cacls.exe

  • File Path: C:\WINDOWS\SysWOW64\cacls.exe
  • Description: Control ACLs Program

Hashes

Type Hash
MD5 2D08255E636BF1C33D7F2857AA6F6239
SHA1 B4A12CF874A913D8261052393FCF518A27D8EB7C
SHA256 D8220A6F99E508DB0A293867B150BE2320D8057D02E56E254B6F44006E533523
SHA384 40344B298D54FBD07D615AD88517E481ADC94516FA594B0155A40656359E25CDE9D15A2A2670B1E59CF4F23A8965C4CB
SHA512 25B6CD1D34E410DFD91BB7EC8AB66E65A72D2FF9B9752FAA2FB6A8B722E322470CFFBE2CAF517BE3A2BF9CF2BE42ECB71C4D8CF96997B9F87C4388509B6FD5D0
SSDEEP 384:+SCr6mX4m0SNl4yO4a1yxH0K3E91w2R1NX+TEIOB2mi0JPGSNRdWzDWO/:UL4m7OX0xBE9CgJtJPGSm
IMP 29323867CDC9A8BC7E9164C47C4E0B13
PESHA1 8D166BDB3E1F59618C0F9058D3E204041E5D0EB2
PE256 E9B5CA35E7727AE7FE7DB8957C0E6D4AD38ACB2A3A7DA62231EF60C36CF1DB00

Runtime Data

Usage (stdout):


 NOTE: Cacls is now deprecated, please use Icacls.

 Displays or modifies access control lists (ACLs) of files

 CACLS filename [/T] [/M] [/L] [/S[:SDDL]] [/E] [/C] [/G user:perm]
        [/R user [...]] [/P user:perm [...]] [/D user [...]]
    filename      Displays ACLs.
    /T            Changes ACLs of specified files in
                  the current directory and all subdirectories.
    /L            Work on the Symbolic Link itself versus the target
    /M            Changes ACLs of volumes mounted to a directory
    /S            Displays the SDDL string for the DACL.
    /S:SDDL       Replaces the ACLs with those specified in the SDDL string
                  (not valid with /E, /G, /R, /P, or /D).
    /E            Edit ACL instead of replacing it.
    /C            Continue on access denied errors.
    /G user:perm  Grant specified user access rights.
                  Perm can be: R  Read
                               W  Write
                               C  Change (write)
                               F  Full control
    /R user       Revoke specified user's access rights (only valid with /E).
    /P user:perm  Replace specified user's access rights.
                  Perm can be: N  None
                               R  Read
                               W  Write
                               C  Change (write)
                               F  Full control
    /D user       Deny specified user access.
 Wildcards can be used to specify more than one file in a command.
 You can specify more than one user in a command.

 Abbreviations:
    CI - Container Inherit.
         The ACE will be inherited by directories.
    OI - Object Inherit.
         The ACE will be inherited by files.
    IO - Inherit Only.
         The ACE does not apply to the current file/directory.
    ID - Inherited.
         The ACE was inherited from the parent directory's ACL.

Usage (stderr):

The system cannot find the file specified.

Loaded Modules:

Path
C:\WINDOWS\SYSTEM32\ntdll.dll
C:\WINDOWS\System32\wow64.dll
C:\WINDOWS\System32\wow64base.dll
C:\WINDOWS\System32\wow64con.dll
C:\WINDOWS\System32\wow64cpu.dll
C:\WINDOWS\System32\wow64win.dll
C:\WINDOWS\SysWOW64\cacls.exe

Signature

  • Status: Signature verified.
  • Serial: 33000002ED2C45E4C145CF48440000000002ED
  • Thumbprint: 312860D2047EB81F8F58C29FF19ECDB4C634CF6A
  • Issuer: CN=Microsoft Windows Production PCA 2011, O=Microsoft Corporation, L=Redmond, S=Washington, C=US
  • Subject: CN=Microsoft Windows, O=Microsoft Corporation, L=Redmond, S=Washington, C=US

File Metadata

  • Original Filename: CACLS.EXE
  • Product Name: Microsoft Windows Operating System
  • Company Name: Microsoft Corporation
  • File Version: 10.0.22000.1 (WinBuild.160101.0800)
  • Product Version: 10.0.22000.1
  • Language: English (United States)
  • Legal Copyright: Microsoft Corporation. All rights reserved.
  • Machine Type: 32-bit

File Scan

  • VirusTotal Detections: 0/73
  • VirusTotal Link: https://www.virustotal.com/gui/file/d8220a6f99e508db0a293867b150be2320d8057d02e56e254b6f44006e533523/detection

Possible Misuse

The following table contains possible examples of cacls.exe being misused. While cacls.exe is not inherently malicious, its legitimate functionality can be abused for malicious purposes.

Source Source File Example License
sigma proc_creation_win_file_permission_modifications.yml - '\cacls.exe' DRL 1.0
sigma proc_creation_win_hiding_malware_in_fonts_folder.yml CommandLine\|re: '(?i).*(echo\|copy\|type\|file createnew\|cacls).*C:\\\\Windows\\\\Fonts\\\\.*(.sh\|.exe\|.dll\|.bin\|.bat\|.cmd\|.js\|.msh\|.reg\|.scr\|.ps\|.vb\|.jar\|.pl\|.inf\|.cpl\|.hta\|.msi\|.vbs).*' DRL 1.0
atomic-red-team index.md - Atomic Test #2: cacls - Grant permission to specified user or group recursively [windows] MIT License. © 2018 Red Canary
atomic-red-team windows-index.md - Atomic Test #2: cacls - Grant permission to specified user or group recursively [windows] MIT License. © 2018 Red Canary
atomic-red-team T1222.001.md Adversaries can interact with the DACLs using built-in Windows commands, such as icacls, cacls, takeown, and attrib, which can grant adversaries higher permissions on specific files and folders. Further, PowerShell provides cmdlets that can be used to retrieve or modify file and directory DACLs. Specific file and directory modifications may be a required step for many techniques, such as establishing Persistence via Accessibility Features, Boot or Logon Initialization Scripts, or tainting/hijacking other instrumental binary/configuration files via Hijack Execution Flow.</blockquote> MIT License. © 2018 Red Canary
atomic-red-team T1222.001.md - Atomic Test #2 - cacls - Grant permission to specified user or group recursively MIT License. © 2018 Red Canary
atomic-red-team T1222.001.md ## Atomic Test #2 - cacls - Grant permission to specified user or group recursively MIT License. © 2018 Red Canary
signature-base cn_pentestset_tools.yar $s1 = “cacls %s /t /c /e /r administrators” fullword ascii /* PEStudio Blacklist: strings */ CC BY-NC 4.0

Additional Info*

*The information below is copied from MicrosoftDocs, which is maintained by Microsoft. Available under CC BY 4.0 license.


cacls

[!IMPORTANT] This command has been deprecated. Please use icacls instead.

Displays or modifies discretionary access control lists (DACL) on specified files.

Syntax

cacls <filename> [/t] [/m] [/l] [/s[:sddl]] [/e] [/c] [/g user:<perm>] [/r user [...]] [/p user:<perm> [...]] [/d user [...]]

Parameters

Parameter Description
<filename> Required. Displays ACLs of specified files.
/t Changes ACLs of specified files in the current directory and all subdirectories.
/m Changes ACLs of volumes mounted to a directory.
/l Works on the Symbolic Link itself instead of the target.
/s:sddl Replaces the ACLs with those specified in the SDDL string. This parameter is not valid for use with the /e, /g, /r, /p, or /d parameters.
/e Edit an ACL instead of replacing it.
/c Continue after access denied errors.
/g user:<perm> Grants specified user access rights, including these valid values for permission:<ul><li>n - None</li><li>r - Read</li><li>w - Write</li><li>c - Change (write)</li><li>f - Full control</li></ul>
/r user […] Revoke specified user’s access rights. Only valid when used with the /e parameter.
[/p user:<perm> [...] Replace specified user’s access rights, including these valid values for permission:<ul><li>n - None</li><li>r - Read</li><li>w - Write</li><li>c - Change (write)</li><li>f - Full control</li></ul>
[/d user […] Deny specified user access.
/? Displays help at the command prompt.
Sample output
Output Access control entry (ACE) applies to
OI Object inherit. This folder and files.
CI Container inherit. This folder and subfolders.
IO Inherit only. The ACE does not apply to the current file/directory.
No output message This folder only.
(OI)(CI) This folder, subfolders, and files.
(OI)(CI)(IO) Subfolders and files only.
(CI)(IO) Subfolders only.
(OI)(IO) Files only.
Remarks
  • You can use wildcards (? and *) to specify multiple files.

  • You can specify more than one user.

Additional References


MIT License. Copyright (c) 2020-2021 Strontic.