Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

8 detections

Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
22 days ago
004
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
22 days ago
004
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
avatar
Arnold Chan@slaz
avatar
Hunters
22 days ago
002
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
22 days ago
001
This rule detects command-line activity and process execution associated with the exploitation of various Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-46300, CVE-2026-43284, CVE-2026-31431, and CVE-2026-43500. It monitors for the compilation and execution of exploit code, manipulation of kernel modules via modprobe for specific network protocols (esp4, esp6, rxrpc), configuration changes to network namespaces (xfrm, unshare), and the presence of known exploit filenames like DirtyClone or DirtyFrag.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
4022
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
4 months ago
11041
Detects suspicious process execution patterns associated with the exploitation of CVE-2026-46300 (Fragnesia). The rule monitors for the combination of user namespace creation via unshare, network tunnel configuration via ip, and kernel module loading related to ESP or rxrpc, which are indicative of an attempt to trigger a privilege escalation vulnerability in the Linux kernel.
avatar
Ibrahim Saud@tektrix
avatar
Detections.ai Community
3 months ago
002
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
avatar
Mikelle Bandin@lightofrhitta
avatar
Detections.ai Community
5 months ago
221857