| elastic |
Kernel Module Load from Unusual Location |
production |
2026-09-18 |
| elastic |
Kubernetes Sensitive Configuration File Activity |
production |
2026-09-18 |
| elastic |
Kubernetes Static Pod Manifest File Access |
production |
2026-09-18 |
| elastic |
Suspicious File Creation via Kworker |
production |
2026-09-18 |
| elastic |
Potential Linux Backdoor User Account Creation |
production |
2026-09-18 |
| elastic |
Linux Group Creation |
production |
2026-09-18 |
| elastic |
Linux User Added to Privileged Group |
production |
2026-09-18 |
| elastic |
Loadable Kernel Module Configuration File Creation |
production |
2026-09-18 |
| elastic |
Manual Dracut Execution |
production |
2026-09-18 |
| elastic |
Message-of-the-Day (MOTD) File Creation |
production |
2026-09-18 |
| elastic |
Process Spawned from Message-of-the-Day (MOTD) |
production |
2026-09-18 |
| elastic |
NetworkManager Dispatcher Script Creation |
production |
2026-09-18 |
| elastic |
OpenSSL Password Hash Generation |
production |
2026-09-18 |
| elastic |
Pluggable Authentication Module or Configuration Creation |
production |
2026-09-18 |
| elastic |
Pluggable Authentication Module (PAM) Creation in Unusual Directory |
production |
2026-09-18 |
| elastic |
Potential Backdoor Execution Through PAM_EXEC |
production |
2026-09-18 |
| elastic |
Pluggable Authentication Module (PAM) Source Download |
production |
2026-09-18 |
| elastic |
Polkit Policy Creation |
production |
2026-09-18 |
| elastic |
Executable Bit Set for Potential Persistence Script |
production |
2026-09-18 |
| elastic |
Process Capability Set via setcap Utility |
production |
2026-09-18 |
| elastic |
Python Path File (pth) Creation |
production |
2026-09-18 |
| elastic |
Suspicious rc.local Error Message |
production |
2026-09-18 |
| elastic |
Potential Execution of rc.local Script |
production |
2026-09-18 |
| elastic |
rc.local/rc.common File Creation |
production |
2026-09-18 |
| elastic |
RPM Package Installed by Unusual Parent Process |
production |
2026-09-18 |
| elastic |
Setcap setuid/setgid Capability Set |
production |
2026-09-18 |
| elastic |
Shadow File Modification by Unusual Process |
production |
2026-09-18 |
| elastic |
Shell Configuration Creation |
production |
2026-09-18 |
| elastic |
Potential Privilege Escalation via Linux DAC permissions |
production |
2026-09-18 |
| elastic |
File System Debugger Launched Inside a Container |
production |
2026-09-18 |
| elastic |
Potential Docker Escape via Nsenter |
production |
2026-09-18 |
| elastic |
Potential Chroot Container Escape via Mount |
production |
2026-09-18 |
| elastic |
Docker Release File Creation |
production |
2026-09-18 |
| elastic |
Potential Privilege Escalation via Enlightenment |
production |
2026-09-18 |
| elastic |
Privilege Escalation via GDB CAP_SYS_PTRACE |
production |
2026-09-18 |
| elastic |
Root Network Connection via GDB CAP_SYS_PTRACE |
production |
2026-09-18 |
| elastic |
Suspicious Kworker UID Elevation |
production |
2026-09-18 |
| elastic |
Modification of Dynamic Linker Preload Shared Object |
production |
2026-09-18 |
| elastic |
Suspicious Symbolic Link Created |
production |
2026-09-18 |
| elastic |
Kernel Load or Unload via Kexec Detected |
production |
2026-09-18 |