PowerShell Set-Acl targeting Windows folder paths on Windows

Flags PowerShell Set-Acl commands that modify ACLs for Windows folder paths, often using FullControl/Allow.

FreeUnreviewedSigmahighv1
title: PowerShell Set-Acl targeting Windows folder paths on Windows
id: add86be3-355a-4cbf-922b-a83150d2f377
related:
  - id: cae80281-ef23-44c5-873b-fd48d2666f49
    type: derived
  - id: bdeb2cff-af74-4094-8426-724dc937f20a
    type: derived
  - id: 3bf1d859-3a7e-44cb-8809-a99e066d3478
    type: derived
  - id: 0944e002-e3f6-4eb5-bf69-3a3067b53d73
    type: derived
status: test
description: This rule identifies PowerShell process executions that invoke the Set-Acl cmdlet and include Windows folder path targets (e.g., C:\Windows or %windir%). It also requires ACL-related parameters such as -AclObject and common permission strings like FullControl and Allow, which can indicate stealthy attempts to weaken or modify access controls. The detection relies on process creation telemetry capturing the PowerShell executable and command line arguments.
references:
  - https://learn.microsoft.com/en-us/powershell/module/microsoft.powershell.security/set-acl?view=powershell-5.1
  - https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1505.005/T1505.005.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/process_creation/proc_creation_win_powershell_set_acl_susp_location.yml
author: Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2022-10-18
tags:
  - attack.stealth
logsource:
  category: process_creation
  product: windows
detection:
  selection_img:
    - OriginalFileName:
        - PowerShell.EXE
        - pwsh.dll
    - Image|endswith:
        - \powershell.exe
        - \pwsh.exe
  selection_cmdlet:
    CommandLine|contains|all:
      - "Set-Acl "
      - "-AclObject "
  selection_paths:
    CommandLine|contains:
      - -Path "C:\Windows
      - -Path 'C:\Windows
      - -Path %windir%
      - -Path $env:windir
  selection_permissions:
    CommandLine|contains:
      - FullControl
      - Allow
  condition: all of selection_*
falsepositives:
  - Unknown
level: high
license: DRL-1.1

What it detects

This rule identifies PowerShell process executions that invoke the Set-Acl cmdlet and include Windows folder path targets (e.g., C:\Windows or %windir%). It also requires ACL-related parameters such as -AclObject and common permission strings like FullControl and Allow, which can indicate stealthy attempts to weaken or modify access controls. The detection relies on process creation telemetry capturing the PowerShell executable and command line arguments.

Known false positives

  • Unknown

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.