Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
23 detections
Filters
Last updated
All Time
Detection languages
6
5
4
3
2
Contributors
4
3
3
3
2
Categories
10
8
7
7
5
Platforms
20
1
Products / Services
2
2
2
2
1
MITRE Techniques
11
6
5
4
4
CVEs
68
68
58
56
50
23
This rule detects the execution of Python processes on Linux systems that include a specific cryptographic template string in their command line. This string, "authencesn(hmac(sha256),cbc(aes))", is indicative of a Proof-of-Concept (PoC) exploit related to CVE-2026-31431, also known as 'Copy Fail'. The detection targets Python binaries (python, python3, or versioned python3.x) and aims to identify attempts to leverage this vulnerability for suspicious cryptographic operations.
This rule detects attempts to mitigate the CVE-2026-31431 vulnerability by either unloading the 'algif_aead' kernel module using 'rmmod' or by configuring 'modprobe' to blackhole the 'algif_aead' module. This activity indicates a system administrator or automated tool is applying a known mitigation for a kernel vulnerability.
