Falco informational stable other

Potential Local Privilege Escalation via Environment Variables Misuse

Process run with suspect environment variable that could be attempting privilege escalation. One use case is detecting the use of the GLIBC_TUNABLES environment variable, which could be used for privilege escalation on systems running vulnerable glibc versions. Only known and carefully profiled processes that legitimately exhibit this behavior should be excluded from this rule. This rule is expected to trigger on every attempt, even failed ones.

View Source

Detection Logic

spawned_process and glibc_tunables_env

Field Validations

Loading…

Comments (0)

Loading comments...