BIOC
Informational
✕
Setuid on file
Setting user identification on an executable file causes it to run with the privileges of the owning user.
- Module:
- Platform Analytics
- Agent event type:
- Process execution
- Category:
- Privilege Escalation
- Status:
- Enabled
ATT&CK tactics: Privilege Escalation (TA0004)
ATT&CK techniques: Abuse Elevation Control Mechanism: Setuid and Setgid (T1548.001)
Indicator:
Process action type = execution AND target process cmd = *u+s* AND target process name = chmod
Preventable: yes