Linux: chattr -i Used to Remove Immutable File Attribute

Flags Linux process use of chattr with -i to remove the immutable file attribute.

FreeUnreviewedSigmamediumv1
title: "Linux: chattr -i Used to Remove Immutable File Attribute"
id: f207b146-5627-421a-ab82-7d439ba4d935
related:
  - id: a5b977d6-8a81-4475-91b9-49dbfcd941f7
    type: derived
  - id: 34979410-e4b5-4e5d-8cfb-389fdff05c12
    type: derived
status: test
description: This rule identifies process executions of the chattr utility where the command line includes the immutable-attribute removal flag (-i). Removing the immutable attribute can enable attackers or administrators to modify files that were previously protected against changes. It relies on Linux process creation telemetry containing the executable path and command-line arguments.
references:
  - https://www.trendmicro.com/en_us/research/22/i/how-malicious-actors-abuse-native-linux-tools-in-their-attacks.html
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chattr_immutable_removal.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-09-15
tags:
  - attack.defense-impairment
  - attack.t1222.002
logsource:
  product: linux
  category: process_creation
detection:
  selection:
    Image|endswith: /chattr
    CommandLine|contains: " -i "
  condition: selection
falsepositives:
  - Administrator interacting with immutable files (e.g. for instance backups).
level: medium
license: DRL-1.1

What it detects

This rule identifies process executions of the chattr utility where the command line includes the immutable-attribute removal flag (-i). Removing the immutable attribute can enable attackers or administrators to modify files that were previously protected against changes. It relies on Linux process creation telemetry containing the executable path and command-line arguments.

Known false positives

  • Administrator interacting with immutable files (e.g. for instance backups).

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.