Samirbous
6b3b84ca38
[New/Tuning] Linux LPE via SUID Shell (#5980)
* [New] Kubernetes Pod Exec with Curl or Wget to HTTPS
Detects pod or attach `exec` API calls where the decoded request query implies curl or wget fetching an https URL (avoid noisy local http services).
* Create execution_kubernetes_pod_exec_potential_reverse_shell.toml
* Update execution_kubernetes_pod_exec_curl_wget_https.toml
* Update execution_kubernetes_pod_exec_potential_reverse_shell.toml
* ++
* ++
* Add auditd rule for root-effective shell -p outside system paths; extend SUID/SGID exploitation coverage.
Made-with: Cursor
* Revert "++"
This reverts commit eb5631d80e980a3ad59f44095741505f5c4fc7ec.
* Revert "++"
This reverts commit 2d2c34ca211879069f666f850cb00a4e18b24f27.
* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_curl_wget_https.toml
* Delete rules/integrations/kubernetes/execution_kubernetes_pod_exec_potential_reverse_shell.toml
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
* Update rules/linux/privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>
* Update privilege_escalation_auditd_euid_root_shell_from_non_standard_path.toml
---------
Co-authored-by: Eric Forte <119343520+eric-forte-elastic@users.noreply.github.com>
2026-05-01 10:51:29 +01:00
..
2026-03-02 13:24:25 +01:00
2026-03-02 13:24:25 +01:00
2026-03-02 13:24:25 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 13:32:43 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:11:05 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2025-11-25 01:08:15 +05:30
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-19 09:19:24 -03:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-03-20 20:32:07 +05:30
2026-04-22 08:03:32 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-22 08:03:32 +02:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-02-17 17:49:56 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:45:32 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:45:32 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-03-02 13:24:25 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-02-23 09:48:12 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-03-20 20:32:07 +05:30
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-02 11:21:09 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-05-01 10:51:29 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2025-11-10 16:03:39 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-01-22 11:17:38 -06:00
2026-04-30 12:24:01 -04:00
2026-05-01 10:51:29 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2026-04-02 11:21:09 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-30 17:38:22 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00