File and Directory Permissions Modification

T1222

Technique with 2 sub-techniques.View on attack.mitre.org

About this technique

Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).

Modifications may include changing specific access rights, which may require taking ownership of a file or directory and/or elevated permissions depending on the file or directory’s existing permissions. This may enable malicious activity such as modifying, replacing, or deleting specific files or directories. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, Unix Shell Configuration Modification, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.

Adversaries may also change permissions of symbolic links. For example, malware (particularly ransomware) may modify symbolic links and associated settings to enable access to files from local shortcuts with remote paths.

Detection rules38

Rules on DetectionCode tagged with T1222 or one of its sub-techniques.

Sigma9

Splunk29

RuleTypeRiskData sourceTechnique
Excessive Usage Of Cacls AppAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222
Hiding Files And Directories With Attrib exeTTPNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222.001
Icacls Deny CommandAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222
ICACLS Grant CommandAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222
Linux Auditd Change File Owner To RootAnomalyNULLLinux Auditd ProctitleT1222.002
Linux Auditd File Permission Modification Via ChmodAnomalyNULLLinux Auditd ProctitleT1222.002
Linux Auditd File Permissions Modification Via ChattrAnomalyNULLLinux Auditd ExecveT1222.002
Linux Change File Owner To RootAnomalyNULLSysmon for Linux EventID 1T1222.002
Modify ACL permission To Files Or FolderAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222
Permission Modification using Takeown AppAnomalyNULLSysmon EventID 1, Windows Event Log Security 4688, CrowdStrike ProcessRollup2T1222
Windows AD Dangerous Deny ACL ModificationTTPNULLWindows Event Log Security 5136T1222.001
Windows AD Dangerous Group ACL ModificationTTPNULLWindows Event Log Security 5136T1222.001
Windows AD Dangerous User ACL ModificationTTPNULLWindows Event Log Security 5136T1222.001
Windows AD DCShadow Privileges ACL AdditionTTPNULLWindows Event Log Security 5136T1222.001
Windows AD Domain Root ACL DeletionTTPNULLWindows Event Log Security 5136T1222.001

Sub-techniques2

IDNameExamples
T1222.001Windows Permissions12
T1222.002Linux and Mac Permissions15

Groups0

None recorded.

Software1

Campaigns0

None recorded.

Procedure examples1

Software1

Used byProcedure example
MalwareQilin

Qilin can use symbolic links to redirect file paths for remote and local objects and can use `chmod +x` to make its payload binary executable.

References7

  1. Hybrid Analysis Icacls1 June 2018 Open source
    Hybrid Analysis. (2018, June 12). c9b65b764985dfd7a11d3faf599c56b8.exe. Retrieved August 19, 2018.
  2. Hybrid Analysis Icacls2 May 2018 Open source
    Hybrid Analysis. (2018, May 30). 2a8efbfadd798f6111340f7c1c956bee.dll. Retrieved August 19, 2018.
  3. bad_luck_blackcat Open source
    Kaspersky Global Research & Analysis Team (GReAT). (2022). A Bad Luck BlackCat. Retrieved May 5, 2022.
  4. blackmatter_blackcat Open source
    Pereira, T. Huey, C. (2022, March 17). From BlackMatter to BlackCat: Analyzing two attacks from one affiliate. Retrieved May 5, 2022.
  5. falconoverwatch_blackcat_attack Open source
    Falcon OverWatch Team. (2022, March 23). Falcon OverWatch Threat Hunting Contributes to Seamless Protection Against Novel BlackCat Attack. Retrieved May 5, 2022.
  6. fsutil_behavior Open source
    Microsoft. (2021, September 27). fsutil behavior. Retrieved January 14, 2022.
  7. new_rust_based_ransomware Open source
    Symantec Threat Hunter Team. (2021, December 16). Noberus: Technical Analysis Shows Sophistication of New Rust-based Ransomware. Retrieved January 14, 2022.

Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.