Skip to content
Threat Feed
high advisory

Detection of File Permission Modification in Writable Linux Directories

This detection rule identifies potential defense evasion activity on Linux systems where a non-root user modifies file permissions within temporary directories to stage or execute malicious payloads.

Adversaries targeting Linux systems frequently utilize world-writable directories such as /tmp, /var/tmp, and /dev/shm to stage malicious artifacts, scripts, or binary payloads. Because these directories are designed to be accessible by multiple users, they provide a convenient environment for attackers to store files that require specific permissions for execution. By modifying the file permissions using commands such as chmod, chattr, or chgrp, adversaries can ensure their payloads are executable while attempting to bypass basic security controls.

The detection logic focuses on identifying instances where a non-root user invokes these permission-changing utilities within these specific directories. It includes a comprehensive exclusion list to filter out expected system activity, such as package manager operations or legitimate maintenance scripts, ensuring security operations teams can focus on anomalous behavior that may signal an ongoing defense evasion attempt.

Impact

Successful exploitation allows an attacker to maintain persistent access or execute malicious code on the target system. In enterprise environments, this behavior is often observed in the later stages of an intrusion to prepare for lateral movement or data exfiltration. Failure to detect these modifications can lead to unauthorized code execution, privilege escalation, or full system compromise.

Recommendation

Prioritized actions for detection and response:

  • Deploy the provided Sigma rule to your SIEM/Detection engine to monitor for suspicious use of chmod, chgrp, or chattr in common writable paths.
  • Review process parent-child relationships for alerts generated by this rule; prioritize investigation of shells or unknown processes spawning these utilities.
  • Audit the contents of /tmp, /var/tmp, and /dev/shm regularly for unauthorized scripts or binaries.
  • Baseline common administrative workflows in your environment to further tune the exclusion list and reduce false positives.

Immediate actions

Deploy the provided Sigma rule to identify unauthorized permission modifications

Detection Engineering 48h

Threat Hunt

Search for historical logs of chmod/chgrp usage in /tmp and /var/tmp

T1222 medium medium confidence hunt now

Data: Process creation logs

Mitigations

Implement strict mount options for temp directories (e.g., noexec)

medium IT Operations

T1222.002

Detection coverage 1

Detect File Permission Modification in Writable Directories

high

Detects non-root users modifying file permissions in /tmp, /var/tmp, or /dev/shm using chmod, chgrp, or chattr.

sigma tactics: defense_evasion techniques: T1222.002 sources: process_creation, linux

Detection queries are available on the platform. Get full rules →