Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
8 detections
Filters
Last updated
All Time
Detection languages
4
2
1
1
Contributors
4
3
1
Categories
6
5
4
2
1
Platforms
6
Products / Services
4
1
1
MITRE Techniques
6
2
2
2
1
CVEs
68
68
58
56
50
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
Detects embedded CVE-2026-46300 (Fragnesia) Linux privilege escalation exploit code used by KATARU IoT malware, copied unmodified from public PoC
This rule detects command-line activity and process execution associated with the exploitation of various Linux kernel vulnerabilities, including CVE-2026-43503, CVE-2026-46300, CVE-2026-43284, CVE-2026-31431, and CVE-2026-43500. It monitors for the compilation and execution of exploit code, manipulation of kernel modules via modprobe for specific network protocols (esp4, esp6, rxrpc), configuration changes to network namespaces (xfrm, unshare), and the presence of known exploit filenames like DirtyClone or DirtyFrag.
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.
Detects suspicious process execution patterns associated with the exploitation of CVE-2026-46300 (Fragnesia). The rule monitors for the combination of user namespace creation via unshare, network tunnel configuration via ip, and kernel module loading related to ESP or rxrpc, which are indicative of an attempt to trigger a privilege escalation vulnerability in the Linux kernel.
Three related Linux kernel local privilege escalation vulnerabilities disclosed between April and May 2026, CopyFail (CVE-2026-31431), DirtyFrag (CVE-2026-43284 / CVE-2026-43500), and Fragnesia (CVE-2026-46300) all share the same core exploitation primitive — an unprivileged local user abuses an in-kernel in-place decryption path (via AF_ALG authencesn, xfrm-ESP, or ESP-in-TCP respectively) combined with repeated splice() syscalls to corrupt the page cache of a setuid binary such as /usr/bin/su, then executes it to obtain a root shell without any authentication; all three have public proof-of-concept code, affect Linux kernels from 4.14 onward, and can be mitigated by blacklisting the esp4, esp6, rxrpc, and algif_aead kernel modules until patched kernels are deployed.


