PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.
FreeUnreviewedSigmahighv1
powershell-set-acl-script-execution-changes-file-or-folder-permissions-on-window-bdeb2cff
title: PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows
id: 34574846-2270-4e4a-bf4b-5fb7b60cf046
related:
- id: cae80281-ef23-44c5-873b-fd48d2666f49
type: derived
- id: 0944e002-e3f6-4eb5-bf69-3a3067b53d73
type: derived
- id: 3bf1d859-3a7e-44cb-8809-a99e066d3478
type: derived
- id: bdeb2cff-af74-4094-8426-724dc937f20a
type: derived
status: test
description: This rule identifies PowerShell process executions that include the Set-Acl cmdlet with -AclObject and -Path parameters, indicating an attempt to modify file or folder permissions. Changing ACLs can help attackers gain or maintain access while blending in with legitimate administrative activity. Telemetry relies on Windows process creation events capturing the executable name and full PowerShell command line.
references:
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-acl?view=powershell-5.1
- https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1505.005/T1505.005.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_acl.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-10-18
tags:
- attack.stealth
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName:
- PowerShell.EXE
- pwsh.dll
- Image|endswith:
- \powershell.exe
- \pwsh.exe
selection_cmdlet:
CommandLine|contains|all:
- "Set-Acl "
- "-AclObject "
- "-Path "
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule identifies PowerShell process executions that include the Set-Acl cmdlet with -AclObject and -Path parameters, indicating an attempt to modify file or folder permissions. Changing ACLs can help attackers gain or maintain access while blending in with legitimate administrative activity. Telemetry relies on Windows process creation events capturing the executable name and full PowerShell command line.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.