Rule Info
Name
Linux Setuid Capability Set on a Binary via Setcap Utility
Author
Luc Génaux
Description
Detects the use of the 'setcap' utility to set the 'setuid' capability (cap_setuid) on a binary file.
This capability allows a non privileged process to make arbitrary manipulations of user IDs (UIDs), including setting its current UID to a value that would otherwise be restricted (i.e. UID 0, the root user).
This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.
Date
2026-01-24 00:00:00
Modified
None
Id
ed447910-bc30-4575-a598-3a2e49516a7a
Tags
attack.privilege-escalation attack.defense-evasion attack.persistence attack.t1548 attack.t1554
Type
Community Rule
Link to Public Repo
Rule History
Author
Title
Date
Commit
