Samirbous
f0467c8bed
[New] Suspicious SUID Binary Execution ( #6018 )
...
* [New] Suspicious SUDI Binary Execution
Detects execution of common privilege elevation helpers (su, sudo, pkexec, passwd, chsh, newgrp) under the root effective user when the real user and parent user are not root, combined with minimal argument counts and suspicious parent context (interpreters, short shell -c invocations, or parents running from user-writable paths) :
* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update rules/linux/privilege_escalation_suspicious_sudi_binary_execution.toml
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
* Update privilege_escalation_suspicious_sudi_binary_execution.toml
* Update privilege_escalation_suspicious_sudi_binary_execution.toml
* Rename privilege_escalation_suspicious_sudi_binary_execution.toml to privilege_escalation_suspicious_suid_binary_execution.toml
* Update privilege_escalation_suspicious_suid_binary_execution.toml
* Update privilege_escalation_suspicious_suid_binary_execution.toml
---------
Co-authored-by: Ruben Groenewoud <78494512+Aegrah@users.noreply.github.com >
2026-04-30 17:38:22 +01:00
..
2026-03-02 13:24:25 +01:00
2026-03-02 13:24:25 +01:00
2026-03-02 13:24:25 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 13:32:43 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:11:05 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-03-23 09:37:42 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2025-11-25 01:08:15 +05:30
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-19 09:19:24 -03:00
2026-01-08 10:11:05 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-03-20 20:32:07 +05:30
2026-04-22 08:03:32 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-01-07 15:55:06 +01:00
2026-04-22 08:03:32 +02:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 15:55:06 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-02-17 17:49:56 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:45:32 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:45:32 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-03-02 13:24:25 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-01-08 11:10:46 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-08 10:01:11 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-01-07 16:18:38 +01:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-02-23 09:48:12 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:18:38 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-03-20 20:32:07 +05:30
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-02 11:21:09 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-10 12:27:52 -04:00
2026-04-10 12:27:52 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2025-11-10 16:03:39 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2025-01-22 11:17:38 -06:00
2026-04-30 12:24:01 -04:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-01-07 16:31:13 +01:00
2026-04-02 11:21:09 +02:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-30 17:38:22 +01:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00
2026-04-01 09:12:42 -05:00