THREAT OPS › Threat News › Linux Detection Engineering - Local Privilege Escalation
Linux Detection Engineering - Local Privilege Escalation
<p><a href="https://attack.mitre.org/tactics/TA0004/">Local privilege escalation</a> (LPE) is the step that turns a foothold into full control of a host. An attacker who lands as an unprivileged user rarely stops there. They want root, and Linux keeps offering new ways to get it.</p><p>In this edition of our "Linux Detection Engineering" series, we’ll cover:</p><ul><li><p>The default flow that a L
MITRE ATT&CK techniques
Indicators of compromise
- 4f957cd61fa2b85a2bce53b28c583e07ba020a94sha1
- 1eaa12aa6d2f2047a680d2260fa75e635dd4b9f6sha1
- 9a00306e5cccfb553949aae393a5cacfdedbda4csha1
- 3a0fda14e932ab7423fb350a2901e5c93d1db72fsha1
- dfd6970f99043ceae15286689eff6d243630a04bsha1
- a9208f465f486bf87dd614c463eb5e790d559a52sha1
- CVE-2026-64600cve
- CVE-2026-31431cve
- CVE-2026-43284cve
- CVE-2026-43500cve
- CVE-2026-46300cve
- CVE-2026-31635cve
- CVE-2026-46331cve
- CVE-2026-43503cve
- CVE-2026-46243cve
- CVE-2026-64531cve
- CVE-2026-46333cve
- https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-a-linux-kernel-local-privilege-escalation-to-root-in-xfs-cve-2026-64600url
- https://heyitsas.im/posts/ovswrap/url
- https://dfir.ch/posts/today_i_learned_binfmt_misc/url
- https://gtfobins.github.io/url
- https://www.cve.org/CVERecord?id=CVE-2026-31431url
- https://www.cve.org/CVERecord?id=CVE-2026-43284url
- https://www.cve.org/CVERecord?id=CVE-2026-43500url
- https://www.cve.org/CVERecord?id=CVE-2026-46300url
- https://www.cve.org/CVERecord?id=CVE-2026-46331url
- https://www.cve.org/CVERecord?id=CVE-2026-43503url
- https://www.cve.org/CVERecord?id=CVE-2026-46243url
- https://www.cve.org/CVERecord?id=CVE-2026-64531url
- https://www.cve.org/CVERecord?id=CVE-2026-46333url
- static-www.elastic.codomain