Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
2 detections
Filters
Last updated
All Time
Detection languages
2
Contributors
2
Categories
2
1
1
1
1
Platforms
2
Products / Services
2
1
MITRE Techniques
2
2
1
1
1
CVEs
68
68
60
58
50
Detects attempts to grant world-writable (0666) permissions to the /dev/kvm device node using chmod or setfacl, or unauthorized (non-root) accounts interacting directly with the device. Such configuration changes are associated with the Januscape (CVE-2026-53359) vulnerability, which allows local users to exploit a shadow MMU use-after-free in the kernel to escalate privileges to root or escape into the host from a virtualized environment.
Identifies Linux systems acting as KVM hypervisors that are running kernels vulnerable to CVE-2026-53359 (Januscape), a use-after-free vulnerability in the shadow MMU (arch/x86/kvm/mmu/mmu.c). This vulnerability permits a guest virtual machine to escape into the underlying host environment, potentially compromising the hypervisor and other hosted workloads.
