What Dangerous Linux Capabilities Does witr Identify and Warn About?

witr flags eight specific Linux capabilities as dangerous, including CAP_SYS_ADMIN, CAP_SYS_PTRACE, CAP_NET_RAW, and CAP_SYS_MODULE, whenever they appear in non-root processes.

Linux capabilities provide fine-grained privilege control, but certain capabilities grant such extensive permissions that they effectively equate to root access. The witr repository (pranshuparmar/witr) implements a security scanner that detects these high-risk capabilities in running processes. This article examines exactly which capabilities witr considers dangerous, how the detection works in the source code, and what warnings users receive.

The Complete List of Dangerous Linux Capabilities in witr

The witr scanner defines its threat model in internal/source/detect.go. The dangerousCapabilities map (lines 15-24) contains eight capability constants mapped to their risk descriptions:

Capability Risk Level Why witr Flags It
CAP_SYS_ADMIN Critical Grants broad administrative powers; often called "the new root"
CAP_SYS_PTRACE Critical Permits tracing and manipulating arbitrary processes
CAP_NET_RAW High Enables raw socket access for packet sniffing and spoofing
CAP_DAC_OVERRIDE High Bypasses all file permission checks for read/write operations
CAP_DAC_READ_SEARCH High Bypasses directory read and search permission checks
CAP_FOWNER High Allows bypassing file ownership verification
CAP_SYS_MODULE Critical Permits loading and unloading kernel modules
CAP_SYS_RAWIO Critical Grants raw I/O access to physical memory and devices

According to the witr source code, these capabilities were selected because each one enables privilege escalation paths or direct system compromise even when held by an unprivileged user.

How witr Detects Dangerous Capabilities

The detection logic resides in three connected components within internal/source/detect.go:

1. The Dangerous Capabilities Map

// internal/source/detect.go, lines 15-24
var dangerousCapabilities = map[string]string{
    "CAP_SYS_ADMIN":       "full administrative powers",
    "CAP_SYS_PTRACE":      "can trace/manipulate other processes",
    "CAP_NET_RAW":         "raw packet access (sniffing/spoofing)",
    "CAP_DAC_OVERRIDE":    "bypasses file permission checks",
    "CAP_DAC_READ_SEARCH": "bypasses directory permission checks",
    "CAP_FOWNER":          "bypasses file ownership checks",
    "CAP_SYS_MODULE":      "can load/unload kernel modules",
    "CAP_SYS_RAWIO":       "raw I/O access to devices",
}

2. The Capability Checker Function

The isDangerousCapability helper (line 26) performs a simple map lookup:

// internal/source/detect.go, line 26
func isDangerousCapability(cap string) bool {
    _, exists := dangerousCapabilities[cap]
    return exists
}

3. Warning Generation in the Warnings Function

When witr scans processes, the Warnings function (lines 81-90) iterates through each process's Capabilities slice. For non-root processes, any match against dangerousCapabilities triggers a formatted warning:


Process has dangerous capabilities: CAP_SYS_ADMIN, CAP_SYS_PTRACE

This warning format includes all matching dangerous capabilities in a single message, making it immediately actionable for system administrators.

Practical Example: Detecting Dangerous Capabilities

The following Go program demonstrates how witr's detection works in practice, using the actual source.Warnings function:

package main

import (
	"fmt"
	"github.com/pranshuparmar/witr/pkg/model"
	"github.com/pranshuparmar/witr/internal/source"
)

func main() {
	// Simulate a process with dangerous capabilities
	proc := model.Process{
		PID:          1234,
		Command:      "myserver",
		User:         "alice",
		Capabilities: []string{"CAP_NET_RAW", "CAP_SYS_PTRACE"},
	}

	// Generate warnings for this process
	warns := source.Warnings([]model.Process{proc}, 0)
	fmt.Println(warns)
	// Output:
	// [Process has dangerous capabilities: CAP_NET_RAW, CAP_SYS_PTRACE]
}

Running this snippet produces a warning because CAP_NET_RAW and CAP_SYS_PTRACE both appear in the dangerousCapabilities map. The User field being non-root ensures the check activates—witr focuses on unprivileged processes with elevated capabilities.

Key Source Files for Capability Detection

File Purpose
internal/source/detect.go Defines dangerousCapabilities map and isDangerousCapability checker
internal/source/warnings_test.go Unit tests verifying capability detection accuracy
pkg/model/process.go Process struct with Capabilities []string field

Summary

  • witr identifies eight dangerous Linux capabilities that grant root-equivalent or system-compromising permissions
  • The complete list: CAP_SYS_ADMIN, CAP_SYS_PTRACE, CAP_NET_RAW, CAP_DAC_OVERRIDE, CAP_DAC_READ_SEARCH, CAP_FOWNER, CAP_SYS_MODULE, and CAP_SYS_RAWIO
  • Detection occurs in internal/source/detect.go through the dangerousCapabilities map and isDangerousCapability helper
  • Warnings are generated only for non-root processes that possess any of these capabilities
  • Each warning lists all dangerous capabilities found in the target process

Frequently Asked Questions

Why does witr consider CAP_SYS_ADMIN especially dangerous?

CAP_SYS_ADMIN is flagged because it grants approximately 100 distinct privileged operations, including mounting filesystems, configuring namespaces, and modifying system limits. According to kernel security researchers, this capability is so powerful that it is commonly described as "the new root"—possessing it effectively bypasses most container isolation mechanisms.

Does witr warn about capabilities in root-owned processes?

No. The Warnings function in internal/source/detect.go specifically excludes root processes from capability warnings. The logic assumes root already possesses unlimited privileges, so additional capability grants do not meaningfully increase risk. The security focus is on capability leakage to unprivileged users.

How can I verify witr's capability detection is working correctly?

Run the unit tests in internal/source/warnings_test.go, which include test cases for each dangerous capability. Alternatively, create a test process with setcap CAP_NET_RAW+eip on a non-root binary and run witr against it—you should observe the corresponding warning in the output.

What should I do when witr reports dangerous capabilities?

Immediately audit the affected process to confirm legitimate use. For containers, consider dropping unnecessary capabilities in the security context. For system services, evaluate whether the capability can be replaced with a more restricted alternative or removed entirely through architecture changes.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →