Chmod Targeting Sensitive Directories
Description
Detects chmod targeting files in sensitive directory paths on Linux systems. Attackers may use chmod to change permissions of files in these directories to maintain persistence, escalate privileges, or disrupt system operations.
Query · sigma
selection: Image|endswith: /chmod CommandLine|contains: - /tmp/ - /.Library/ - /etc/ - /opt/ filter_main_update_shells: CommandLine|contains: chmod --reference=/etc/shells ParentCommandLine|endswith: /update-shells filter_main_postinst: CommandLine|contains: /etc/ ParentCommandLine|contains|all: - /var/lib/dpkg/info/ - .postinst configure filter_main_apt_key: CommandLine|startswith: chmod 700 /tmp/apt-key-gpghome. filter_main_mkinitramfs: CommandLine|startswith: chmod 755 /var/tmp/mkinitramfs filter_main_landscape: CommandLine: chmod 0775 /etc/landscape/ filter_main_ubuntu_apparmor: CommandLine: chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu condition: selection and not 1 of filter_main_*
Known false positives
- Some false positives are to be expected. Apply additional filters as needed before pushing to production.