Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
23 detections
Filters
Last updated
All Time
Detection languages
6
5
4
3
2
Contributors
4
3
3
3
2
Categories
10
8
7
7
5
Platforms
20
1
Products / Services
2
2
2
2
1
MITRE Techniques
11
6
5
4
4
CVEs
68
68
58
56
50
23
This rule monitors for file and process creation events associated with known FeralWolf threat actor malware, including MQTTDoor, MatrixDoor, RDPSocksProxy, GenieLocker ransomware, fscan, and tools leveraging CVE-2026-31431.
Detects KATARU IoT malware embedded exploit code for CVE-2026-31431 (Copy Fail) Linux privilege escalation, identified by shared exploit-chain strings and syscall sequences used to spawn su as root
Detects KATARU IoT malware embedded exploit code for CVE-2026-31431 (Copy Fail) Linux privilege escalation, identified by shared exploit-chain strings and syscall sequences used to spawn su as root
Detects KATARU IoT malware embedded exploit code for CVE-2026-31431 (Copy Fail) Linux privilege escalation, identified by shared exploit-chain strings and syscall sequences used to spawn su as root
Detects KATARU IoT malware embedded exploit code for CVE-2026-31431 (Copy Fail) Linux privilege escalation, identified by shared exploit-chain strings and syscall sequences used to spawn su as root
The following analytic detects when the AF_ALG kernel crypto socket interface being loaded more than 300 seconds after system boot, which is a primary kernel-level indicator of Copy Fail (CVE-2026-31431) exploitation activity on Debian and Ubuntu family systems.
The AF_ALG interface is required by the exploit to access the vulnerable authencesn crypto code path, and on systems where it is not auto-loaded at boot, its on-demand registration by an unprivileged process is a strong indicator of exploitation in progress.
The AF_ALG interface is required by the exploit to access the vulnerable authencesn crypto code path, and on systems where it is not auto-loaded at boot, its on-demand registration by an unprivileged process is a strong indicator of exploitation in progress.
The following analytic detects when su runs from a page-cache-corrupted binary.
When this happens a partial corruption of its runtime state can prevent it from resolving the identity of the calling user.
Under normal conditions, su logs both the target account and the invoking user.
When exploitation has occurred via this path, the invoking username field is absent.
This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access.
If confirmed malicious, an attacker could achieve full control over the system, execute arbitrary commands, and compromise the entire environment.
When this happens a partial corruption of its runtime state can prevent it from resolving the identity of the calling user.
Under normal conditions, su logs both the target account and the invoking user.
When exploitation has occurred via this path, the invoking username field is absent.
This activity is significant because it indicates a possible privilege escalation attempt, allowing a user to gain root access.
If confirmed malicious, an attacker could achieve full control over the system, execute arbitrary commands, and compromise the entire environment.
This rule detects instances of the 'su' utility being executed in a manner inconsistent with normal system administration patterns. By filtering out common, expected parent processes (such as login shells, terminal multiplexers, or established system services) and identifying 'su' command-line execution or shell commands attempting to invoke it, the rule flags potentially malicious privilege escalation attempts, such as those exploiting local vulnerabilities.
This rule detects command-line activity and process execution associated with the exploitation of various Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-46300, CVE-2026-43284, CVE-2026-31431, and CVE-2026-43500. It monitors for the compilation and execution of exploit code, manipulation of kernel modules via modprobe for specific network protocols (esp4, esp6, rxrpc), configuration changes to network namespaces (xfrm, unshare), and the presence of known exploit filenames like DirtyClone or DirtyFrag.
This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
This rule detects two scenarios on Linux systems: 1. A non-root process interacting with a root process (e.g., cross-process communication where the source is non-root and the target is root). 2. Any process (excluding root) exhibiting indicators related to 'AF_ALG' or 'splice', or mentioning 'CVE-2026-31431' in its name or description. These indicators are often associated with privilege escalation attempts or kernel exploits.
Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail).
An unprivileged user can gain root access on major Linux distributions by exploiting CVE-2026-31431, a deterministic 4-byte page cache write bug in the authencesn cryptographic template.
The 'Copy Fail' vulnerability (CVE-2026-31431) is a critical logic flaw in the Linux kernel's crypto subsystem disclosed by Xint Code. Unlike previous high-profile kernel exploits that relied on race conditions, Copy Fail is a straight-line logic bug that allows an unprivileged local user to perform a controlled 4-byte write into the page cache of any readable file. This enables an attacker to modify the in-memory version of setuid binaries (like /usr/bin/su) to execute arbitrary shellcode as root without changing the file on disk.
Vulnerability affects Linux Kernel version starting 4.14 before 6.18.22.
The 'Copy Fail' vulnerability (CVE-2026-31431) is a critical logic flaw in the Linux kernel's crypto subsystem disclosed by Xint Code. Unlike previous high-profile kernel exploits that relied on race conditions, Copy Fail is a straight-line logic bug that allows an unprivileged local user to perform a controlled 4-byte write into the page cache of any readable file. This enables an attacker to modify the in-memory version of setuid binaries (like /usr/bin/su) to execute arbitrary shellcode as root without changing the file on disk.
Vulnerability affects Linux Kernel version starting 4.14 before 6.18.22.
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
Query looks for non-root users launching the switch user (su) process via a parent process other than the normally expected processes such as shells, sudo, or su itself.
Query looks for potential CopyFail proof of concept (POC) code execution via identifying potentially correlated curl and su process executions. May identify false positives, yet works well for identification of CopyFail POC provided by Xint.Code.
Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail). While this is a mitigation step, monitoring for it ensures compliance and tracks remediation efforts.
Detects the execution of commands used to disable the algif_aead module to mitigate CVE-2026-31431 (Copy Fail). This rule monitors for dynamic unloading of the module using 'rmmod' or persistent configuration changes via 'modprobe.d' to disable the module. While this is a mitigation step, monitoring for it ensures compliance and tracks remediation efforts.
Detects Python command lines referencing a specific cryptographic string ('authencesn(hmac(sha256),cbc(aes))') known to be used in the exploitation of the 'Copy Fail' vulnerability (CVE-2026-31431). This string is highly specific and its presence in a Python command line is indicative of an attempt to exploit this particular CVE.
This rule detects the execution of a Python Proof-of-Concept (PoC) script named 'exp.py' followed by the execution of the 'su' binary within a 5-minute window on a Linux system. This correlation is indicative of an attempt to exploit CVE-2026-31431 (Copy Fail), which leverages AF_ALG sockets to overwrite the 'su' setuid binary in memory, aiming to achieve root privileges.









