A security-focused guide to chattr and lsattr — covering the immutable file attribute, protecting critical configuration files against root-level modification, detecting attackers' use of chattr for persistence, and the limitations of immutability as a security control.

What is chattr?

The chattr command changes extended attributes on Linux filesystem files — most importantly the immutable flag (+i). A file with the immutable attribute set cannot be modified, deleted, renamed, or have its permissions changed by any user — including root — without first removing the immutable flag. This provides a meaningful protection layer for critical configuration files: even if an attacker gains root access, they cannot modify an immutable file without an explicit additional step that will be visible in audit logs. The companion command lsattr displays current file attributes, revealing whether the immutable flag is set or — critically — whether an attacker has used chattr to protect their own persistence files from deletion.

Syntax

chattr +i filename          # Set immutable flag
chattr -i filename          # Remove immutable flag
chattr +i -R /etc/ssh/      # Recursively set immutable
lsattr filename             # Show file attributes
lsattr -R /etc/ | grep '\-i-'  # Find all immutable files in /etc

chattr +attribute adds an attribute, chattr -attribute removes it. The -R flag applies changes recursively. Key attributes: i (immutable — cannot be modified or deleted), a (append-only — can only be appended to, not overwritten), e (extents — informational, set by default on ext4 files). lsattr displays attributes as a string of flags.

Key Attributes and Flags

Flag / ParameterDescriptionSecurity Note
+i (immutable)File cannot be modified, deleted, renamed, or hard-linked. No process, including root, can bypass this without removing the flag first.Best applied to /etc/passwd, /etc/shadow, /etc/sudoers, /etc/crontab, /etc/ssh/sshd_config
-iRemove the immutable flag — required before any modification, including package updatesAn attacker removing +i from a file before modifying it will leave a ctime change as evidence
+a (append-only)File can only be appended to — existing content cannot be modified or deletedUse on log files to prevent retroactive tampering — ensures log entries can be added but not removed
-RApply attribute change recursively to all files in a directoryUse carefully — immutable directories also prevent file creation within them
lsattrList current extended attributes of filesRun lsattr on /tmp, /var/tmp, /dev/shm during incident response — attackers use +i on their malware files to prevent deletion

Common Use Cases

Set Immutable Flag on /etc/passwd to Prevent Unauthorized Modification

The /etc/passwd file contains user account information. An attacker who gains root can add a backdoor account by appending a line. Making it immutable adds a required additional step that will be logged by the audit subsystem and may not be performed by automated attack tools.

# Set immutable on critical account files
chattr +i /etc/passwd /etc/shadow /etc/gshadow /etc/group

# Verify
lsattr /etc/passwd /etc/shadow

# Before any legitimate modification (e.g., useradd), remove first
chattr -i /etc/passwd
useradd newuser
chattr +i /etc/passwd

Protect SSH Configuration and Authorized Keys

An attacker who gains root often modifies /etc/ssh/sshd_config to weaken security (re-enable root login, permit all users) or adds an entry to ~root/.ssh/authorized_keys for persistent key-based access. Making these immutable forces an explicit additional step that can be detected via audit logs.

chattr +i /etc/ssh/sshd_config
chattr +i /root/.ssh/authorized_keys 2>/dev/null
lsattr /etc/ssh/sshd_config

Detect Attacker-Set Immutable Attributes on Malware Files

Attackers frequently use chattr +i on their dropped files to prevent security tools and administrators from deleting them. Running lsattr on known attacker staging directories reveals files protected this way. The immutable flag must be removed before the file can be deleted.

# Check for immutable files in attacker staging areas
lsattr /tmp/ 2>/dev/null
lsattr /dev/shm/ 2>/dev/null
lsattr /var/tmp/ 2>/dev/null

# Remove and delete if confirmed malicious
chattr -i /tmp/suspicious_file
rm /tmp/suspicious_file

Security Relevance: Immutability as a Speed Bump, Not a Wall

The immutable attribute provides meaningful but not absolute protection. An attacker with root access can simply run chattr -i to remove the flag before modifying the file. The security value is: (1) it blocks automated attack tools that do not include chattr steps in their exploitation scripts; (2) removing the immutable flag generates a ctime change on the file, which AIDE or auditd can detect; (3) it adds friction to the attack workflow, increasing the chance of detection. Think of it as one layer in a defense-in-depth stack, not a standalone solution. For maximum effectiveness, combine chattr +i on critical files with auditd rules monitoring those files — any attempt to remove the flag will generate an audit event regardless of whether the modification succeeded.

  • chattr +i does NOT protect against an attacker who knows to run chattr -i first — it only adds friction
  • Immutable directories also block file creation within them — do not apply +i to directories like /etc unless all expected file creation is complete
  • Package managers cannot update immutable files — remove +i before running apt upgrade or yum update, then re-apply after
  • The immutable attribute is filesystem-specific — it works on ext2/ext3/ext4/btrfs but may not be supported on all filesystem types (notably not on FAT or NTFS)
  • An attacker who has kernel-level access (rootkit, eBPF programs) can bypass filesystem-level attributes entirely

Practical Examples

Harden a new server by setting immutable on core configuration files

# Apply to the most critical files
for f in /etc/passwd /etc/shadow /etc/gshadow /etc/group \
         /etc/sudoers /etc/crontab /etc/hosts \
         /etc/ssh/sshd_config /etc/fstab; do
  [ -f "$f" ] && chattr +i "$f" && echo "Protected: $f"
done

# Verify all
for f in /etc/passwd /etc/shadow /etc/sudoers /etc/ssh/sshd_config; do
  echo -n "$f: "; lsattr "$f" 2>/dev/null
done

Iterates over the most security-critical configuration files and sets the immutable flag on each. The loop skips files that do not exist (graceful for varying distributions). Verify immediately after — lsattr output should show ‘—-i———–‘ for each protected file.

Make log files append-only to prevent retroactive tampering

chattr +a /var/log/auth.log
chattr +a /var/log/syslog
chattr +a /var/log/secure
lsattr /var/log/auth.log /var/log/syslog

The append-only attribute allows the log daemon to write new entries but prevents any process — including root — from truncating or overwriting existing content. This protects the authentication audit trail from retroactive clearing while still allowing normal log rotation (which typically renames rather than overwrites).

List all files with immutable or append-only attributes system-wide

lsattr -R / 2>/dev/null | grep -E ' ----i|----a'

Scans the entire filesystem for files with immutable or append-only attributes. During incident response, this reveals two things: your own hardening controls (expected), and any files an attacker has protected with chattr to prevent deletion (unexpected, especially in /tmp, /dev/shm, or application directories).

Troubleshooting Common Issues

Problem: Cannot modify or delete a file even as root

Solution: The file likely has the immutable attribute set. Check with lsattr filename. If the ‘i’ flag appears, remove it with chattr -i filename before proceeding with your modification. This is the expected behavior — the attribute is working as designed.

Problem: Package update fails with 'cannot overwrite file' or permission errors on a specific file

Solution: The file being updated has the immutable flag set. Remove it temporarily: chattr -i /path/to/file, run the update, then reapply: chattr +i /path/to/file. For automated updates, consider adding a pre/post apt hook that toggles immutability on a defined list of protected files.

Problem: chattr: Operation not supported on a specific filesystem

Solution: The filesystem may not support extended attributes. Verify the filesystem type with df -T /path/to/file. chattr requires ext2/ext3/ext4 or similar. It is not supported on tmpfs (/tmp if mounted as tmpfs), NFS, or FAT filesystems. BTRFS has partial support.

Summary

The chattr +i command adds the immutable attribute to files, requiring an explicit additional step before any modification — even by root. It is a low-overhead hardening measure that blocks automated attack tools, adds friction to manual attacks, and creates detectable audit events when bypassed. Apply it to the most critical configuration files during initial server setup, combine it with auditd monitoring of those files, and periodically run lsattr on staging directories to detect attacker-applied immutability on malware files.

  • Apply chattr +i to /etc/passwd, /etc/sudoers, /etc/ssh/sshd_config, and cron files as a baseline hardening step
  • Check /tmp, /dev/shm, and /var/tmp with lsattr during incident response — attackers use +i on malware files to prevent deletion
  • Immutability is a friction layer, not a security boundary — combine with auditd monitoring for detecting bypass attempts

Are Your Critical Config Files Protected Against Root-Level Modification?

INTRAM applies immutable attributes to critical configuration files, monitors for bypass attempts via auditd, and maintains hardened filesystem baselines on all managed Linux servers.

Harden My Server Configuration

Let’s assess what your business actually needs.

We will use these details only to understand your request and reply appropriately.