Linux chmod Process Creation Targeting Sensitive Directory Paths

Flags Linux chmod commands that modify permissions for paths under /tmp/, /.Library/, /etc/, or /opt/, excluding several known benign package-maintenance patterns.

FreeUnreviewedSigmamediumv1
title: Linux chmod Process Creation Targeting Sensitive Directory Paths
id: 644a08e4-f8e6-48a1-bafa-cfee4e744654
status: test
description: This rule identifies Linux process executions of chmod where the command line targets files under sensitive-looking directories such as /tmp/, /.Library/, /etc/, and /opt/. Changing permissions in these locations can help attackers persist, escalate access, or impair system behavior by altering how other components read or execute files. It relies on process creation telemetry including the executable path ending in /chmod and the full command line content.
references:
  - https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
  - https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chmod_targeting_sensitive_directories.yml
author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule Team
date: 2022-06-03
modified: 2026-03-18
tags:
  - attack.defense-impairment
  - attack.t1222.002
logsource:
  product: linux
  category: process_creation
detection:
  selection:
    Image|endswith: /chmod
    CommandLine|contains:
      - /tmp/
      - /.Library/
      - /etc/
      - /opt/
  filter_main_update_shells:
    CommandLine|contains: chmod --reference=/etc/shells
    ParentCommandLine|endswith: /update-shells
  filter_main_postinst:
    CommandLine|contains: /etc/
    ParentCommandLine|contains|all:
      - /var/lib/dpkg/info/
      - .postinst configure
  filter_main_apt_key:
    CommandLine|startswith: chmod 700 /tmp/apt-key-gpghome.
  filter_main_mkinitramfs:
    CommandLine|startswith: chmod 755 /var/tmp/mkinitramfs
  filter_main_landscape:
    CommandLine: chmod 0775 /etc/landscape/
  filter_main_ubuntu_apparmor:
    CommandLine: chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu
  condition: selection and not 1 of filter_main_*
falsepositives:
  - Some false positives are to be expected. Apply additional filters as needed before pushing to production.
level: medium
license: DRL-1.1
related:
  - id: 6419afd1-3742-47a5-a7e6-b50386cd15f8
    type: derived

What it detects

This rule identifies Linux process executions of chmod where the command line targets files under sensitive-looking directories such as /tmp/, /.Library/, /etc/, and /opt/. Changing permissions in these locations can help attackers persist, escalate access, or impair system behavior by altering how other components read or execute files. It relies on process creation telemetry including the executable path ending in /chmod and the full command line content.

Known false positives

  • Some false positives are to be expected. Apply additional filters as needed before pushing to production.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.