Linux chmod Process Creation Targeting Sensitive Directory Paths
Flags Linux chmod commands that modify permissions for paths under /tmp/, /.Library/, /etc/, or /opt/, excluding several known benign package-maintenance patterns.
FreeUnreviewedSigmamediumv1
linux-chmod-process-creation-targeting-sensitive-directory-paths-6419afd1
title: Linux chmod Process Creation Targeting Sensitive Directory Paths
id: 644a08e4-f8e6-48a1-bafa-cfee4e744654
status: test
description: This rule identifies Linux process executions of chmod where the command line targets files under sensitive-looking directories such as /tmp/, /.Library/, /etc/, and /opt/. Changing permissions in these locations can help attackers persist, escalate access, or impair system behavior by altering how other components read or execute files. It relies on process creation telemetry including the executable path ending in /chmod and the full command line content.
references:
- https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chmod_targeting_sensitive_directories.yml
author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule Team
date: 2022-06-03
modified: 2026-03-18
tags:
- attack.defense-impairment
- attack.t1222.002
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /chmod
CommandLine|contains:
- /tmp/
- /.Library/
- /etc/
- /opt/
filter_main_update_shells:
CommandLine|contains: chmod --reference=/etc/shells
ParentCommandLine|endswith: /update-shells
filter_main_postinst:
CommandLine|contains: /etc/
ParentCommandLine|contains|all:
- /var/lib/dpkg/info/
- .postinst configure
filter_main_apt_key:
CommandLine|startswith: chmod 700 /tmp/apt-key-gpghome.
filter_main_mkinitramfs:
CommandLine|startswith: chmod 755 /var/tmp/mkinitramfs
filter_main_landscape:
CommandLine: chmod 0775 /etc/landscape/
filter_main_ubuntu_apparmor:
CommandLine: chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu
condition: selection and not 1 of filter_main_*
falsepositives:
- Some false positives are to be expected. Apply additional filters as needed before pushing to production.
level: medium
license: DRL-1.1
related:
- id: 6419afd1-3742-47a5-a7e6-b50386cd15f8
type: derived
What it detects
This rule identifies Linux process executions of chmod where the command line targets files under sensitive-looking directories such as /tmp/, /.Library/, /etc/, and /opt/. Changing permissions in these locations can help attackers persist, escalate access, or impair system behavior by altering how other components read or execute files. It relies on process creation telemetry including the executable path ending in /chmod and the full command line content.
Known false positives
- Some false positives are to be expected. Apply additional filters as needed before pushing to production.
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.