Analytics BIOC Informational

Adding execution privileges

A script was granted execution privileges using chmod before being run.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Execution (TA0002)
ATT&CK techniques: Command and Scripting Interpreter: Unix Shell (T1059.004)
Detector tags: Kubernetes - AGENT Containers
Attacker's goals:

Attackers may use chmod to grant execution privileges to scripts or binaries for malicious execution.

Investigative actions:

Verify that this activity is not part of normal IT operations. Check for similar commands executed on other hosts.

Test period:
N/A (single event)
Deduplication:
1 Day
1 variation:
  • Adding execution privileges in a Kubernetes pod Informational