1200kmSECURITY RESEARCH
Loading interactive filters…

1200KM / detection

T1548.001 Setuid and Setgid — Detection Rules

Detection workspace for T1548.001 Setuid and Setgid: 1 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.

Source-backed rule directory

  • Setuid and Setgid · test · low · {"product":"linux","category":"process_creation"}

Atlas deterministic concepts

T1548.001 Setuid and Setgid

MATCH(file_permission_change_sets_setuid_or_setgid) AND file NOT_IN approved_setuid_files -> ALERT

Anomaly models

No exact Atlas model in this snapshot.

ATT&CK analytic guidance

DET0110 Setuid/Setgid Privilege Abuse Detection (Linux/macOS)

AN0307 Analytic 0307

Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths.

AN0308 Analytic 0308

Observation of chmod commands setting setuid/setgid bits, paired with launch of binaries under elevated execution context (e.g., root-owned binaries launched by unprivileged users).

Connected ecosystem references

Linked tags

Simulation, tools and telemetry

T1548.001 simulation workspace

No reviewed association in this snapshot.

Existing anomaly research

Original publication snapshot · Anomaly Detection Atlas

Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.