linux
SUID & SGID
Quick notes on SUID and SGID permissions, enumeration, and why unusual privileged binaries matter.
2026-09-12
1 min read
linuxsuidsgidprivilage-escalationenumerationred-team
Finding SUID & SGID Files#
permission enumeration
TTY1ZSH 5.9
SUID is represented by:
s in the owner's execute position.
Example:
-rwsr-xr-x
The executable runs with the owner's privileges.
SGID is represented by:
s in the group's execute position.
Example:
-rwxr-sr-x
The executable runs with the group's privileges.
Findings
INFO
Pay attention to:
• SUID binaries in unusual locations
• Custom binaries with SUID/SGID
• Unexpected ownership
• Binaries writable by unprivileged users
• Recently created privileged executables
• Applications with known privilege-escalation paths
Takeaway#
Always enumerate SUID and SGID files during Linux privilege-escalation assessments, but treat the results as leads that require further investigation.
Back to Notesnote: suid-sgid