Skip to content
Threat Feed
low advisory

Suspicious File Execution Permission Modification in Containers

Detection of unauthorized use of the chmod utility to grant execution permissions to files within container environments, often indicative of post-exploitation or privilege escalation activity.

This brief details a detection capability focused on monitoring the modification of file execution permissions via the chmod utility within containerized Linux environments. Attackers frequently use chmod during post-exploitation phases to change the permissions of dropped malicious scripts, binaries, or payloads, enabling their execution. This activity is often associated with defense evasion and privilege escalation efforts. The detection mechanism targets specific permission arguments (such as 755, 777, or +x) that are commonly used to facilitate unauthorized code execution. Monitoring these changes helps defenders identify anomalous behavior within isolated container workloads, distinguishing between legitimate operational maintenance and malicious post-exploitation activity.

Impact

Successful exploitation involving unauthorized permission modification can lead to the execution of arbitrary malicious code within a container, potentially resulting in container breakout, lateral movement, or the deployment of ransomware within cloud-native environments.

Recommendation

Detection engineering teams should implement monitoring for chmod executions within container environments.

  • Deploy the provided Sigma rule to detect suspicious chmod command-line arguments.
  • Tune the detection logic by adding organizational allow-lists for known legitimate automation and system update scripts to reduce false positives.
  • Investigate any alert that originates from a non-standard container process or a user/service account that does not typically perform permission management.

Immediate actions

Deploy Sigma detection rule to environment

Detection Engineering 48h

Threat Hunt

Search for chmod usage with execution flags across container logs

T1222.002 medium medium confidence convert to detection

Data: Process command line arguments

Detection coverage 1

Detect Suspicious chmod Usage Within Containers

low

Detects the use of chmod to add execution permissions to files within a container, which may indicate unauthorized code execution or privilege escalation attempts.

sigma tactics: execution techniques: T1222.002 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →