1200KM / simulation
T1548.001 Setuid and Setgid — Attack Simulation
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or…
Technique description
An adversary may abuse configurations where an application has the setuid or setgid bits set in order to get code running in a different (and possibly more privileged) user’s context. On Linux or macOS, when the setuid or setgid bits are set for an application binary, the application will run with the privileges of the owning user or group respectively. Normally an application is run in the current user’s context, regardless of which user or…
At least one platform-compatible Atomic procedure is documented. Individual review, lab prerequisites, and validation remain required.
Official ATT&CK definition · Detection rules and anomaly models
Documented simulation candidates
- Provide the SetUID capability to a file
Procedure 1ac3272f-9bcf-443a-9888-4b1d3de785c1; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Set a SetGID flag on file (freebsd)
Procedure 1f73af33-62a8-4bf1-bd10-3bea931f2c0d; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Do reconnaissance for files that have the setgid bit set
Procedure 3fb46e17-f337-4c14-9f9a-a471946533e2; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Set a SetUID flag on file
Procedure 759055b3-3885-4582-a8ec-c00c9d64dd79; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Make and modify binary from C source
Procedure 896dfe97-ae43-4101-8e96-9a7996555d80; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Do reconnaissance for files that have the setuid bit set
Procedure 8e36da01-cd29-45fd-be72-8a0fcaad4481; elevation not declared required; cleanup not declared. Not executed or individually validated.
- Set a SetUID flag on file (freebsd)
Procedure 9be9b827-ff47-4e1b-bef8-217db6fb7283; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Make and modify capabilities of a binary
Procedure db53959c-207d-4000-9e7a-cd8eb417e072; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Set a SetGID flag on file
Procedure db55f666-7cba-46c6-9fe6-205a05c3242c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
- Make and modify binary from C source (freebsd)
Procedure dd580455-d84b-481b-b8b0-ac96f3b1dc4c; elevation required; cleanup present, not reviewed. Not executed or individually validated.
Connected ecosystem references
Linked tags
Detection and collection
Attack tools
No reviewed association in this snapshot.
Existing research
Pinned research references. No browser attack runner, live simulation result or validated detector is asserted. Source mappings and validation limits are preserved. ATT&CK / Atomic provenance · Detection provenance.