# What Dangerous Linux Capabilities Does witr Identify and Warn About?

> Discover the dangerous Linux capabilities witr identifies like CAP_SYS_ADMIN and CAP_NET_RAW in non-root processes. Enhance your system security today.

- Repository: [Pranshu Parmar/witr](https://github.com/pranshuparmar/witr)
- Tags: deep-dive
- Published: 2026-08-10

---

**`witr` flags eight specific Linux capabilities as dangerous, including `CAP_SYS_ADMIN`, `CAP_SYS_PTRACE`, `CAP_NET_RAW`, and `CAP_SYS_MODULE`, whenever they appear in non-root processes.**

Linux capabilities provide fine-grained privilege control, but certain capabilities grant such extensive permissions that they effectively equate to root access. The `witr` repository (`pranshuparmar/witr`) implements a security scanner that detects these high-risk capabilities in running processes. This article examines exactly which capabilities `witr` considers dangerous, how the detection works in the source code, and what warnings users receive.

## The Complete List of Dangerous Linux Capabilities in witr

The `witr` scanner defines its threat model in [`internal/source/detect.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/detect.go). The `dangerousCapabilities` map (lines 15-24) contains eight capability constants mapped to their risk descriptions:

| Capability | Risk Level | Why witr Flags It |
|------------|-----------|-------------------|
| `CAP_SYS_ADMIN` | **Critical** | Grants broad administrative powers; often called "the new root" |
| `CAP_SYS_PTRACE` | **Critical** | Permits tracing and manipulating arbitrary processes |
| `CAP_NET_RAW` | **High** | Enables raw socket access for packet sniffing and spoofing |
| `CAP_DAC_OVERRIDE` | **High** | Bypasses all file permission checks for read/write operations |
| `CAP_DAC_READ_SEARCH` | **High** | Bypasses directory read and search permission checks |
| `CAP_FOWNER` | **High** | Allows bypassing file ownership verification |
| `CAP_SYS_MODULE` | **Critical** | Permits loading and unloading kernel modules |
| `CAP_SYS_RAWIO` | **Critical** | Grants raw I/O access to physical memory and devices |

According to the `witr` source code, these capabilities were selected because each one enables **privilege escalation paths** or **direct system compromise** even when held by an unprivileged user.

## How witr Detects Dangerous Capabilities

The detection logic resides in three connected components within [`internal/source/detect.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/detect.go):

### 1. The Dangerous Capabilities Map

```go
// internal/source/detect.go, lines 15-24
var dangerousCapabilities = map[string]string{
    "CAP_SYS_ADMIN":       "full administrative powers",
    "CAP_SYS_PTRACE":      "can trace/manipulate other processes",
    "CAP_NET_RAW":         "raw packet access (sniffing/spoofing)",
    "CAP_DAC_OVERRIDE":    "bypasses file permission checks",
    "CAP_DAC_READ_SEARCH": "bypasses directory permission checks",
    "CAP_FOWNER":          "bypasses file ownership checks",
    "CAP_SYS_MODULE":      "can load/unload kernel modules",
    "CAP_SYS_RAWIO":       "raw I/O access to devices",
}

```

### 2. The Capability Checker Function

The `isDangerousCapability` helper (line 26) performs a simple map lookup:

```go
// internal/source/detect.go, line 26
func isDangerousCapability(cap string) bool {
    _, exists := dangerousCapabilities[cap]
    return exists
}

```

### 3. Warning Generation in the Warnings Function

When `witr` scans processes, the `Warnings` function (lines 81-90) iterates through each process's `Capabilities` slice. For non-root processes, any match against `dangerousCapabilities` triggers a formatted warning:

```

Process has dangerous capabilities: CAP_SYS_ADMIN, CAP_SYS_PTRACE

```

This warning format includes **all matching dangerous capabilities** in a single message, making it immediately actionable for system administrators.

## Practical Example: Detecting Dangerous Capabilities

The following Go program demonstrates how `witr`'s detection works in practice, using the actual `source.Warnings` function:

```go
package main

import (
	"fmt"
	"github.com/pranshuparmar/witr/pkg/model"
	"github.com/pranshuparmar/witr/internal/source"
)

func main() {
	// Simulate a process with dangerous capabilities
	proc := model.Process{
		PID:          1234,
		Command:      "myserver",
		User:         "alice",
		Capabilities: []string{"CAP_NET_RAW", "CAP_SYS_PTRACE"},
	}

	// Generate warnings for this process
	warns := source.Warnings([]model.Process{proc}, 0)
	fmt.Println(warns)
	// Output:
	// [Process has dangerous capabilities: CAP_NET_RAW, CAP_SYS_PTRACE]
}

```

Running this snippet produces a warning because `CAP_NET_RAW` and `CAP_SYS_PTRACE` both appear in the `dangerousCapabilities` map. The `User` field being non-root ensures the check activates—`witr` focuses on **unprivileged processes with elevated capabilities**.

## Key Source Files for Capability Detection

| File | Purpose |
|------|---------|
| [`internal/source/detect.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/detect.go) | Defines `dangerousCapabilities` map and `isDangerousCapability` checker |
| [`internal/source/warnings_test.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/warnings_test.go) | Unit tests verifying capability detection accuracy |
| [`pkg/model/process.go`](https://github.com/pranshuparmar/witr/blob/main/pkg/model/process.go) | `Process` struct with `Capabilities []string` field |

## Summary

- `witr` identifies **eight dangerous Linux capabilities** that grant root-equivalent or system-compromising permissions
- The complete list: `CAP_SYS_ADMIN`, `CAP_SYS_PTRACE`, `CAP_NET_RAW`, `CAP_DAC_OVERRIDE`, `CAP_DAC_READ_SEARCH`, `CAP_FOWNER`, `CAP_SYS_MODULE`, and `CAP_SYS_RAWIO`
- Detection occurs in [`internal/source/detect.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/detect.go) through the `dangerousCapabilities` map and `isDangerousCapability` helper
- Warnings are generated only for **non-root processes** that possess any of these capabilities
- Each warning lists **all dangerous capabilities** found in the target process

## Frequently Asked Questions

### Why does witr consider CAP_SYS_ADMIN especially dangerous?

`CAP_SYS_ADMIN` is flagged because it grants approximately 100 distinct privileged operations, including mounting filesystems, configuring namespaces, and modifying system limits. According to kernel security researchers, this capability is so powerful that it is commonly described as "the new root"—possessing it effectively bypasses most container isolation mechanisms.

### Does witr warn about capabilities in root-owned processes?

No. The `Warnings` function in [`internal/source/detect.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/detect.go) specifically excludes root processes from capability warnings. The logic assumes root already possesses unlimited privileges, so additional capability grants do not meaningfully increase risk. The security focus is on **capability leakage to unprivileged users**.

### How can I verify witr's capability detection is working correctly?

Run the unit tests in [`internal/source/warnings_test.go`](https://github.com/pranshuparmar/witr/blob/main/internal/source/warnings_test.go), which include test cases for each dangerous capability. Alternatively, create a test process with `setcap CAP_NET_RAW+eip` on a non-root binary and run `witr` against it—you should observe the corresponding warning in the output.

### What should I do when witr reports dangerous capabilities?

Immediately audit the affected process to confirm legitimate use. For containers, consider dropping unnecessary capabilities in the security context. For system services, evaluate whether the capability can be replaced with a more restricted alternative or removed entirely through architecture changes.