icacls/cacls Permission Modification on Sensitive Directories (T1222.001)
Detects the use of icacls.exe or cacls.exe to modify access control lists (ACLs) on sensitive Windows system directories and files. The rule specifically alerts when these commands are executed by non-Microsoft signed processes, which is a common indicator of unauthorized privilege escalation or persistence mechanisms.
SentinelOne

