PowerShell Set-Acl Script Execution Changes File or Folder Permissions on Windows

Flags PowerShell commands using Set-Acl (-AclObject and -Path) to alter Windows file or folder permissions.

FreeReviewedSigma · High · v1
Product
windows
Category
process_creation
Author
Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2022-10-18
Updated
2026-07-30

What it detects

This rule identifies PowerShell process executions that include the Set-Acl cmdlet with -AclObject and -Path parameters, indicating an attempt to modify file or folder permissions. Changing ACLs can help attackers gain or maintain access while blending in with legitimate administrative activity. Telemetry relies on Windows process creation events capturing the executable name and full PowerShell command line.

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.