The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Read process capability masks | grep -E '^Cap(Inh|Prm|Eff|Bnd|Amb):' /proc/1234/status | View examples |
| Decode a capability mask | capsh --decode=0000000000000400 | View examples |
| Show current capability context | capsh --print | View examples |
| Read file capabilities | getcap -v /usr/local/bin/ping-helper | View examples |
| Scan one filesystem tree | sudo getcap -r /usr/local 2>/dev/null | View examples |
| Grant network bind capability | sudo setcap 'cap_net_bind_service=ep' \
/usr/local/bin/webd | View examples |
| Remove file capabilities | sudo setcap -r /usr/local/bin/webd | View examples |
| Verify expected capability | getcap /usr/local/bin/webd |
grep -F 'cap_net_bind_service=ep' | View examples |
| Show highest supported capability | cat /proc/sys/kernel/cap_last_cap | View examples |
| Check no-new-privileges | grep '^NoNewPrivs:' /proc/1234/status | View examples |
| Inspect unit capability policy | systemctl show webd.service -p CapabilityBoundingSet -p \
AmbientCapabilities -p NoNewPrivileges | View examples |
| Analyze unit exposure | systemd-analyze security webd.service | View examples |
| List file attributes | lsattr -d /etc/important.conf | View examples |
| Set immutable | sudo chattr +i /etc/important.conf | View examples |
| Clear immutable | sudo chattr -i /etc/important.conf | View examples |
| Set append-only | sudo chattr +a /var/log/example.log | View examples |
| List extended attributes | getfattr --dump --absolute-names /usr/local/bin/webd | View examples |
| Read raw capability xattr | getfattr --name=security.capability --hex \
/usr/local/bin/webd | View examples |
| Copy while preserving xattrs | cp --archive --preserve=xattr /usr/local/bin/webd \
/srv/stage/webd | View examples |
| Archive with xattrs | tar --xattrs --acls -cpf webd-backup.tar \
/usr/local/bin/webd | View examples |
Linux capabilities split root privilege into individual bits, but many remain broad enough for full host compromise. File capabilities are security.capability extended attributes whose behavior depends on exec transitions, namespaces, mount options, and kernel support. File attributes such as immutable and append-only are separate controls. Grant the smallest tested privilege, preserve xattrs in deployment and backup, and keep a rollback path before changing privileged binaries or boot-critical files.
Step by step
Detailed examples
Read all five capability sets in context
Permitted bounds what a thread may make effective; effective is checked by the kernel; inheritable and ambient participate in exec transitions; the bounding set limits future acquisition. Capability state is per thread even though tools often display a process. Decode against the running system because new kernels add capabilities.
grep -E '^(Name|Uid|Gid|CapInh|CapPrm|CapEff|CapBnd|CapAmb|NoNewPrivs):' /proc/1234/status
capsh --decode=0000000000000400
cat /proc/sys/kernel/cap_last_cap Grant file capabilities only to controlled immutable artifacts
setcap writes security.capability to an executable. Replacing the file usually drops that xattr, while a writable executable lets an attacker inherit its privilege. Verify ownership, modes, hash, mount policy, interpreter behavior, and update workflow. Scripts generally do not safely gain file capabilities through their interpreter.
stat /usr/local/bin/webd
sha256sum /usr/local/bin/webd
findmnt -T /usr/local/bin/webd -o TARGET,SOURCE,FSTYPE,OPTIONS
getcap -v /usr/local/bin/webd
# sudo setcap 'cap_net_bind_service=ep' /usr/local/bin/webd Audit bounded paths and compare to an allowlist
Unexpected file capabilities are high-value persistence. Scan package and locally managed executable trees, but avoid crossing huge or remote filesystems blindly. Compare path, inode, owner, mode, package provenance, hash, and exact capabilities to a reviewed baseline; do not remove entries before establishing why they exist.
sudo getcap -r /usr/local 2>/dev/null
sudo getcap -r /opt 2>/dev/null
findmnt -R /usr/local
# Compare results to a version-controlled allowlist and package inventory. Interpret privilege relative to the governing user namespace
Capabilities are checked in relation to a user namespace, and namespaced file capabilities can be scoped to a root user ID. Container root does not automatically equal initial-namespace root, but broad device access, host mounts, or CAP_SYS_ADMIN can erase isolation. Capability support and decomposition vary by kernel.
readlink /proc/1234/ns/user
readlink /proc/1/ns/user
grep -E '^Cap(Bnd|Eff|Amb):' /proc/1234/status
cat /proc/sys/kernel/cap_last_cap Prefer service-scoped capability policy
systemd can restrict CapabilityBoundingSet and grant AmbientCapabilities to a service while NoNewPrivileges prevents later exec-based privilege gain. Ambient capabilities must also be permitted and inheritable. Combine narrow capabilities with an unprivileged user and other sandbox controls, then test required behavior and restart rollback.
systemctl show webd.service -p User -p Group -p CapabilityBoundingSet -p AmbientCapabilities -p NoNewPrivileges
systemd-analyze security webd.service
systemctl cat webd.service Use immutable and append-only flags as guardrails, not access control
chattr flags are filesystem-dependent and require privilege to change. Immutable can block writes, renames, deletion, and package upgrades; append-only can break log rotation and applications that rewrite headers. Attackers with sufficient privilege can clear them. Record every flag and an emergency reversal procedure.
findmnt -T /etc/important.conf -o FSTYPE,OPTIONS
lsattr -d /etc/important.conf /var/log/example.log
# Clear a documented guard only for the maintenance window:
# sudo chattr -i /etc/important.conf Distinguish capability xattrs from ACLs and security labels
security.capability is one xattr; SELinux labels, IMA/EVM metadata, user attributes, and POSIX ACLs are separate. Dumping xattrs can expose provenance or security data. Destination filesystems, copy tools, archives, network protocols, and privileges may omit or transform metadata.
getcap -v /usr/local/bin/webd
getfattr --dump --absolute-names /usr/local/bin/webd
getfacl --absolute-names /usr/local/bin/webd
ls -lZ /usr/local/bin/webd Test capability preservation across every deployment path
Copy, archive, extraction, package installation, overlay filesystems, and restore can lose file capabilities or restore them unexpectedly. A successful data checksum does not validate metadata. Test backup and rollback on the destination filesystem, inventory getcap after deployment, and avoid privileged extraction from untrusted archives.
getcap -v /usr/local/bin/webd /srv/stage/webd
getfattr --name=security.capability --hex /usr/local/bin/webd
getfattr --name=security.capability --hex /srv/stage/webd
sha256sum /usr/local/bin/webd /srv/stage/webd Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



