Elastic high stable eql
Potential Privilege Escalation via CVE-2023-4911
This rule detects potential privilege escalation attempts through Looney Tunables (CVE-2023-4911). Looney Tunables is a buffer overflow vulnerability in GNU C Library's dynamic loader's processing of the GLIBC_TUNABLES environment variable.
Detection Logic
sequence by host.id, process.parent.entity_id, process.executable with maxspan=5s
[process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and
process.env_vars : "*GLIBC_TUNABLES=glibc.*=glibc.*=*"] with runs=5 Field Validations
Loading…
Comments (0)
Loading comments...