Clankerusecase
MITRE ATT&CK detection coverage
← Back to main site
Home/ MITRE Matrix/ Privilege Escalation/ T1548.001

T1548.001Setuid and Setgid

T1548.001 — Setuid and Setgid is a MITRE ATT&CK technique in the Privilege Escalation tactic. Clankerusecase tracks 12 detection use cases covering it and 5 threat-intel articles citing it.

Privilege Escalation
View on the matrix → Filter Detection Library MITRE official spec ↗
12Use cases
5Articles
0Sub-techniques
1Tactic

Use cases covering this technique (12)

Linux Auditd Setuid Using Chmod Utility ESCU actions · hunting P Linux Auditd Setuid Using Setcap Utility ESCU actions · alerting P Linux Common Process For Elevation Control ESCU actions · hunting P Linux Dirty Frag Kernel Privilege Escalation ESCU actions · alerting P Linux Setuid Using Chmod Utility ESCU actions · hunting P Linux Setuid Using Setcap Utility ESCU actions · hunting P [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux Bespoke exploit · hunting DSΣPDDCS [LLM] SleeperGem privilege escalation: setuid-root shell planted as /usr/local/sbin/ping6 Bespoke install · alerting DSΣPDDCS [LLM] Node extraction writing ld.so.preload or setuid/privileged path as root (CVE-2026-53486 privesc) Bespoke install · alerting DSΣDDCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] PwnKit pkexec executed with empty argv (CVE-2021-4034 exploit primitive) Bespoke exploit · alerting DSΣPDDCS [LLM] Root shell spawned by pkexec with empty parent command line (PwnKit post-exploitation) Bespoke install · alerting DSΣPCS

Articles citing this technique (5)