1200KM / detection
T1222.002 Linux and Mac Permissions — Detection Rules
Detection workspace for T1222.002 Linux and Mac Permissions: 4 Sigma sources, 0 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Remove Immutable File Attribute - Auditd · test · medium · {"product":"linux","service":"auditd"}
- File or Folder Permissions Change · test · low · {"product":"linux","service":"auditd"}
- Remove Immutable File Attribute · test · medium · {"product":"linux","category":"process_creation"}
- Chmod Targeting Sensitive Directories · test · medium · {"product":"linux","category":"process_creation"}
Atlas deterministic concepts
No exact concept selected.
Anomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0351 Unix-like File Permission Manipulation Behavioral Chain Detection Strategy
AN0998 Analytic 0998
Linux permission escalation behavioral chain: (1) Process creation of permission modification utilities (chmod, chown, chgrp, setfacl) with suspicious parameters indicating privilege escalation intent, (2) System call analysis revealing direct file metadata manipulation (chmod, fchmod, chown, fchown syscalls), (3) Extended attribute and ACL modifications targeting critical system paths, (4) Temporal correlation with subsequent file access or process execution from modified locations, (5) Anomalous permission patterns deviating from system baselines
AN0999 Analytic 0999
macOS permission and attribute manipulation behavioral chain: (1) Process execution of permission utilities (chmod, chown, chgrp) or macOS-specific tools (chflags) with suspicious parameters, (2) System Integrity Protection (SIP) bypass attempts through permission modifications, (3) File flags manipulation (uchg, schg, hidden) for evasion or persistence, (4) Extended attribute (xattr) modifications affecting security metadata, (5) Unified log correlation with file system events and subsequent access patterns, (6) Gatekeeper and code signing bypass through permission/attribute manipulation
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1222.002 simulation workspace
No reviewed association in this snapshot.
Threat actor context
These are explicit actor-to-technique associations in the existing Threat Matrix snapshot, not attribution of an event or proof that a detector identifies the actor. No tool-to-actor relationship is inferred.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.