Chmod Targeting Sensitive Directories


Description

Detects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.

Query · sigma

selection:
  Image|endswith: /chmod
  CommandLine|contains:
  - /tmp/
  - /.Library/
  - /etc/
  - /opt/
filter_main_update_shells:
  CommandLine|contains: chmod --reference=/etc/shells
  ParentCommandLine|endswith: /update-shells
filter_main_postinst:
  CommandLine|contains: /etc/
  ParentCommandLine|contains|all:
  - /var/lib/dpkg/info/
  - .postinst configure
filter_main_apt_key:
  CommandLine|startswith: chmod 700 /tmp/apt-key-gpghome.
filter_main_mkinitramfs:
  CommandLine|startswith: chmod 755 /var/tmp/mkinitramfs
filter_main_landscape:
  CommandLine: chmod 0775 /etc/landscape/
filter_main_ubuntu_apparmor:
  CommandLine: chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu
condition: selection and not 1 of filter_main_*

Known false positives

  • Some false positives are to be expected. Apply additional filters as needed before pushing to production.
Raw source Chmod Targeting Sensitive Directories · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Chmod Targeting Sensitive Directories
id: 6419afd1-3742-47a5-a7e6-b50386cd15f8
status: test
description: |
    Detects chmod targeting files in sensitive directory paths on Linux systems.
    Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.
references:
    - https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
    - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
author: 'Christopher Peacock @SecurePeacock, SCYTHE @scythe_io'
date: 2022-06-03
modified: 2026-03-18
tags:
    - attack.defense-impairment
    - attack.t1222.002
logsource:
    product: linux
    category: process_creation
detection:
    selection:
        Image|endswith: '/chmod'
        CommandLine|contains:
            - '/tmp/'
            - '/.Library/'
            - '/etc/'
            - '/opt/'
    filter_main_update_shells:
        CommandLine|contains: 'chmod --reference=/etc/shells'
        ParentCommandLine|endswith: '/update-shells'
    filter_main_postinst:
        CommandLine|contains: '/etc/'
        ParentCommandLine|contains|all:
            - '/var/lib/dpkg/info/'
            - '.postinst configure'
    filter_main_apt_key:
        CommandLine|startswith: 'chmod 700 /tmp/apt-key-gpghome.'
    filter_main_mkinitramfs:
        CommandLine|startswith: 'chmod 755 /var/tmp/mkinitramfs'
    filter_main_landscape:
        CommandLine: 'chmod 0775 /etc/landscape/'
    filter_main_ubuntu_apparmor:
        CommandLine: 'chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu'
    condition: selection and not 1 of filter_main_*
falsepositives:
    - Some false positives are to be expected. Apply additional filters as needed before pushing to production.
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.