Techniques
Sample rules
ESXi File Made Executable with chmod
- source: elastic
- technicques:
- T1222
Description
Detects chmod making a file executable on an ESXi host, including +x and numeric modes such as 755 and 777.
The host will not run a file until the execute bit is set. Making a file under /tmp executable is the step that
lets a later command launch it against the datastore.
Detection logic
data_stream.dataset:vsphere.log and event.module:vsphere and message:(chmod and ("+x" or 0511 or 0555 or 0700 or 0711 or 0750 or 0755 or 0775 or 0777 or 111 or 1777 or 4755 or 511 or 555 or 700 or 711 or 750 or 755 or 775 or 777 or "a+x" or "g+x" or "o+x" or "u+x"))