1200KM / detection
T1222 File and Directory Permissions Modification — Detection Rules
Detection workspace for T1222 File and Directory Permissions Modification: 2 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- PowerShell Script Change Permission Via Set-Acl - PsScript · test · low · {"product":"windows","category":"ps_script","definition":"bade5735-5ab0-4aa7-a642-a11be0e40872"}
- PowerShell Set-Acl On Windows Folder - PsScript · test · high · {"product":"windows","category":"ps_script","definition":"bade5735-5ab0-4aa7-a642-a11be0e40872"}
Atlas deterministic concepts
T1222 File and Directory Permissions Modification
MATCH(permission_or_owner_change_on_protected_path) AND actor NOT_IN approved_admins -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0299 Multi-Platform File and Directory Permissions Modification Detection Strategy
AN0834 Analytic 0834
Sequential behavioral chain of privilege escalation through permission modification: (1) Process creation of permission-modifying utilities (icacls, takeown, attrib, cacls), (2) Correlation with unusual user context or timing, (3) DACL modification events targeting sensitive files/directories, (4) Subsequent file access or modification attempts indicating successful privilege bypass
AN0835 Analytic 0835
Behavioral sequence of unauthorized privilege escalation via permission modification: (1) chmod/chown/setfacl process execution with suspicious parameters, (2) Targeting of critical system files or unusual permission values, (3) Correlation with non-privileged user context or unusual timing patterns, (4) Follow-on file access indicating successful permission bypass
AN0836 Analytic 0836
macOS-specific permission modification behavioral chain: (1) chmod/chown/chflags process execution, (2) System Integrity Protection (SIP) bypass attempts, (3) Extended attribute (xattr) modifications, (4) Unified log correlation with file system events, (5) Subsequent access to previously restricted resources
AN0837 Analytic 0837
ESXi hypervisor permission modification behavioral chain: (1) SSH access to ESXi host, (2) chmod/chown execution on VMFS datastore files or system configuration, (3) Modification of VM configuration files (.vmx) or virtual disk permissions, (4) Hostd service log correlation, (5) vCenter permission change events if centrally managed
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
- Active Directory Object Modification · DC0066
- Command Execution · DC0064
- File Creation · DC0039
- File Metadata · DC0059
- Process Creation · DC0032
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.