data:image/s3,"s3://crabby-images/800bd/800bddfb2db1a4e8d8cfa9840e3bb0570d873fd0" alt="File permissions"
Some times, when you analysis dynamically a malware sample and this created files and then deleted them, disable the permissions for delete files in one specific folder could be useful.
Ok, I know, you might be thinking “a sandbox can do that”, but there are times when you need to run the sample manually (because you need a special configuration to run the sample, because you need to interact with it, etc). In this scenario this procedure can be useful.
Right clic on the folder, then “properties”.
data:image/s3,"s3://crabby-images/56b7c/56b7c6813dc5c423f37147a6b15eba7b9936af99" alt=""
Then go to “Security” tab and clic on “Advanced”.
data:image/s3,"s3://crabby-images/9de1f/9de1f6be41378d7aa7f0bcd01efc616ece95dd96" alt=""
After that, clic on “Disable inheritance”.
data:image/s3,"s3://crabby-images/5171e/5171e9cd14df97485c33659ccc4f2f5e9932489b" alt=""
Next, clic on “Convert inherited permissions into explicit permissions on this object”
data:image/s3,"s3://crabby-images/6f391/6f391335ab6817448f9a84ebf7efdff5c2a29a13" alt=""
After that, select a user and clic on “Edit” button.
data:image/s3,"s3://crabby-images/17152/17152b454efd75a41fc6f24af817f934703ad285" alt=""
Select “Show advanced permissions”.
data:image/s3,"s3://crabby-images/d560a/d560a60e30187f67eeef1a38ce4f8c300bf87940" alt=""
Finally, deselect the permissions “Delete subfolders and files” and “Delete”.
data:image/s3,"s3://crabby-images/ad0de/ad0deed6679d65877517e5590b904c48498657cd" alt=""