LoFP LoFP / administrator interacting with immutable files (e.g. for instance backups).

Techniques

Sample rules

Remove Immutable File Attribute - Auditd

Description

Detects removing immutable file attribute.

Detection logic

condition: selection
selection:
  a0|contains: chattr
  a1|contains: -i
  type: EXECVE

Remove Immutable File Attribute

Description

Detects usage of the ‘chattr’ utility to remove immutable file attribute.

Detection logic

condition: selection
selection:
  CommandLine|contains: ' -i '
  Image|endswith: /chattr