Linux chmod Process Commandlines Targeting Sensitive Directory Paths
Flags Linux chmod commands that modify permissions for paths under /tmp/, /.Library/, /etc/, or /opt/, excluding several known benign package-maintenance patterns.
- Product
- linux
- Category
- process_creation
- Author
- Christopher Peacock @SecurePeacock, SCYTHE @scythe_io (SigmaHQ), DRL 1.1
- Published
- 2022-06-03
- Updated
- 2026-07-31
ATT&CK techniques
Defense EvasionRecon
Resource Dev
Initial Access
Execution
Persistence
Priv Esc
Defense Evasion
Cred Access
Discovery
Lateral Movement
Collection
C2
Exfiltration
Impact
What it detects
This rule flags Linux process executions where the command line contains specific sensitive directory paths and the executable path ends with '/chmod'. Changing permissions in locations such as /etc, /opt, and /tmp can help attackers persist, escalate, or disrupt system behavior. It relies on Linux process creation telemetry that includes the process image path and full command line, with exclusions for several known benign chmod use cases.
Reporting behind it
- intezer.comhttps://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
- github.comhttps://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
- github.comhttps://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chmod_targeting_sensitive_directories.yml
Changelog
v3- v3Candidate ingested via manual entry.2026-07-31
- v2Candidate ingested via manual entry.2026-07-31
- v1No changelog recorded for this version.2026-07-30
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.
title: Linux chmod Process Commandlines Targeting Sensitive Directory Paths
id: 644a08e4-f8e6-48a1-bafa-cfee4e744654
status: test
description: This rule flags Linux process executions where the command line contains specific sensitive directory paths and the executable path ends with '/chmod'. Changing permissions in locations such as /etc, /opt, and /tmp can help attackers persist, escalate, or disrupt system behavior. It relies on Linux process creation telemetry that includes the process image path and full command line, with exclusions for several known benign chmod use cases.
references:
- https://www.intezer.com/blog/malware-analysis/new-backdoor-sysjoker/
- https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1222.002/T1222.002.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/linux/process_creation/proc_creation_lnx_chmod_targeting_sensitive_directories.yml
author: Christopher Peacock @SecurePeacock, SCYTHE @scythe_io, Huntrule Team
date: 2022-06-03
modified: 2026-03-18
tags:
- attack.defense-impairment
- attack.t1222.002
logsource:
product: linux
category: process_creation
detection:
selection:
Image|endswith: /chmod
CommandLine|contains:
- /tmp/
- /.Library/
- /etc/
- /opt/
filter_main_update_shells:
CommandLine|contains: chmod --reference=/etc/shells
ParentCommandLine|endswith: /update-shells
filter_main_postinst:
CommandLine|contains: /etc/
ParentCommandLine|contains|all:
- /var/lib/dpkg/info/
- .postinst configure
filter_main_apt_key:
CommandLine|startswith: chmod 700 /tmp/apt-key-gpghome.
filter_main_mkinitramfs:
CommandLine|startswith: chmod 755 /var/tmp/mkinitramfs
filter_main_landscape:
CommandLine: chmod 0775 /etc/landscape/
filter_main_ubuntu_apparmor:
CommandLine: chmod 644 /etc/apparmor.d/tunables/home.d/ubuntu
condition: selection and not 1 of filter_main_*
falsepositives:
- Some false positives are to be expected. Apply additional filters as needed before pushing to production.
level: medium
license: DRL-1.1
related:
- id: 6419afd1-3742-47a5-a7e6-b50386cd15f8
type: derived