Create check-setugid cronjob This cronjob and associated whitelist will search the Scripts servers daily for set[ug]id binaries, and complain if any unexpected ones are found.
223 5 * * * root find / -xdev -not -perm -o=x -prune -o -type f -perm /ug=s -print | grep -Fxvf /etc/scripts/allowed-setugid.list | sed 's/^/Extra set[ug]id binary: /'
