Linux: chattr Used to Remove Immutable File Attribute
Flags Linux process use of chattr with -i to remove the immutable file attribute.
- Product
- linux
- Category
- process_creation
- Author
- Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
- Published
- 2022-09-15
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags process executions where the command invokes the chattr utility with the immutable-attribute removal option ("-i"), indicating an attempt to alter file protection. Removing immutability can help attackers modify or delete files that were intended to resist tampering, supporting defense-impairment and persistence activities. It relies on Linux process creation telemetry, matching the chattr executable path and the presence of the " -i " argument in the command line.
Reporting behind it
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: "Linux: chattr Used to Remove Immutable File Attribute"
id: f207b146-5627-421a-ab82-7d439ba4d935
related:
- id: a5b977d6-8a81-4475-91b9-49dbfcd941f7
type: derived
- id: 34979410-e4b5-4e5d-8cfb-389fdff05c12
type: derived
status: test
description: This rule flags process executions where the command invokes the chattr utility with the immutable-attribute removal option ("-i"), indicating an attempt to alter file protection. Removing immutability can help attackers modify or delete files that were intended to resist tampering, supporting defense-impairment and persistence activities. It relies on Linux process creation telemetry, matching the chattr executable path and the presence of the " -i " argument in the command line.
references:
- https://www.trendmicro.com/en_us/research/22/i/how-malicious-actors-abuse-native-linux-tools-in-their-attacks.html
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chattr_immutable_removal.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-09-15
tags:
- attack.defense-impairment
- attack.t1222.002
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /chattr
CommandLine|contains: " -i "
condition: selection
falsepositives:
- Administrator interacting with immutable files (e.g. for instance backups).
level: medium
license: DRL-1.1