BIOCs

Browse the Cortex behavioral indicator of compromise (BIOC) detection rules.

Severity
Category

1 BIOC match the current filters. technique: T1068 ✕

Download CSV Show ATT&CK heatmap
  • Modifying ELF file capabilities via setcap Informational File Privilege Manipulation

    An attacker may attempt to gain privileges by setting the capabilities of a file.

    Indicator:

    Process action type = execution AND target process name = setcap

    ATT&CK tactics: Privilege Escalation (TA0004)
    ATT&CK techniques: Exploitation for Privilege Escalation (T1068)
    Preventable:
    Yes
    Source:
    Palo Alto Networks
    Updated:
    2026-02-11