{"id":"T1548.001","name":"Setuid and Setgid","url":"https://attack.mitre.org/techniques/T1548/001","tactics":["privilege-escalation"],"platforms":["Linux","macOS"],"live":true,"revoked":false,"deprecated":false,"revoked_by":null,"detection_strategies":[{"id":"DET0110","stix_id":"x-mitre-detection-strategy--bc8cd246-1521-4643-a07e-428d45093b38","name":"Setuid/Setgid Privilege Abuse Detection (Linux/macOS)","url":"https://attack.mitre.org/detectionstrategies/DET0110","analytics":[{"id":"AN0307","stix_id":"x-mitre-analytic--c7d513f4-5113-4031-8125-7f145128c2e1","name":"Analytic 0307","description":"Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths.","url":"https://attack.mitre.org/detectionstrategies/DET0110#AN0307","platforms":["Linux"],"log_source_references":[{"name":"auditd:SYSCALL","channel":"chmod, execve","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"auditd-syscall"},{"name":"auditd:SYSCALL","channel":"execve","data_component":"DC0032","data_component_name":"Process Creation","log_source_slug":"auditd-syscall"}],"mutable_elements":[{"field":"UserContext","description":"Track execution of setuid binaries where UID != EUID or executed from unexpected user context"},{"field":"FilePathScope","description":"Restrict detection to non-standard locations (e.g., /tmp, /home/*, /var/tmp)"},{"field":"TimeWindow","description":"Time delta between chmod setting setuid/gid and process execution to define a suspicious window"}],"live":true,"detection_strategies":["DET0110"],"techniques":["T1548.001"]},{"id":"AN0308","stix_id":"x-mitre-analytic--08314a8b-becd-4853-8a6c-dd5a947b36c0","name":"Analytic 0308","description":"Observation of chmod commands setting setuid/setgid bits, paired with launch of binaries under elevated execution context (e.g., root-owned binaries launched by unprivileged users).","url":"https://attack.mitre.org/detectionstrategies/DET0110#AN0308","platforms":["macOS"],"log_source_references":[{"name":"macos:unifiedlog","channel":"chmod command with arguments including '+s', 'u+s', or numeric values 4000–6777","data_component":"DC0064","data_component_name":"Command Execution","log_source_slug":"macos-unifiedlog"},{"name":"macos:unifiedlog","channel":"exec of binary with setuid/setgid and EUID != UID","data_component":"DC0034","data_component_name":"Process Metadata","log_source_slug":"macos-unifiedlog"}],"mutable_elements":[{"field":"UserContext","description":"Monitor execution chains where UID != EUID or child process inherits root without known sudo context"},{"field":"ExecutionPath","description":"Focus on binaries in user-writable locations or abnormal directories"},{"field":"ChmodPattern","description":"Tailor detection to chmod commands that imply privilege elevation via numeric mode or symbolic mode"}],"live":true,"detection_strategies":["DET0110"],"techniques":["T1548.001"]}],"live":true,"version":"1.0","techniques":["T1548.001"]}],"sigma_rules":[{"id":"0506a799-698b-43b4-85a1-ac4c84c720e9","title":"PwnKit Local Privilege Escalation","author":"Sreeman","status":"test","level":"high","date":"2022-01-26","modified":"2024-09-11","description":"Detects potential PwnKit exploitation CVE-2021-4034 in auth logs","references":["https://twitter.com/wdormann/status/1486161836961579020"],"logsource":{"product":"linux","service":"auth"},"tags":["attack.privilege-escalation","attack.t1548.001","detection.emerging-threats","cve.2021-4034"],"path":"rules-emerging-threats/2021/Exploits/CVE-2021-4034/lnx_auth_exploit_cve_2021_4034_pwnkit_lpe.yml","techniques":["T1548.001"],"cves":["CVE-2021-4034"]},{"id":"c21c4eaa-ba2e-419a-92b2-8371703cbe21","title":"Setuid and Setgid","author":"Ömer Günal","status":"test","level":"low","date":"2020-06-16","modified":"2022-10-05","description":"Detects suspicious change of file privileges with chown and chmod commands","references":["https://github.com/redcanaryco/atomic-red-team/blob/f339e7da7d05f6057fdfcdd3742bfcf365fee2a9/atomics/T1548.001/T1548.001.md"],"logsource":{"product":"linux","category":"process_creation"},"tags":["attack.persistence","attack.privilege-escalation","attack.t1548.001"],"path":"rules/linux/process_creation/proc_creation_lnx_setgid_setuid.yml","techniques":["T1548.001"],"cves":[]}],"kev_cves":[{"cveID":"CVE-2023-0386","state":"stale","mapping_types":["exploitation_technique"]}],"_built":"2026-08-23 05:47 UTC","_attack_version":"19.2","_sigma_commit":"da9bb07d642a2826e89702445d32c795209ec108"}