Detection of File Permission Modification in Writable Linux Directories
This detection rule identifies potential defense evasion activity on Linux systems where a non-root user modifies file permissions within temporary directories to stage or execute malicious payloads.
Adversaries targeting Linux systems frequently utilize world-writable directories such as /tmp, /var/tmp, and /dev/shm to stage malicious artifacts, scripts, or binary payloads. Because these directories are designed to be accessible by multiple users, they provide a convenient environment for attackers to store files that require specific permissions for execution. By modifying the file permissions using commands such as chmod, chattr, or chgrp, adversaries can ensure their payloads are executable while attempting to bypass basic security controls.
The detection logic focuses on identifying instances where a non-root user invokes these permission-changing utilities within these specific directories. It includes a comprehensive exclusion list to filter out expected system activity, such as package manager operations or legitimate maintenance scripts, ensuring security operations teams can focus on anomalous behavior that may signal an ongoing defense evasion attempt.
Impact
Successful exploitation allows an attacker to maintain persistent access or execute malicious code on the target system. In enterprise environments, this behavior is often observed in the later stages of an intrusion to prepare for lateral movement or data exfiltration. Failure to detect these modifications can lead to unauthorized code execution, privilege escalation, or full system compromise.
Recommendation
Prioritized actions for detection and response:
- Deploy the provided Sigma rule to your SIEM/Detection engine to monitor for suspicious use of chmod, chgrp, or chattr in common writable paths.
- Review process parent-child relationships for alerts generated by this rule; prioritize investigation of shells or unknown processes spawning these utilities.
- Audit the contents of /tmp, /var/tmp, and /dev/shm regularly for unauthorized scripts or binaries.
- Baseline common administrative workflows in your environment to further tune the exclusion list and reduce false positives.
Immediate actions
Deploy the provided Sigma rule to identify unauthorized permission modifications
Threat Hunt
Search for historical logs of chmod/chgrp usage in /tmp and /var/tmp
Data: Process creation logs
Mitigations
Implement strict mount options for temp directories (e.g., noexec)
T1222.002
Detection coverage 1
Detect File Permission Modification in Writable Directories
highDetects non-root users modifying file permissions in /tmp, /var/tmp, or /dev/shm using chmod, chgrp, or chattr.
Detection queries are available on the platform. Get full rules →