PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows

Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.

FreeUnreviewedSigmahighv1
title: PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
id: 34574846-2270-4e4a-bf4b-5fb7b60cf046
related:
  - id: cae80281-ef23-44c5-873b-fd48d2666f49
    type: derived
  - id: 0944e002-e3f6-4eb5-bf69-3a3067b53d73
    type: derived
  - id: 3bf1d859-3a7e-44cb-8809-a99e066d3478
    type: derived
  - id: bdeb2cff-af74-4094-8426-724dc937f20a
    type: derived
status: test
description: This rule identifies PowerShell process executions that include the Set-Acl cmdlet with -AclObject and -Path parameters, indicating an attempt to modify file or folder permissions. Changing ACLs can help attackers gain or maintain access while blending in with legitimate administrative activity. Telemetry relies on Windows process creation events capturing the executable name and full PowerShell command line.
references:
  - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-acl?view=powershell-5.1
  - https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1505.005/T1505.005.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_acl.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-10-18
tags:
  - attack.stealth
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
  selection_cmdlet:
    CommandLine|contains|all:
      - "Set-Acl "
      - "-AclObject "
      - "-Path "
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies PowerShell process executions that include the Set-Acl cmdlet with -AclObject and -Path parameters, indicating an attempt to modify file or folder permissions. Changing ACLs can help attackers gain or maintain access while blending in with legitimate administrative activity. Telemetry relies on Windows process creation events capturing the executable name and full PowerShell command line.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.