File and Directory Permission Modification: Windows File and Directory Permissions Modification

ID Name
ATAGS-T1095.001 Linux and Mac File and Directory Permissions Modification
ATAGS-T1095.002 Windows File and Directory Permissions Modification

Threat Actors may modify file or directory permissions/attributes to evade access control lists (ACLs) and access protected files. File and directory permissions are commonly managed by ACLs configured by the file or directory owner, or users with the appropriate permissions. File and directory ACL implementations vary by platform, but generally explicitly designate which users or groups can perform which actions (read, write, execute, etc.).

ID: ATAGS-T1095.002
Sub-technique of:  ATAGS-T1095
Tactic: Defense Evasion
Targeted Components: Software
Responsibility: Provider
Created: 18 April 2026
Last Modified: 18 April 2026

Mitigations

This type of attack technique cannot be easily mitigated with preventive controls since it is based on the abuse of system features.