Potential Suspicious Change To Sensitive/Critical Files


Description

Detects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system. These files include, but are not limited to, system configuration files, authentication files, and critical application files. Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.

Query · sigma

selection_img_1:
  Image|endswith:
  - /cat
  - /echo
  - /grep
  - /head
  - /more
  - /tail
  CommandLine|contains: '>'
selection_img_2:
  Image|endswith:
  - /emacs
  - /nano
  - /sed
  - /vi
  - /vim
selection_paths:
  CommandLine|contains:
  - /bin/login
  - /bin/passwd
  - /boot/
  - /etc/*.conf
  - /etc/cron.
  - /etc/crontab
  - /etc/hosts
  - /etc/init.d
  - /etc/sudoers
  - /opt/bin/
  - /sbin
  - /usr/bin/
  - /usr/local/bin/
filter_main_mdadm.conf:
  Image|endswith: /bin/sed
  CommandLine|startswith:
  - sed -i /^*
  - sed -ne s/^
  CommandLine|endswith: /etc/mdadm/mdadm.conf
condition: 1 of selection_img_* and selection_paths and not 1 of filter_main_*

Known false positives

  • Some false positives are to be expected on user or administrator machines. Apply additional filters as needed.
Raw source Potential Suspicious Change To Sensitive/Critical Files · Sigma
Esc
Published by SigmaHQ/sigma ↗, licensed under Detection Rule License 1.1 ↗. Reproduced here unmodified.
title: Potential Suspicious Change To Sensitive/Critical Files
id: 86157017-c2b1-4d4a-8c33-93b8e67e4af4
status: test
description: |
    Detects changes of sensitive and critical files. Monitors files that you don't expect to change without planning on Linux system.
    These files include, but are not limited to, system configuration files, authentication files, and critical application files.
    Attackers often target these files to maintain persistence, escalate privileges, or disrupt system operations.
references:
    - https://learn.microsoft.com/en-us/azure/defender-for-cloud/file-integrity-monitoring-overview#which-files-should-i-monitor
author: '@d4ns4n_ (Wuerth-Phoenix)'
date: 2023-05-30
modified: 2026-03-18
tags:
    - attack.impact
    - attack.t1565.001
logsource:
    category: process_creation
    product: linux
detection:
    selection_img_1:
        Image|endswith:
            - '/cat'
            - '/echo'
            - '/grep'
            - '/head'
            - '/more'
            - '/tail'
        CommandLine|contains: '>'
    selection_img_2:
        Image|endswith:
            - '/emacs'
            - '/nano'
            - '/sed'
            - '/vi'
            - '/vim'
    selection_paths:
        CommandLine|contains:
            - '/bin/login'
            - '/bin/passwd'
            - '/boot/'
            - '/etc/*.conf'
            - '/etc/cron.' # Covers different cron config files "daily", "hourly", etc.
            - '/etc/crontab'
            - '/etc/hosts'
            - '/etc/init.d'
            - '/etc/sudoers'
            - '/opt/bin/'
            - '/sbin' # Covers: '/opt/sbin', '/usr/local/sbin/', '/usr/sbin/'
            - '/usr/bin/'
            - '/usr/local/bin/'
    filter_main_mdadm.conf:
        Image|endswith: '/bin/sed'
        CommandLine|startswith:
            - 'sed -i /^*'
            - 'sed -ne s/^'
        CommandLine|endswith: '/etc/mdadm/mdadm.conf'
    condition: 1 of selection_img_* and selection_paths and not 1 of filter_main_*
falsepositives:
    - Some false positives are to be expected on user or administrator machines. Apply additional filters as needed.
level: medium

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.