Windows PowerShell Script Modifies File Permissions with Set-Acl

Flags PowerShell scripts that call Set-Acl to change ACL permissions on a specified path.

FreeReviewedSigma · Low · v2
Product
windows
Category
ps_script
Author
frack113, Nasreddine Bencherchali (Nextron Systems) (SigmaHQ), DRL 1.1
Published
2023-07-18
Updated
2026-07-31
title: Windows PowerShell Script Modifies File Permissions with Set-Acl
id: b7dc076d-69af-4a5d-a768-d2150b93fa27
related:
  - id: 0944e002-e3f6-4eb5-bf69-3a3067b53d73
    type: derived
  - id: bdeb2cff-af74-4094-8426-724dc937f20a
    type: derived
  - id: 3bf1d859-3a7e-44cb-8809-a99e066d3478
    type: derived
  - id: cae80281-ef23-44c5-873b-fd48d2666f49
    type: derived
status: test
description: This rule identifies PowerShell script content that invokes Set-Acl to change permissions on a specified path. Attackers may use ACL changes to impair defenses, control access, or persist by altering who can read, write, or execute files and folders. It relies on PowerShell script block telemetry capturing ScriptBlockText that contains the Set-Acl call parameters.
references:
  - https://github.com/redcanaryco/atomic-red-team/blob/74438b0237d141ee9c99747976447dc884cb1a39/atomics/T1505.005/T1505.005.md
  - https://github.com/SigmaHQ/sigma/blob/master/rules/windows/powershell/powershell_script/posh_ps_set_acl.yml
author: frack113, Nasreddine Bencherchali (Nextron Systems), Huntrule Team
date: 2023-07-18
tags:
  - attack.defense-impairment
  - attack.t1222
logsource:
  product: windows
  category: ps_script
  definition: bade5735-5ab0-4aa7-a642-a11be0e40872
detection:
  selection:
    ScriptBlockText|contains|all:
      - "Set-Acl "
      - "-AclObject "
      - "-Path "
  condition: selection
falsepositives:
  - Unknown
level: low
license: DRL-1.1