1200KM / detection
T1548.001 Setuid and Setgid — Detection Rules
Detection workspace for T1548.001 Setuid and Setgid: 1 Sigma sources, 1 Atlas concepts and 0 anomaly models. No live detection validation.
Source-backed rule directory
- Setuid and Setgid · test · low · {"product":"linux","category":"process_creation"}
Atlas deterministic concepts
T1548.001 Setuid and Setgid
MATCH(file_permission_change_sets_setuid_or_setgid) AND file NOT_IN approved_setuid_files -> ALERTAnomaly models
No exact Atlas model in this snapshot.
ATT&CK analytic guidance
DET0110 Setuid/Setgid Privilege Abuse Detection (Linux/macOS)
AN0307 Analytic 0307
Correlation of chmod operations setting setuid/setgid bits followed by privileged process execution (EUID != UID), especially from user-writable or abnormal paths.
AN0308 Analytic 0308
Observation of chmod commands setting setuid/setgid bits, paired with launch of binaries under elevated execution context (e.g., root-owned binaries launched by unprivileged users).
Connected ecosystem references
Linked tags
Simulation, tools and telemetry
T1548.001 simulation workspace
No reviewed association in this snapshot.
Existing anomaly research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.