File Permission Modification in Writable Directory

edit
IMPORTANT: This documentation is no longer updated. Refer to Elastic's version policy and the latest documentation.

File Permission Modification in Writable Directory

edit

Identifies file permission modifications in common writable directories by a non-root user. Adversaries often drop files or payloads into a writable directory, and change permissions prior to execution.

Rule type: query

Rule indices:

  • auditbeat-*

Severity: low

Risk score: 21

Runs every: 5 minutes

Searches indices from: now-6m (Date Math format, see also Additional look-back time)

Maximum signals per execution: 100

Tags:

  • Elastic
  • Linux

Version: 1

Added (Elastic Stack release): 7.8.0

Potential false positives

edit

Certain programs or applications may modify files or change ownership in writable directories. These can be exempted by username.

Rule query

edit
event.action:executed and process.name:(chmod or chown or chattr or
chgrp) and process.working_directory:(/tmp or /var/tmp or /dev/shm)
and not user.name:root

Threat mapping

edit

Framework: MITRE ATT&CKTM