1200KM / simulation
T1222 File and Directory Permissions Modification — Attack Simulation
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).…
Technique description
Adversaries may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Enable Local and Remote Symbolic Links via fsutil
Procedure 6c4ac96f-d4fa-44f4-83ca-56d8f4a55c02; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enable Local and Remote Symbolic Links via Powershell
Procedure 6cd715aa-20ac-4be1-a8f1-dda7bae160bd; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Enable Local and Remote Symbolic Links via reg.exe
Procedure 78bef0d4-57fb-417d-a67a-b75ae02ea3ab; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.