T1222 icacls/takeown or chmod/chown Weakening AV-EDR Directory Permissions

This rule detects attempts to modify file or directory permissions (e.g., using icacls, takeown, chmod, or chown) on paths associated with known security products. Such activity is often indicative of an adversary attempting to tamper with, disable, or exclude security tools from logging or inspection.