Skip to content

Hide Navigation Hide TOC

Linux Setgid Capability Set on a Binary via Setcap Utility (3a716279-c18c-4488-83be-f9ececbfb9fc)

Detects the use of the 'setcap' utility to set the 'setgid' capability (cap_setgid) on a binary file. This capability allows a non privileged process to make arbitrary manipulations of group IDs (GIDs), including setting its current GID to a value that would otherwise be restricted (i.e. GID 0, the root group). This behavior can be used by adversaries to backdoor a binary in order to escalate privileges again in the future if needed.

Cluster A Galaxy A Cluster B Galaxy B Level
Abuse Elevation Control Mechanism - T1548 (67720091-eee3-4d2d-ae16-8264567f6f5b) Attack Pattern Linux Setgid Capability Set on a Binary via Setcap Utility (3a716279-c18c-4488-83be-f9ececbfb9fc) Sigma-Rules 1
Compromise Host Software Binary - T1554 (960c3c86-1480-4d72-b4e0-8c242e84a5c5) Attack Pattern Linux Setgid Capability Set on a Binary via Setcap Utility (3a716279-c18c-4488-83be-f9ececbfb9fc) Sigma-Rules 1