A security-focused guide to chattr and lsattr — covering the immutable file attribute, protecting critical configuration files against root-level modification, detecting attackers' use of chattr for persistence, and the limitations of immutability as a security control.
What is chattr?
The chattr command changes extended attributes on Linux filesystem files — most importantly the immutable flag (+i). A file with the immutable attribute set cannot be modified, deleted, renamed, or have its permissions changed by any user — including root — without first removing the immutable flag. This provides a meaningful protection layer for critical configuration files: even if an attacker gains root access, they cannot modify an immutable file without an explicit additional step that will be visible in audit logs. The companion command lsattr displays current file attributes, revealing whether the immutable flag is set or — critically — whether an attacker has used chattr to protect their own persistence files from deletion.
Syntax
chattr +i filename # Set immutable flag
chattr -i filename # Remove immutable flag
chattr +i -R /etc/ssh/ # Recursively set immutable
lsattr filename # Show file attributes
lsattr -R /etc/ | grep '\-i-' # Find all immutable files in /etcchattr +attribute adds an attribute, chattr -attribute removes it. The -R flag applies changes recursively. Key attributes: i (immutable — cannot be modified or deleted), a (append-only — can only be appended to, not overwritten), e (extents — informational, set by default on ext4 files). lsattr displays attributes as a string of flags.
Key Attributes and Flags
| Flag / Parameter | Description | Security Note |
|---|---|---|
+i (immutable) | File cannot be modified, deleted, renamed, or hard-linked. No process, including root, can bypass this without removing the flag first. | Best applied to /etc/passwd, /etc/shadow, /etc/sudoers, /etc/crontab, /etc/ssh/sshd_config |
-i | Remove the immutable flag — required before any modification, including package updates | An attacker removing +i from a file before modifying it will leave a ctime change as evidence |
+a (append-only) | File can only be appended to — existing content cannot be modified or deleted | Use on log files to prevent retroactive tampering — ensures log entries can be added but not removed |
-R | Apply attribute change recursively to all files in a directory | Use carefully — immutable directories also prevent file creation within them |
lsattr | List current extended attributes of files | Run lsattr on /tmp, /var/tmp, /dev/shm during incident response — attackers use +i on their malware files to prevent deletion |
Common Use Cases
Set Immutable Flag on /etc/passwd to Prevent Unauthorized Modification
The /etc/passwd file contains user account information. An attacker who gains root can add a backdoor account by appending a line. Making it immutable adds a required additional step that will be logged by the audit subsystem and may not be performed by automated attack tools.
# Set immutable on critical account files
chattr +i /etc/passwd /etc/shadow /etc/gshadow /etc/group
# Verify
lsattr /etc/passwd /etc/shadow
# Before any legitimate modification (e.g., useradd), remove first
chattr -i /etc/passwd
useradd newuser
chattr +i /etc/passwdProtect SSH Configuration and Authorized Keys
An attacker who gains root often modifies /etc/ssh/sshd_config to weaken security (re-enable root login, permit all users) or adds an entry to ~root/.ssh/authorized_keys for persistent key-based access. Making these immutable forces an explicit additional step that can be detected via audit logs.
chattr +i /etc/ssh/sshd_config
chattr +i /root/.ssh/authorized_keys 2>/dev/null
lsattr /etc/ssh/sshd_configDetect Attacker-Set Immutable Attributes on Malware Files
Attackers frequently use chattr +i on their dropped files to prevent security tools and administrators from deleting them. Running lsattr on known attacker staging directories reveals files protected this way. The immutable flag must be removed before the file can be deleted.
# Check for immutable files in attacker staging areas
lsattr /tmp/ 2>/dev/null
lsattr /dev/shm/ 2>/dev/null
lsattr /var/tmp/ 2>/dev/null
# Remove and delete if confirmed malicious
chattr -i /tmp/suspicious_file
rm /tmp/suspicious_fileSecurity Relevance: Immutability as a Speed Bump, Not a Wall
The immutable attribute provides meaningful but not absolute protection. An attacker with root access can simply run chattr -i to remove the flag before modifying the file. The security value is: (1) it blocks automated attack tools that do not include chattr steps in their exploitation scripts; (2) removing the immutable flag generates a ctime change on the file, which AIDE or auditd can detect; (3) it adds friction to the attack workflow, increasing the chance of detection. Think of it as one layer in a defense-in-depth stack, not a standalone solution. For maximum effectiveness, combine chattr +i on critical files with auditd rules monitoring those files — any attempt to remove the flag will generate an audit event regardless of whether the modification succeeded.
- chattr +i does NOT protect against an attacker who knows to run chattr -i first — it only adds friction
- Immutable directories also block file creation within them — do not apply +i to directories like /etc unless all expected file creation is complete
- Package managers cannot update immutable files — remove +i before running apt upgrade or yum update, then re-apply after
- The immutable attribute is filesystem-specific — it works on ext2/ext3/ext4/btrfs but may not be supported on all filesystem types (notably not on FAT or NTFS)
- An attacker who has kernel-level access (rootkit, eBPF programs) can bypass filesystem-level attributes entirely
Practical Examples
Harden a new server by setting immutable on core configuration files
# Apply to the most critical files
for f in /etc/passwd /etc/shadow /etc/gshadow /etc/group \
/etc/sudoers /etc/crontab /etc/hosts \
/etc/ssh/sshd_config /etc/fstab; do
[ -f "$f" ] && chattr +i "$f" && echo "Protected: $f"
done
# Verify all
for f in /etc/passwd /etc/shadow /etc/sudoers /etc/ssh/sshd_config; do
echo -n "$f: "; lsattr "$f" 2>/dev/null
doneIterates over the most security-critical configuration files and sets the immutable flag on each. The loop skips files that do not exist (graceful for varying distributions). Verify immediately after — lsattr output should show ‘—-i———–‘ for each protected file.
Make log files append-only to prevent retroactive tampering
chattr +a /var/log/auth.log
chattr +a /var/log/syslog
chattr +a /var/log/secure
lsattr /var/log/auth.log /var/log/syslogThe append-only attribute allows the log daemon to write new entries but prevents any process — including root — from truncating or overwriting existing content. This protects the authentication audit trail from retroactive clearing while still allowing normal log rotation (which typically renames rather than overwrites).
List all files with immutable or append-only attributes system-wide
lsattr -R / 2>/dev/null | grep -E ' ----i|----a'Scans the entire filesystem for files with immutable or append-only attributes. During incident response, this reveals two things: your own hardening controls (expected), and any files an attacker has protected with chattr to prevent deletion (unexpected, especially in /tmp, /dev/shm, or application directories).
Troubleshooting Common Issues
Problem: Cannot modify or delete a file even as root
Solution: The file likely has the immutable attribute set. Check with lsattr filename. If the ‘i’ flag appears, remove it with chattr -i filename before proceeding with your modification. This is the expected behavior — the attribute is working as designed.
Problem: Package update fails with 'cannot overwrite file' or permission errors on a specific file
Solution: The file being updated has the immutable flag set. Remove it temporarily: chattr -i /path/to/file, run the update, then reapply: chattr +i /path/to/file. For automated updates, consider adding a pre/post apt hook that toggles immutability on a defined list of protected files.
Problem: chattr: Operation not supported on a specific filesystem
Solution: The filesystem may not support extended attributes. Verify the filesystem type with df -T /path/to/file. chattr requires ext2/ext3/ext4 or similar. It is not supported on tmpfs (/tmp if mounted as tmpfs), NFS, or FAT filesystems. BTRFS has partial support.
Summary
The chattr +i command adds the immutable attribute to files, requiring an explicit additional step before any modification — even by root. It is a low-overhead hardening measure that blocks automated attack tools, adds friction to manual attacks, and creates detectable audit events when bypassed. Apply it to the most critical configuration files during initial server setup, combine it with auditd monitoring of those files, and periodically run lsattr on staging directories to detect attacker-applied immutability on malware files.
- Apply
chattr +ito/etc/passwd,/etc/sudoers,/etc/ssh/sshd_config, and cron files as a baseline hardening step - Check
/tmp,/dev/shm, and/var/tmpwithlsattrduring incident response — attackers use+ion malware files to prevent deletion - Immutability is a friction layer, not a security boundary — combine with auditd monitoring for detecting bypass attempts
Related Commands
aide for comprehensive file integrity monitoring • chmod for file permission management • ausearch for kernel audit of file modifications • find command for filesystem security audits
Are Your Critical Config Files Protected Against Root-Level Modification?
INTRAM applies immutable attributes to critical configuration files, monitors for bypass attempts via auditd, and maintains hardened filesystem baselines on all managed Linux servers.
Harden My Server Configuration