From - man capabilities
UNIX implementations distinguish two categories of processes: privileged processes (whose effective user ID is 0, referred to as superuser or root), and unprivileged processes (whose effective UID is nonzero).
and
Starting with kernel 2.2, Linux divides the privileges traditionally associated with superuser into distinct units, known as capabilities, which can be independently enabled and disabled. Capabilities are a per-thread attribute.
Does any Linux command or technique exist to determine the capabilities associated with a running process (or thread).
The utility
getpcaps
will show the capabilities for a given PID.From the man page: