Windows Permissions

T1222.001

Sub-technique of T1222 File and Directory Permissions Modification.View on attack.mitre.org

About this technique

Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).

Windows implements file and directory ACLs as Discretionary Access Control Lists (DACLs). Similar to a standard ACL, DACLs identifies the accounts that are allowed or denied access to a securable object. When an attempt is made to access a securable object, the system checks the access control entries in the DACL in order. If a matching entry is found, access to the object is granted. Otherwise, access is denied.

Adversaries can interact with the DACLs using built-in Windows commands, such as `icacls`, `cacls`, `takeown`, and `attrib`, which can grant adversaries higher permissions on specific files and folders. Further, PowerShell provides cmdlets that can be used to retrieve or modify file and directory DACLs. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.

Detection rules21

Rules on DetectionCode tagged with T1222.001.

Sigma3

RuleLevelLog source
AD Object WriteDAC Accesscriticalwindows / NULL
Potentially Suspicious NTFS Symlink Behavior Modificationmediumwindows / process_creation
Suspicious Recursive Takeownmediumwindows / process_creation

Splunk18

RuleTypeRiskData source
Hiding Files And Directories With Attrib exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2
Windows AD Dangerous Deny ACL ModificationTTPNULLWindows Event Log Security 5136
Windows AD Dangerous Group ACL ModificationTTPNULLWindows Event Log Security 5136
Windows AD Dangerous User ACL ModificationTTPNULLWindows Event Log Security 5136
Windows AD DCShadow Privileges ACL AdditionTTPNULLWindows Event Log Security 5136
Windows AD Domain Root ACL DeletionTTPNULLWindows Event Log Security 5136
Windows AD Domain Root ACL ModificationTTPNULLWindows Event Log Security 5136
Windows AD GPO New CSE AdditionTTPNULLWindows Event Log Security 5136
Windows AD Hidden OU CreationTTPNULLWindows Event Log Security 5136
Windows AD Object Owner UpdatedTTPNULLWindows Event Log Security 5136
Windows AD Suspicious Attribute ModificationTTPNULLWindows Event Log Security 5136
Windows AD Suspicious GPO ModificationTTPNULLWindows Event Log Security 5136, Windows Event Log Security 5145
Windows File and Directory Enable ReadOnly PermissionsTTPNULLSysmon EventID 1, Windows Event Log Security 4688
Windows File and Directory Permissions Enable InheritanceHuntingNULLSysmon EventID 1, Windows Event Log Security 4688
Windows File and Directory Permissions Remove InheritanceAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688

Groups2

Software10

Campaigns0

None recorded.

Procedure examples12

Groups2

Used byProcedure example
GroupStorm-1811

Storm-1811 has used `cacls.exe` via batch script to modify file and directory permissions in victim environments.

GroupWizard Spider

Wizard Spider has used the icacls command to modify access control to backup servers, providing them with full control of all the system folders.

Software10

Used byProcedure example
MalwareBitPaymer

BitPaymer can use icacls /reset and takeown /F to reset a targeted executable's permissions and then take ownership.

MalwareBlackByte Ransomware

BlackByte Ransomware uses the `mountvol.exe` command to mount volume names and leverages the Microsoft Discretionary Access Control List tool, `icacls.exe`, to grant the group to “Everyone” full access to the root of the drive.

MalwareBlackCat

BlackCat can use Windows commands such as `fsutil behavior set SymLinkEvaluation R2L:1` to redirect file system access to a different location after gaining access into compromised networks.

MalwareCaddyWiper

CaddyWiper can modify ACL entries to take ownership of files.

ToolDiskpart

Diskpart can be used to display, set, or clear attributes of a disk or volume.

MalwareGrandoreiro

Grandoreiro can modify the binary ACL to prevent security tools from running.

MalwareJPIN

JPIN can use the command-line utility cacls.exe to change file permissions.

MalwareRyuk

Ryuk can launch icacls <path> /grant Everyone:F /T /C /Q to delete every access-based restrictions on files and directories.

View all 10 software examples

References4

  1. Hybrid Analysis Icacls1 June 2018 Open source
    Hybrid Analysis. (2018, June 12). c9b65b764985dfd7a11d3faf599c56b8.exe. Retrieved August 19, 2018.
  2. Hybrid Analysis Icacls2 May 2018 Open source
    Hybrid Analysis. (2018, May 30). 2a8efbfadd798f6111340f7c1c956bee.dll. Retrieved August 19, 2018.
  3. Microsoft Access Control Lists May 2018 Open source
    M. Satran, M. Jacobs. (2018, May 30). Access Control Lists. Retrieved February 4, 2020.
  4. Microsoft DACL May 2018 Open source
    Microsoft. (2018, May 30). DACLs and ACEs. Retrieved August 19, 2018.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.