SUID/GUID permission discovery
Synopsis
Field
Value
Activation Period
14 Days
Training Period
30 Days
Test Period
N/A (single event)
Deduplication Period
1 Day
Required Data
XDR Agent
ATT&CK Tactic
Discovery (TA0007)
ATT&CK Technique
File and Directory Discovery (T1083)
Severity
Low
Description
Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled.
Attacker's Goals
Attackers may use GUID/SUID binaries to elevate privileges.
Investigative actions
Check whether additional malicious commands were executed from the same process.
Verify if the command-line seems suspicious or contains malicious indicators.
Was this helpful?
