DirtyClone LPE - Suspicious User Namespace Creation with Network Admin for IPsec Exploit

Detects the execution of the 'unshare' utility with arguments that create new user, network, and mount namespaces (-U, -n, -r) by a non-root user. This technique is often used to bypass namespace restrictions or perform privilege escalation by gaining elevated capabilities within a new, user-controlled namespace.