DirtyClone LPE - Privilege Escalation via Kernel IPsec Page Cache Overwrite

Detects a sequence of events where a non-root user attempts to manipulate kernel components (specifically involving xfrm/esp modules via ip or modprobe) followed immediately by a sudo or su command, suggesting an attempt to load malicious kernel modules or exploit kernel vulnerabilities to escalate privileges.