I don't have a good example of the command, but it was basically looking for 'worldly' permissions that were too open. It's important to note the users/groups could be discarded/ignored.
They were using 'find ... -exec ls -ld {} \;', which does an LDAP lookup on each result to resolve UIDs and GIDs to names.
They could have made the process far more efficient with either the native '-ls' argument built into find, or adding '-n' to the exec'd 'ls'
Either would skip the name resolution/domain. At a certain number of results/files the expense is too high, causing the job to time out
I like to call what I do "taking the coward's way out" -- using FreeIPA
My team setup the infrastructure in question and I've been too slow to learn it. FreeIPA is nice for quick/easy deployments.
I'm not sure how well it "scales", but it's great for getting comfortable with the "Domain Language" (sorry, pun)
The 'ls' output is honestly superfluous, though - 'find' will report the paths.
I won't even get into how these are batched/time limited. If not this, it'd be something else eventually