Linux auditd: getcap scanning for setuid/setgid-capable files under root

Flags getcap command-line usage scanning / for Linux capability-bearing files via auditd.

FreeReviewedSigma · Low · v3
Product
linux
Service
auditd
Author
Pawel Mazur (SigmaHQ), DRL 1.1
Published
2021-11-28
Updated
2026-07-31

ATT&CK techniques

Priv Esc → Discovery
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Lateral Movement

  8. Collection

  9. C2

  10. Exfiltration

  11. Impact

What it detects

This rule flags executions of the getcap command that query with the options `-r /`, indicating a recursive scan of the root filesystem for capability-bearing files. Such discovery can help an attacker identify privilege-escalation opportunities from binaries that have elevated capabilities. It relies on Linux auditd telemetry capturing process execution events with the specific command-line arguments `getcap -r /`.

Related detections9 linkedT1548 — drag to rearrange
Suspicious User Home Directory Modification via dscl Process Creation
Possible Local File Inclusion Path Traversal Targeting CentreStack Web.config
Possible GTFOBins Shell Breakout via apt Command
Malicious Update Orchestrator Service Reconfiguration for Privilege Escalation
Malicious macOS Credential Verification via dscl authonly
Malicious setcap Assigning cap_sys_admin for GameOverlay Privilege Escalation (via process_creation)
Suspicious AWS GetFederationToken Console Access by JavaGhost (via cloudtrail)
Linux: Detect changes to fs.suid_dumpable enabling core dumps for SUID processes
Linux setcap sets cap_setgid on binaries (Setgid capability assignment)
Linux auditd: getcap scanning for setuid/setgid-capable files under root
Pivot detection · T1548 · 9 related

Changelog

v3
  1. v3
    Candidate ingested via manual entry.2026-07-31
  2. v2
    Candidate ingested via manual entry.2026-07-31
  3. v1
    No changelog recorded for this version.2026-07-30

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.