Elastic high stable eql
Potential Privilege Escalation via unshare and UID Change
Identifies potentially suspicious use of unshare to create a user namespace context followed by a UID change event indicating a transition to root. Adversaries may use unshare-based primitives as part of local privilege escalation chains. This rule is intentionally generic and can surface multiple local privesc patterns beyond a single CVE.
Detection Logic
sequence by process.parent.entity_id, host.id with maxspan=60s
[process where host.os.type == "linux" and event.type == "start" and event.action == "exec" and
process.name == "unshare" and process.args : ("-r", "-rm", "-m", "-U", "--user") and user.id != "0"]
[process where host.os.type == "linux" and event.action == "uid_change" and event.type == "change" and
user.id == "0"] Field Validations
Loading…
Comments (0)
Loading comments...