Analytics BIOC Low

SUID/GUID permission discovery

Attackers may search for potential to elevate permissions using binaries that have the SUID or GUID bit enabled.

Module:
Platform Analytics
Data source:
XDR Agent
ATT&CK tactics: Discovery (TA0007)
ATT&CK techniques: File and Directory Discovery (T1083)
Attacker's goals:

Attackers may use GUID/SUID binaries to elevate privileges.

Investigative actions:

Check whether additional malicious commands were executed from the same process. Verify if the command-line seems suspicious or contains malicious indicators.

Test period:
N/A (single event)
Deduplication:
1 Day