LoFP LoFP / administrator interacting with immutable files (e.g. for instance backups).

Techniques

Sample rules

Remove Immutable File Attribute

Description

Detects usage of the ‘chattr’ utility to remove immutable file attribute.

Detection logic

condition: selection
selection:
  CommandLine|contains: ' -i '
  Image|endswith: /chattr

Remove Immutable File Attribute - Auditd

Description

Detects removing immutable file attribute.

Detection logic

condition: selection
selection:
  a0|contains: chattr
  a1|contains: -i
  type: EXECVE