Capabilities Discovery - Linux

 Original Source: [Sigma source]
Title: Capabilities Discovery - Linux
Status: test
Description:Detects usage of "getcap" binary. This is often used during recon activity to determine potential binaries that can be abused as GTFOBins or other.
References:
  -https://github.com/SaiSathvik1/Linux-Privilege-Escalation-Notes
  -https://github.com/carlospolop/PEASS-ng
  -https://github.com/diego-treitos/linux-smart-enumeration
Author: Nasreddine Bencherchali (Nextron Systems)
Date: 2022-12-28
modified:2026-01-24
Tags:
  • -'attack.discovery'
  • -'attack.t1083'
Logsource:
  • category: process_creation
  • product: linux
Detection:
  selection:
    Image|endswith: '/getcap'
    CommandLine|contains: ' -r '
  condition:selection
Falsepositives:
  -Unknown
Level: low