DirtyClone LPE - Privilege Escalation via Kernel IPsec Page Cache Overwrite
Detects a sequence of events where a non-root user attempts to manipulate kernel components (specifically involving xfrm/esp modules via ip or modprobe) followed immediately by a sudo or su command, suggesting an attempt to load malicious kernel modules or exploit kernel vulnerabilities to escalate privileges.
Microsoft Sentinel (KQL)

