Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

23 detections

This rule detects the execution of Python processes on Linux systems that include a specific cryptographic template string in their command line. This string, "authencesn(hmac(sha256),cbc(aes))", is indicative of a Proof-of-Concept (PoC) exploit related to CVE-2026-31431, also known as 'Copy Fail'. The detection targets Python binaries (python, python3, or versioned python3.x) and aims to identify attempts to leverage this vulnerability for suspicious cryptographic operations.
avatar
nomit vyas@xoxo
avatar
Detections.ai Community
5 months ago
110505
This rule detects attempts to mitigate the CVE-2026-31431 vulnerability by either unloading the 'algif_aead' kernel module using 'rmmod' or by configuring 'modprobe' to blackhole the 'algif_aead' module. This activity indicates a system administrator or automated tool is applying a known mitigation for a kernel vulnerability.
avatar
nomit vyas@xoxo
avatar
Detections.ai Community
5 months ago
30458