User ACL Modification | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD DCShadow Privileges ACL Addition | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Domain Root ACL Deletion | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Domain Root ACL Modification | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD GPO New CSE Addition | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Hidden OU Creation | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Object Owner Updated | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Suspicious Attribute Modification | TTP | NULL | Windows Event Log Security 5136 | T1222.001 |
| Windows AD Suspicious GPO Modification | TTP | NULL | Windows Event Log Security 5136, Windows Event Log Security 5145 | T1222.001 |
| Windows Common Abused Cmd Shell Risk Behavior | Correlation | NULL | T1222 | |
| Windows File and Directory Enable ReadOnly Permissions | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1222.001 |
| Windows File and Directory Permissions Enable Inheritance | Hunting | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1222.001 |
| Windows File and Directory Permissions Remove Inheritance | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688 | T1222.001 |
| Windows Files and Dirs Access Rights Modification Via Icacls | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222.001 |
| Windows SubInAcl Execution | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222.001 |
| Windows SymbolicLink-Testing-Tools Utility Execution | TTP | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222 |
| Windows Symlink Evaluation Change via Fsutil | Anomaly | NULL | Sysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2 | T1222.001 |
None recorded.
None recorded.
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.