LoFP LoFP / admin changing file permissions.

Techniques

Sample rules

Chmod Suspicious Directory

Description

Detects chmod targeting files in abnormal directory paths.

Detection logic

condition: selection
selection:
  CommandLine|contains:
  - /tmp/
  - /.Library/
  - /etc/
  - /opt/
  Image|endswith: /chmod