Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

9 detections

Detects KATARU IoT malware samples embedding the DirtyFrag (CVE-2026-43284) Linux local privilege escalation exploit copied from public PoC code, as part of a chained LPE attempt targeting root shell spawning
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
002
Detects KATARU IoT malware samples embedding the DirtyFrag (CVE-2026-43284) Linux local privilege escalation exploit copied from public PoC code, as part of a chained LPE attempt targeting root shell spawning
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
002
Detects KATARU IoT malware samples embedding the DirtyFrag (CVE-2026-43284) Linux local privilege escalation exploit copied from public PoC code, as part of a chained LPE attempt targeting root shell spawning
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
001
Detects KATARU IoT malware samples embedding the DirtyFrag (CVE-2026-43284) Linux local privilege escalation exploit copied from public PoC code, as part of a chained LPE attempt targeting root shell spawning
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
000
The following analytic detects an unprivileged user invoking the unshare syscall with user namespace flags followed within 120 seconds by a root-owned shell or interpreter spawning under the same parent process, correlating auditd syscall telemetry with Sysmon process creation events to identify the two-step sequence characteristic of user-namespace-based Linux kernel privilege escalation exploits such as DirtyFrag.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
2010
The following analytic detects kernel-level events where a setuid binary launches a shell or interpreter with a NULL argument vector, which occurs when a privilege escalation exploit gains root and executes a process via execve() without constructing a legitimate argument array.
Splunk Security@SplunkSecurity
avatar
Splunk Security Content
2 months ago
003
This rule detects command-line activity and process execution associated with the exploitation of various Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-46300, CVE-2026-43284, CVE-2026-31431, and CVE-2026-43500. It monitors for the compilation and execution of exploit code, manipulation of kernel modules via modprobe for specific network protocols (esp4, esp6, rxrpc), configuration changes to network namespaces (xfrm, unshare), and the presence of known exploit filenames like DirtyClone or DirtyFrag.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
4022
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
4 months ago
11041
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
avatar
Mikelle Bandin@lightofrhitta
avatar
Detections.ai Community
5 months ago
221857