LoFP LoFP / user interacting with files permissions (normal/daily behaviour).

Techniques

Sample rules

File or Folder Permissions Change

Description

Detects file and folder permission changes.

Detection logic

condition: selection
selection:
  a0|contains:
  - chmod
  - chown
  type: EXECVE