System File Modification
This rule flags an AI coding or automation agent when it writes or overwrites files in sensitive system locations like /etc/ or /usr/local/bin/. It catches this whether done through shell redirect commands or through the agent's own file-editing tools.
How the attack works
An attacker with control over an AI agent's prompts or tasks directs it to modify files outside normal project directories. This can happen via a Bash command using redirect operators (like `>` or `>>`) targeting a system path, or via the agent's built-in Write/Edit tool pointed at a system file path. The goal is usually to plant a malicious binary, alter startup or configuration files, or gain persistence on the host. A companion rule covers the same behavior when it happens at the EDR/OS level rather than through the agent's own logged actions.
Netzilo detection
Netzilo can block this behaviour when it is observed.
- Signature ID
- 89404989-df81-5ae1-9b23-d9e845e9be65
- Severity
- Critical
Why it matters
Successful modification of system directories can let an attacker achieve persistence, escalate privileges, or break system integrity — effects that outlast the current agent session and are harder to trace back to the agent.
What you can do
- →Restrict the AI agent's file-system permissions so it cannot write outside designated project or workspace directories.
- →Review any agent activity that touches /etc/, /usr/local/bin/, or similar system paths, especially outside known install/update workflows.
- →Require human approval for agent actions that write to system directories rather than allowing fully autonomous execution.
- →Exclude known package manager and configuration management processes from alerts, but still log and periodically audit their writes.
Known benign look-alikes
- Package managers writing to /etc/ or /usr/local/bin/ during legitimate installation
- System configuration management tools updating /etc/ files