Techniques
Sample rules
Chmod Suspicious Directory
- source: sigma
- technicques:
- t1222
- t1222.002
Description
Detects chmod targeting files in abnormal directory paths.
Detection logic
condition: selection
selection:
CommandLine|contains:
- /tmp/
- /.Library/
- /etc/
- /opt/
Image|endswith: /chmod