Suspicious SUID Binary Discovery via Find Perm 4000

PremiumReviewedSigma · Low · v1
Product
linux
Category
process_creation
Author
HuntRule
Published
2026-09-17
Updated
2026-09-17

ATT&CK techniques

Priv Esc → Defense Evasion
  1. Recon

  2. Resource Dev

  3. Initial Access

  4. Execution

  5. Persistence

  6. Cred Access

  7. Discovery

  8. Lateral Movement

  9. Collection

  10. C2

  11. Exfiltration

  12. Impact

What it detects

This rule detects the find command searching the filesystem for setuid binaries using the perm 4000 predicate which is a common privilege escalation discovery step on Linux hosts. Adversaries enumerate SUID executables to locate misconfigured binaries that can be abused to elevate to root.

Related detections4 linkedT1548.001 — drag to rearrange
Possible CopyFail Root Exploitation via Python Spawning SUID Shell (via process_creation)
Suspicious User and Network Namespace Creation via unshare on Linux
Linux auth logs: pkexec and XAUTHORITY strings indicating PwnKit (CVE-2021-4034) attempt
Linux process activity: chown root and setuid/setgid chmod flags
Suspicious SUID Binary Discovery via Find Perm 4000
Pivot detection · T1548.001 · 4 related

Detection content is published as a reviewed draft. Tune thresholds and exclusions against your own telemetry before enabling this rule for alerting.