Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
1
1
Contributors
1
1
Categories
2
2
1
1
1
Platforms
2
1
Products / Services
2
MITRE Techniques
2
2
2
2
1
CVEs
68
68
58
56
50
Detects potential exploitation of CVE-2025-41244, a local privilege escalation vulnerability in VMware Tools and Aria Operations.
An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
An attacker can stage a malicious binary in a world-writable directory (e.g., /tmp) which is then executed with root privileges by the VMware service discovery mechanism when it attempts to determine the binary's version.
Detects potential exploitation of VMware CVE-2025-41244, where a privileged VMware service discovery script executes a binary from a world-writable directory like /tmp. This behavior is consistent with the local privilege escalation technique used by UNC5174.

