KATARU Linux LPE exploit chain spawning su as root
Detects the execution of the 'su' binary preceded by command-line strings that are highly indicative of known Linux privilege escalation exploits, specifically those targeting vulnerabilities like PwnKit (CVE-2021-4034). The rule monitors for common exploit payloads or status messages (e.g., 'prctl PR_SET_DUMPABLE', 'fork userns mapper') associated with successful exploitation attempts that manipulate environment variables or process attributes to elevate privileges to root, while filtering out legitimate container-related processes.
Microsoft Sentinel (KQL)

