PowerShell Set-Acl targeting Windows folder paths on Windows
Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.
FreeUnreviewedSigmahighv1
powershell-set-acl-targeting-windows-folder-paths-on-windows-0944e002
title: PowerShell Set-Acl targeting Windows folder paths on Windows
id: add86be3-355a-4cbf-922b-a83150d2f377
related:
- id: cae80281-ef23-44c5-873b-fd48d2666f49
type: derived
- id: bdeb2cff-af74-4094-8426-724dc937f20a
type: derived
- id: 3bf1d859-3a7e-44cb-8809-a99e066d3478
type: derived
- id: 0944e002-e3f6-4eb5-bf69-3a3067b53d73
type: derived
status: test
description: This rule identifies PowerShell process executions that invoke the Set-Acl cmdlet and include Windows folder path targets (e.g., C:\Windows or %windir%). It also requires ACL-related parameters such as -AclObject and common permission strings like FullControl and Allow, which can indicate stealthy attempts to weaken or modify access controls. The detection relies on process creation telemetry capturing the PowerShell executable and command line arguments.
references:
- https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-acl?view=powershell-5.1
- https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1505.005/T1505.005.md
- https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_acl_susp_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-10-18
tags:
- attack.stealth
logsource:
category: process_creation
product: windows
detection:
selection_img:
- OriginalFileName:
- PowerShell.EXE
- pwsh.dll
- Image|endswith:
- \powershell.exe
- \pwsh.exe
selection_cmdlet:
CommandLine|contains|all:
- "Set-Acl "
- "-AclObject "
selection_paths:
CommandLine|contains:
- -Path "C:\Windows
- -Path 'C:\Windows
- -Path %windir%
- -Path $env:windir
selection_permissions:
CommandLine|contains:
- FullControl
- Allow
condition: all of selection_*
falsepositives:
- Unknown
level: high
license: DRL-1.1
What it detects
This rule identifies PowerShell process executions that invoke the Set-Acl cmdlet and include Windows folder path targets (e.g., C:\Windows or %windir%). It also requires ACL-related parameters such as -AclObject and common permission strings like FullControl and Allow, which can indicate stealthy attempts to weaken or modify access controls. The detection relies on process creation telemetry capturing the PowerShell executable and command line arguments.
Known false positives
- Unknown
Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.