🐧Linux detections
Clankerusecase tracks 549 detection use cases covering the Linux attack surface across 161 MITRE ATT&CK techniques.
Detections targeting Linux servers and workstations — auditd / Sysmon for Linux / syslog.
549Use cases
161Techniques
60Articles
6Kill-chain phases
Top techniques on Linux (25)
Exploitation (122)
[WEEKLY] Auth-Bypass on Public-Facing Service → Post-Exploit Action on Same Host (≤10 min) Internal exploit · alerting DSPDD [WEEKLY] Developer/AI tooling runtime spawns shell or egress LOLBin (unauth RCE post-expl) Internal exploit · alerting DSPDDCS [WEEKLY] Developer/Data-tooling Daemon Spawns Shell Child Seconds After POST to Runner/Exec Endpoint Internal exploit · alerting DSPDD [WEEKLY] Internet-facing service process spawns shell/LOLBin within minutes of public inbound connection — post-RCE command execution Internal exploit · alerting DSΣPDD [WEEKLY] Language-runtime server (node/python/java) spawns OS shell shortly after inbound request — eval / sandbox-escape exploitation chain Internal exploit · alerting DSPDD [WEEKLY] Linux LPE chain — anomalous algif_aead/esp4/esp6/rxrpc kernel-module load followed by same-user root transition Internal exploit · alerting DSPDD [WEEKLY] Low-Code / AI Workflow Runtime Sandbox-Escape — Server Process Spawns Shell + Public Egress Internal exploit · alerting DSΣPDD [WEEKLY] Public-Facing App Runtime Spawns Shell, LOLBin, or Container-Control Tool Internal exploit · alerting DSΣPDD [WEEKLY] Self-hosted application service spawns shell or SSH within seconds of inbound unauthenticated API write Internal exploit · alerting DSPDD [WEEKLY] Server / AI-agent process spawns shell or LOLBIN with public egress — post-RCE behavioural chain Internal exploit · alerting DSΣPDD [WEEKLY] Service-process parent spawns subprocess containing CLI-argument-injection tokens Internal exploit · alerting DSΣPDD [WEEKLY] Web App Interpreter (Node/Python/Java/PHP) Spawns Shell or Net-Download LOLBin on Internet-Facing Host Internal exploit · alerting DSPDD Article-specific behavioural hunt — Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Bespoke exploit · hunting DSP [LLM] Cisco FMC www account runs package_info.pl on staged /var/tmp/license.tmp (CVE-2026-20316/20079) Bespoke exploit · alerting SΣPDD [LLM] Cisco FMC www web-service account escalating to root via sudo under /usr/local/sf/bin/ Bespoke exploit · hunting SPDD [LLM] JFrog Artifactory service process spawning a shell or downloader (RCE exploitation) Bespoke exploit · alerting DSΣPCS [LLM] Ruflo MCP bridge unauthenticated tools/call terminal_execute (RufRoot CVE-2026-59726) Bespoke exploit · alerting SΣPDD [LLM] Ruflo/Node MCP bridge spawning interactive shell inside container (RufRoot RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] Gitea git process spawning shell / network tool via planted hook (CVE-2026-60004 RCE) Bespoke exploit · alerting DSΣPDDCS [LLM] ClickHouse query_log shows injected SQL from @hypequery escapeValue bypass Bespoke exploit · hunting SPDD [LLM] ClickHouse SQL syntax-error spike from @hypequery/clickhouse injection probing Bespoke exploit · alerting SPDD [LLM] Vulnerable goshs SFTP launch: empty-credential basic-auth (-b 'user:' / ':pass') with -sftp and no -fkf Bespoke exploit · alerting DSΣPDDCS [LLM] JFrog Artifactory service process spawning a shell or network tool (RCE) Bespoke exploit · alerting DSΣPCS [LLM] Linux root process executed from memfd (CVE-2026-53264 core-dump payload) Bespoke exploit · alerting DSΣPDDCS [LLM] Unprivileged Linux tc clsact/flower/gact traffic-control manipulation (CVE-2026-53264 trigger) Bespoke exploit · hunting DSΣPDDCS [LLM] Fastjson 1.x CVE-2026-16723 exploit payload in inbound JSON (@type + nested JAR / /proc/self/fd) Bespoke exploit · hunting SΣP [LLM] GitLab Puma/Ruby worker (running as git) spawns shell or network tool — Oj .ipynb RCE landing Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Compromised PyPI Package: mrmustard 0.7.4 Steals SSH, Cloud, and Kubernetes Cred Bespoke exploit · hunting DSP [LLM] OpenDJ SASL PLAIN bind invoking proxied authorization (authzid) — impersonation Bespoke exploit · hunting SΣPDD Article-specific behavioural hunt — [GHSA / CRITICAL] GHSA-r277-6w6q-xmqw: kin-openapi: ValidationHandler.Load() Fai Bespoke exploit · hunting DSP [LLM] Web/interpreter process connecting to internal HiveServer2 (10000) or Hadoop NameNode (50070) Bespoke exploit · alerting DSΣPCS [LLM] LinPEAS / SUID sweep privilege-escalation enumeration on Linux Bespoke exploit · hunting DSΣPDDCS [LLM] redis-server spawns a shell/interpreter (system() from Redis RCE chain) Bespoke exploit · alerting DSΣPCS [LLM] EnvoyExtensionPolicy Lua with double-slash path traversal to secrets (CVE-2026-53713) Bespoke exploit · alerting SΣPDD Article-specific behavioural hunt — The npm Threat Landscape: Attack Surface and Mitigations (Updated July 15) Bespoke exploit · hunting DSP [LLM] ATTACH DATABASE statement targeting persistence paths in Anyquery query logs Bespoke exploit · hunting SPDD Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-47677: FacturaScripts: Account takeover of any 2FA-en Bespoke exploit · hunting DSP [LLM] DIRAC FileCatalog checkDataset SQL injection carrying Python eval gadget (CVE-2026-61667) Bespoke exploit · hunting SPDD [LLM] DIRAC ReqManager service (CVE-2026-45579) spawning a shell or recon/egress binary Bespoke exploit · alerting DSΣP [LLM] TSDProxy x-tsdproxy-auth-token leaked to backend in upstream HTTP requests Bespoke exploit · hunting SPDD [LLM] TSDProxy management-port replay: loopback connection to 127.0.0.1:8080 by non-proxy process Bespoke exploit · alerting DSΣPCS [LLM] File Browser hook-auth pre-auth RCE: filebrowser spawns shell/recon commands (CVE-2026-54088) Bespoke exploit · alerting DSΣPCS [LLM] FileBrowser proxy-auth header forgery naming admin on /api/login Bespoke exploit · alerting SΣPDD [LLM] YesWiki CalcField exploit attempts — PHP parse/fatal errors from CalcField.php in syslog Bespoke exploit · hunting SPDD [LLM] YesWiki web-server process spawning an OS shell (deserialization RCE outcome) Bespoke exploit · alerting DSΣPDDCS [LLM] Git-spawned hook execution during recursive clone (CVE-2024-32002) Bespoke exploit · alerting DSΣPDDCS [LLM] Joro native plugin RCE: joro process spawns interactive /bin/bash shell (CVE-2026-53649) Bespoke exploit · alerting DSΣPCS [LLM] Nuclio CronJob container args carry injected shell (CVE-2026-52831 header/body OS command injection) Bespoke exploit · alerting SPDD [LLM] Cypher injection primitives in Langroid LLM prompt / inbound HTTP input Bespoke exploit · hunting SPDD [LLM] Neo4j executes attacker-primitive Cypher (apoc.*, dbms.*, LOAD CSV) via query.log Bespoke exploit · alerting SΣPDD [LLM] Langroid Python agent spawning shell/downloader child (os.system RCE) Bespoke exploit · hunting DSΣPCS [LLM] Langroid eval() exploit signature: __import__('os') / full_eval=True in cmdline or app logs Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Camel gridfs.* control-header injection inbound (CVE-2026-48204 exploit) Bespoke exploit · hunting SΣPDD [LLM] GitHub Actions runner spawns network tool / interpreter under compromised trivy-action or KICS Bespoke exploit · hunting DSΣPDDCS [LLM] 9router (node) process spawning 'sudo -S sh' — CVE-2026-59800 command injection primitive Bespoke exploit · hunting DSΣPDDCS [LLM] zebrad node process execution at vulnerable version (CVE-2026-52735) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — [GHSA / CRITICAL] CVE-2026-50027: mcp-memory-service: Missing Authentication on Bespoke exploit · hunting DSP [LLM] Ghost x-ghost-preview request carrying XSS payload markers (CVE-2026-53943 execution) Bespoke exploit · alerting SΣPDD [LLM] Bun runtime executing a temp payload spawned by node (Miasma Node.js-monitoring evasion) Bespoke exploit · hunting DSΣPDDCS [LLM] Bun executes dropped temp payload /tmp/p*.js (Miasma stealer launch) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Pythagora-io/gpt-pilot Compromised on GitHub - Shai-Hulud Credential Stealer Blo Bespoke exploit · hunting DSP Article-specific behavioural hunt — Wait, binding.gyp Can Do What? Exploring npm's Weirdest Build System Bespoke exploit · hunting DSP [LLM] Phantom Gyp: node-gyp install-time code execution via weaponized binding.gyp Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Legitimate-Looking Codex Remote UI Secretly Steals Your AI Tokens Bespoke exploit · hunting DSP Article-specific behavioural hunt — Microsoft's durabletask package on PyPi Compromised. Mini Shai Hulud attacks aga Bespoke exploit · hunting DSP Article-specific behavioural hunt — Shai-Hulud Worm Pivots to Multi-Cloud: intercom-client@7.0.4 Hijacked — 361,000 Bespoke exploit · hunting DSP Article-specific behavioural hunt — Malicious Release of elementary-data PyPI Package Steals Cloud Credentials from Bespoke exploit · hunting DSP Article-specific behavioural hunt — hackerbot-claw: An AI-Powered Bot Actively Exploiting GitHub Actions - Microsoft Bespoke exploit · hunting DSP [LLM] TeamPCP Linux/Mac stdin-piped Python second stage (sys.executable -) Bespoke exploit · hunting DSPDDCS Article-specific behavioural hunt — How a Poisoned Security Scanner Became the Key to Backdooring LiteLLM Bespoke exploit · hunting DSP Article-specific behavioural hunt — CanisterWorm Gets Teeth: TeamPCP's Kubernetes Wiper Targets Iran Bespoke exploit · hunting DSP Article-specific behavioural hunt — TeamPCP deploys CanisterWorm on NPM following Trivy compromise Bespoke exploit · hunting DSP [LLM] BodySnatcher (CVE-2025-12420) — Hardcoded 'servicenowexternalagent' Token Observed in HTTP Traffic Bespoke exploit · alerting DSΣPDDCS [LLM] Node.js process spawning interactive shell — suspected post-exploit RCE on Next.js / RSC server Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Malicious MCP Server on npm postmark-mcp Harvests Emails Bespoke exploit · hunting DSP Article-specific behavioural hunt — Weaponizing AI Coding Agents for Malware in the Nx Malicious Package Security In Bespoke exploit · hunting DSP Article-specific behavioural hunt — Reconstructing the TJ Actions Changed Files GitHub Actions Compromise Bespoke exploit · hunting DSP [LLM] Malicious tj-actions base64 payload prefix observed in process command line Bespoke exploit · alerting DSΣPDDCS [LLM] Apache Spark CVE-2022-33891 doAs command injection — shell spawned by Spark JVM running 'id -Gn' with metacharacters Bespoke exploit · alerting DSΣPDDCS [LLM] GitPython CVE-2022-24439 RCE — git 'ext::sh' transport command injection via crafted clone URL Bespoke exploit · alerting DSΣPDDCS [LLM] GitHub Actions branch-name template injection — bash brace-expansion shell signature Bespoke exploit · alerting DSΣPDDCS [LLM] ImageMagick 'convert -resize' command injection via sh -c in Go web app Bespoke exploit · hunting DSΣPDDCS [LLM] cups-browsed spawning foomatic-rip or shell child (CVE-2024-47177 RCE) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk Fetch the Flag CTF 2023 writeup: Off the SETUID Bespoke exploit · hunting DSP [LLM] PHP CLI dev server (php -S) spawning a shell or child interpreter (proc_open php -a) Bespoke exploit · alerting DSΣPDDCS [LLM] Curl invoked with SOCKS5-hostname resolution (CVE-2023-38545 exploit precondition) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — What are AI hallucinations and why should developers care? Bespoke exploit · hunting DSP [LLM] Ruby/Rails app server spawning a Unix shell (post-deserialization RCE) Bespoke exploit · alerting DSΣPCS [LLM] Pistache CVE-2022-26068 path traversal reading /etc/passwd via /doc/../ Bespoke exploit · alerting SΣP [LLM] curl --path-as-is traversal command exfiltrating /proc/self/exe or /etc/passwd Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — NPM security: preventing supply chain attacks Bespoke exploit · hunting DSP [LLM] Server application runtime spawning shell with /dev/tcp redirection (RCE to reverse shell) Bespoke exploit · alerting DSΣPCS [LLM] Node.js web process overwriting application .js service file (GraphQL path-traversal file write) Bespoke exploit · hunting DSΣPCS [LLM] Dirty Pipe (CVE-2022-0847): /etc/passwd or /etc/shadow modified by unexpected process Bespoke exploit · alerting DSΣPCS [LLM] Dirty Pipe SUID hijack: root-privileged process executing from /tmp or /dev/shm Bespoke exploit · alerting DSΣPDDCS [LLM] Celery worker (Python) spawning a shell — CVE-2021-23727 stored command injection Bespoke exploit · hunting DSΣPCS [LLM] PwnKit pkexec executed with empty argv (CVE-2021-4034 exploit primitive) Bespoke exploit · alerting DSΣPDDCS [LLM] PwnKit GCONV_PATH artifact directory/file creation Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — URL confusion vulnerabilities in the wild: Exploring parser inconsistencies Bespoke exploit · hunting DSP [LLM] Tomcat/Java server process spawning an OS command shell (CVE-2020-9484 RCE outcome) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Snyk uncovers malicious code activities in open source supply chain security on Bespoke exploit · hunting DSP Article-specific behavioural hunt — Developer driven workflows: Dockerfile image scanning, prioritization, and remed Bespoke exploit · hunting DSP Article-specific behavioural hunt — How I was hacking docker containers by exploiting ImageMagick vulnerabilities Bespoke exploit · hunting DSP [LLM] ImageMagick convert spawning shell/LOLBin child (ImageTragick CVE-2016-3714 RCE) Bespoke exploit · alerting DSΣPCS Article-specific behavioural hunt — 10 Kubernetes Security Context settings you should understand Bespoke exploit · hunting DSP Article-specific behavioural hunt — Command line tools for containers—using Snyk with Buildah, Podman, and Skopeo Bespoke exploit · hunting DSP [LLM] Unprivileged user-namespace creation (unshare CLONE_NEWUSER) preceding Linux privilege escalation Bespoke exploit · hunting DSΣPDDCS [LLM] systeminformation inetChecksite curl argument injection (CVE-2020-7752) Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Python Poetry package manager and security integration with software composition Bespoke exploit · hunting DSP [LLM] Apache Airflow Celery worker spawns non-airflow child (command-injection RCE, CVE-2020-11981) Bespoke exploit · alerting DSΣPCS [LLM] Apache Airflow task run with --pickle flag (pickle deserialization, CVE-2020-11982) Bespoke exploit · hunting DSΣPDDCS [LLM] Prototype pollution payload in CLI args (--__proto__ / constructor.prototype) to Node tool Bespoke exploit · alerting DSΣPDDCS Article-specific behavioural hunt — Understanding filesystem takeover vulnerabilities in npm JavaScript package mana Bespoke exploit · hunting DSP [LLM] Webmin RCE: miniserv/password_change.cgi spawning reverse shell (CVE-2019-15107) Bespoke exploit · alerting DSΣPDDCS [LLM] EC2 instance IMDS credential theft via curl/wget to security-credentials path Bespoke exploit · hunting DSΣPDDCS [LLM] runc /proc/self/exe re-exec abuse (CVE-2019-5736 exploit primitive) Bespoke exploit · hunting DSΣPDDCS [LLM] Bower archive extraction arbitrary file write to sensitive paths (CVE-2019-5484 / Zip Slip) Bespoke exploit · hunting DSΣPDDCS Article-specific behavioural hunt — Attacking an FTP Client: MGETting more than you bargained for Bespoke exploit · hunting DSP [LLM] FTP control-channel connection followed by write to Unix system path (CVE-2018-1315 traversal chain) Bespoke exploit · hunting DSPCS Article-specific behavioural hunt — Type Manipulation: Escaping Template Sandboxes Bespoke exploit · hunting DSP [LLM] Dust.js qs type-manipulation RCE payload in web request query string Bespoke exploit · alerting SΣP [LLM] ImageMagick binary spawning shell/recon process (ImageTragick CVE-2016-3714 delegate RCE) Bespoke exploit · hunting DSΣPCS Actions on Objectives (145)
[WEEKLY] Edge-service post-exploitation chain: internet-facing daemon → child shell or token redemption within 10 min of external request Internal actions · alerting DSPDD [WEEKLY] Non-Browser Process Reads Browser Credential / Cookie SQLite Then Egresses to Public Destination Within 10 Minutes Internal actions · alerting DSPDD [WEEKLY] npm-install spawned process performing cred-file fan-out plus IMDS reach Internal actions · alerting DSPDDCSCW [WEEKLY] Supply-chain repo credential theft → outbound exfil to attacker infra Internal actions · alerting DSPDD Linux Add Files In Known Crontab Directories ESCU actions · hunting P Linux Auditd At Application Execution ESCU actions · hunting P Linux Auditd Copy Fail Privilege Escalation ESCU actions · alerting P Linux Auditd Edit Cron Table Parameter ESCU actions · hunting P Linux Auditd Possible Append Cronjob Entry On Existing Cronjob File ESCU actions · hunting P Linux Auditd Service Restarted ESCU actions · hunting P Linux Auditd Service Started ESCU actions · hunting P Linux Common Process For Elevation Control ESCU actions · hunting P Linux Deleting Critical Directory Using RM Command ESCU actions · alerting P Linux Deletion Of Cron Jobs ESCU actions · hunting P Linux Dirty Frag Kernel Privilege Escalation ESCU actions · alerting P Linux Disable Services ESCU actions · alerting P Linux Docker Shell Execution ESCU actions · hunting P Linux Indicator Removal Clear Cache ESCU actions · alerting P Linux Iptables Firewall Modification ESCU actions · hunting P Linux Kworker Process In Writable Process Path ESCU actions · hunting P Linux Magic SysRq Key Abuse ESCU actions · alerting P Linux Medusa Rootkit ESCU actions · alerting P Linux Possible Access To Credential Files ESCU actions · hunting P Linux Possible Append Cronjob Entry on Existing Cronjob File ESCU actions · hunting P Linux Possible Cronjob Modification With Editor ESCU actions · hunting P Linux Service File Created In Systemd Directory ESCU actions · hunting P Linux Service Restarted ESCU actions · hunting P Linux Service Started Or Enabled ESCU actions · hunting P Linux Stop Services ESCU actions · alerting P Linux System Reboot Via System Request Key ESCU actions · alerting P Linux Unix Shell Enable All SysRq Functions ESCU actions · hunting P MacOS Keychains Dumped ESCU actions · alerting P MacOS plutil ESCU actions · alerting P [LLM] Cloud instance metadata (IMDS 169.254.169.254) queried by a recon tool inside a workload Bespoke actions · hunting DSΣPDDCS [LLM] Rails/libvips worker reading process environment or system secrets (CVE-2026-66066 file-read) Bespoke actions · alerting SΣPCS [LLM] Fluentd aggregator pod reaches cloud IMDS 169.254.169.254 (credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Ruflo AgentDB memory poisoning via MCP pattern-store write Bespoke actions · hunting SΣPDD [LLM] Cloud instance-metadata (IMDS 169.254.169.254) credential theft by interpreter/shell in pipeline pod Bespoke actions · alerting DSΣDDCS [LLM] goshs process deletes or renames served files while launched with --no-delete (impact confirmation) Bespoke actions · alerting DSΣPDDCS [LLM] vBulletin web-server process (php-fpm/apache/nginx) spawning OS shell after CVE-2026-61511 Bespoke actions · alerting DSΣPDDCS [LLM] Successful IPMI/BMC login from unexpected source using default ADMIN/root accounts Bespoke actions · hunting SPDD [LLM] vBulletin web-server process (php-fpm/httpd/w3wp) spawning OS shell — CVE-2026-61511 post-exploitation Bespoke actions · alerting DSΣPDDCS [LLM] n8n/Node child command accessing N8N_ENCRYPTION_KEY or host credential stores Bespoke actions · alerting DSΣPDDCS [LLM] OpenDJ proxied-auth fan-out — one source assuming many distinct authz identities Bespoke actions · hunting SPDD [LLM] Microsoft Kiota APIPlugin manifest generation from OpenAPI spec (CVE-2026-59864) Bespoke actions · hunting DSΣPDDCS [LLM] Gitea webhook/migration SSRF reaching cloud metadata endpoints (IMDS / Azure WireServer) Bespoke actions · hunting DSΣPDDCS [LLM] actions/attest push-to-registry invocation using @sigstore/oci — externally influenced destination (CVE-2026-59891) Bespoke actions · hunting DSΣPDDCS [LLM] Build/attestation tooling reading ~/.docker/config.json (credential harvest surface, CVE-2026-59891) Bespoke actions · hunting DSΣPCS [LLM] Siemens ROX II xz utility misused as cat to read root-owned secrets (CVE-2025-40948) Bespoke actions · hunting DSΣDD [LLM] Leaked SA token / file contents in EnvoyExtensionPolicy status (CVE-2026-53713 disclosure) Bespoke actions · alerting SΣPDD [LLM] Post-RCE read of DIRAC dirac.cfg / proxy / token stores on FileCatalog host Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC service process deletes or truncates its own logs (anti-forensics post-RCE) Bespoke actions · hunting DSΣPDDCS [LLM] DIRAC post-exploit read of dirac.cfg by a shell/read utility (CVE-2026-45579 credential theft) Bespoke actions · hunting DSΣPDDCS [LLM] TSDProxy management API abuse: /api/v1 request with forged x-tsdproxy-id and auth token Bespoke actions · alerting SPDD [LLM] YesWiki credential access — web user reads wakka.config.php / .env / /etc/passwd Bespoke actions · hunting DSΣPDDCS [LLM] Nuclio cron pod shell reads Kubernetes service-account token (CVE-2026-52831 credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] EGroupware web runtime (php-fpm/apache) spawning a shell or network tool — CVE-2026-27823 RCE execution Bespoke actions · hunting DSΣPCS [LLM] Mass graph destruction via unbounded DETACH DELETE in Neo4j query.log Bespoke actions · alerting SΣPDD [LLM] Cilium Envoy admin socket abuse: TLS secret / config disclosure via admin.sock (CVE-2026-49445) Bespoke actions · hunting DSΣPDDCS [LLM] Cilium Envoy admin socket abuse: destructive DoS via /quitquitquit /drain_listeners (CVE-2026-49445) Bespoke actions · alerting DSΣPDDCS [LLM] Credential harvest via /proc/<pid>/mem read of GitHub Actions Runner.Worker Bespoke actions · hunting DSΣPDDCS [LLM] GitHub Actions Runner.Worker memory read via /proc/<pid>/mem (CI secret unmasking) Bespoke actions · alerting DSΣPDDCS [LLM] Runner.Worker process memory scrape via /proc on self-hosted GitHub Actions runner Bespoke actions · alerting DSΣPDDCS [LLM] Atomic Arch infostealer: build-spawned process harvesting SSH keys, dev tokens and browser/Electron sessions Bespoke actions · hunting DSΣPCS [LLM] CI runner secret theft via /proc/<pid>/mem read of Runner.Worker (Miasma memory scraper) Bespoke actions · hunting SΣPCS [LLM] Lateral movement via aws ssm send-command or kubectl exec spawned by python/node Bespoke actions · alerting DSΣPDDCSCW [LLM] Cloud credential file access by node/python runtime Bespoke actions · hunting DSΣPDDCS [LLM] Locale-conditional rm -rf wiper command from python/node runtime Bespoke actions · alerting DSΣPDDCS [LLM] Process reading /proc/<pid>/mem of GitHub Actions Runner.Worker (in-memory secret extraction) Bespoke actions · alerting DSΣPDDCS [LLM] Orphaned process (ppid=1) executing from /tmp hidden hex path (post-dropper stage-2) Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: telemetry.js postinstall harvesting tokens via gh auth token Bespoke actions · alerting DSΣPDDCS [LLM] s1ngularity Nx compromise: results.b64 credential dump written on developer host Bespoke actions · alerting DSΣPDDCS [LLM] AWS IMDS (169.254.169.254) Hit from Developer / Non-EC2 Endpoint (Nx Console Credential Theft) Bespoke actions · hunting DSPDDCS [LLM] AI coding agent bulk-deleting JUnit test files after jqwik resolution Bespoke actions · alerting DSPDDCS [LLM] node child of npm/yarn/pnpm reading cloud and CI credential files (Miasma sweep) Bespoke actions · alerting DSPDDCS [LLM] Mini Shai-Hulud npm worm exfil to filev2.getsession.org Bespoke actions · alerting DSPDDCS [LLM] postmark-mcp BCC exfil to giftshop.club Bespoke actions · alerting DSΣPDDCS [LLM] Non-Codex-CLI node process reading ~/.codex/auth.json (Codex OAuth credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: curl POST to C2 /collect endpoint on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Megalodon harvester: bash secret-grep across workspace (API_KEY|SECRET|TOKEN|PRIVATE_KEY|BEGIN RSA) Bespoke actions · hunting DSΣPDDCS [LLM] Megalodon harvester: clustered read of ~/.ssh/id_*, ~/.kube/config, ~/.npmrc, ~/.docker/config.json in one session Bespoke actions · hunting DSPDDCS [LLM] Developer credential store read by Python or Node spawned from VS Code (Nx Console stealer pattern) Bespoke actions · hunting DSPDDCS [LLM] VS Code extension host fan-out reads of developer secrets (.ssh, .aws, .npmrc, ~/.claude/settings.json) Bespoke actions · hunting DSPDDCS [LLM] Python Process Reading Multi-Cloud Credential Stores (durabletask Stealer Stage) Bespoke actions · hunting DSPDDCS [LLM] Kubernetes propagation via kubectl staged in /tmp (kubectl exec / get secrets) Bespoke actions · alerting DSΣPDDCS [LLM] GitHub Actions Runner.Worker process-memory secret scraping via /proc Bespoke actions · hunting DSΣPDDCS [LLM] python3 reading /proc/<PID>/mem to scrape Runner.Worker secrets Bespoke actions · alerting DSΣPDDCS [LLM] Outbound egress to node-ipc stealer infrastructure (azurestaticprovider[.]net / 37.16.75.69) Bespoke actions · alerting DSΣPDDCS [LLM] node.js process staging credential dump in nt-* temp directory Bespoke actions · hunting DSΣPDDCS [LLM] Mini Shai-Hulud dead-drop git commit authored as claude@users.noreply.github.com Bespoke actions · alerting DSΣPDDCS [LLM] Node/npm/Bun process enumerating cloud, wallet, AI, and messaging credential file paths Bespoke actions · hunting DSPDDCS [LLM] Stage-3 exfil archive trin.tar.gz POST via curl --data-binary Bespoke actions · alerting DSΣPDDCS [LLM] Mini Shai-Hulud: Bun runtime executing `router_runtime.js` (2nd-stage stealer) Bespoke actions · alerting DSΣPDD [LLM] Svix Ingest webhook exfiltration relay (src_3387PLMB2uhXOBe3Q8sHu) Bespoke actions · alerting DSΣPDDCS [LLM] Node.js postinstall reading .env / .env.* during package install Bespoke actions · alerting DSPDDCS [LLM] Java/Tomcat process spawns OS command interpreter (post-Thymeleaf SSTI RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Credential archive staging — trin.tar.gz created by python process Bespoke actions · alerting DSΣPDDCS [LLM] Read of /proc/<pid>/mem targeting GitHub Runner.Worker (TeamPCP credential dump) Bespoke actions · alerting DSΣPDD [LLM] plain-crypto-js setup.js self-deletion or package.json overwrite (anti-forensics) Bespoke actions · hunting DSΣPDDCS [LLM] hackerbot-claw token exfiltration: curl POST with GITHUB_TOKEN to recv.hackmoltrepeat.com Bespoke actions · alerting DSΣPDDCS [LLM] Access to OpenClaw credential store (~/.openclaw/credentials/, ~/.openclaw/config.json5) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive tpcp.tar.gz created on disk Bespoke actions · alerting DSΣPDDCS [LLM] Python process spawning shell with TeamPCP recon chain (hostname; whoami; uname; ip addr fallback) Bespoke actions · alerting DSΣPDDCS [LLM] Python process contacting AWS IMDS 169.254.169.254 (litellm stealer IAM credential theft) Bespoke actions · alerting DSΣPDDCS [LLM] In-cluster Kubernetes secret enumeration with Python user-agent (litellm stealer K8s pivot) Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP exfiltration archive — tpcp.tar.gz file creation on host Bespoke actions · alerting DSΣPDD [LLM] GitHub Actions runner credential stealer: python3 base64-decoded payload reading /proc/<pid>/mem Bespoke actions · hunting DSPDD [LLM] Exfil staging artefacts: session.key, payload.enc, session.key.enc, tpcp.tar.gz in temp Bespoke actions · alerting DSΣPDDCS [LLM] TeamPCP Linux credential harvest: Python reading /etc/shadow + auth.log + cloud Bespoke actions · hunting DSPDDCS [LLM] Host-root mount wiper: chroot /mnt/host reboot -f or rm -rf / --no-preserve-root Bespoke actions · alerting DSΣPDDCS [LLM] Compromised kubernetes.el destructive payload — Emacs spawning `rm -rf / --no-preserve-root` Bespoke actions · alerting DSΣPDD [LLM] Outbound traffic to *.oastify.com (BurpSuite Collaborator) from corporate endpoint Bespoke actions · alerting DSΣPDDCS [LLM] npm install referencing GitHub commit SHA (github:owner/repo#sha) — dangling-commit supply chain hunt Bespoke actions · hunting DSΣPDDCS [LLM] npm/node post-install (telemetry.js) spawning credential CLIs (gh auth token / npm whoami) — s1ngularity Nx Bespoke actions · alerting DSΣPDDCS [LLM] Ultralytics PyPI supply-chain XMRig coinminer execution from /tmp/ultralytics_runner Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files compromise: memdump.py secret-exfiltration shell pattern on runner (CVE-2025-30066) Bespoke actions · alerting DSΣPDD [LLM] SKILL.md file written referencing fabricated openclaw-core prerequisite (ClawHub skill social engineering hook) Bespoke actions · hunting DSPDDCS [LLM] AI session-log harvest via prompt-log extract.sh writing markdown with embedded secrets Bespoke actions · alerting DSΣPDDCS [LLM] GhostChat C2 beacon URL pattern: hitpak.org/page.php?tynor=<host>sss<user> Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity: npm postinstall weaponizes AI CLI tools (claude/gemini/q) for credential recon Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity exfiltration via public GitHub repo 's1ngularity-repository' Bespoke actions · alerting DSΣPDDCS [LLM] tj-actions/changed-files: CI runner pipes gist memdump.py to python to scrape secrets Bespoke actions · alerting DSΣPDDCS [LLM] TruffleHog secret-scanner execution on developer / CI host (SHA1-Hulud credential harvest) Bespoke actions · alerting DSΣPDDCS [LLM] Cloud metadata service (IMDS) access from npm / node child process Bespoke actions · alerting DSPDDCS [LLM] SHA1-Hulud wiper: mass deletion of user home directory by npm/node descendant Bespoke actions · alerting DSPDDCS [LLM] TruffleHog secret-scanner executed by node/npm postinstall context Bespoke actions · alerting DSΣPDDCS [LLM] Postinstall node child enumerating multiple developer credential stores Bespoke actions · hunting DSPDDCS [LLM] AI coding agent CLI (claude/gemini/q) invoked with permission-bypass flags Bespoke actions · alerting DSΣPDDCS [LLM] Nx s1ngularity inventory file written to /tmp (inventory.txt / inventory.txt.bak) Bespoke actions · alerting DSΣPDDCS [LLM] Node process creating GitHub repo via api.github.com (s1ngularity exfil channel) Bespoke actions · hunting DSPDDCS [LLM] Runner.Worker process memory dumped via /proc/PID/mem read on Linux runner Bespoke actions · alerting DSΣPDDCS [LLM] Git checkout of compromised tj-actions/changed-files commit on runner host Bespoke actions · hunting DSPDDCS [LLM] HTTP/2 server crash-loop on internet-facing host (CONTINUATION flood DoS exploitation signal) Bespoke actions · alerting DSPDDCS [LLM] Tomcat/Java process spawns OS shell or LOLBin (post-webshell RCE) Bespoke actions · alerting DSΣPDDCS [LLM] Container PID 1 environment harvest via /proc/1/environ read Bespoke actions · hunting DSΣPDDCS [LLM] Pistache binary theft via /doc/../../proc/self/exe path traversal Bespoke actions · alerting SΣP [LLM] Spring4Shell post-exploitation arbitrary file read (/etc/passwd via relocated docBase) Bespoke actions · alerting SΣPCS [LLM] CodeCov Bash Uploader CI env-var exfiltration via curl (<<<<<< ENV marker) Bespoke actions · alerting DSΣPDDCS [LLM] SuiteCRM upload/files .htaccess deleted by web-server process (PHAR gadget) Bespoke actions · alerting DSΣPCS [LLM] npm/node install hook exfiltrating /etc/passwd, kube config & krb5 ticket via wget --post-file Bespoke actions · alerting DSΣPDDCS [LLM] Arbitrary child process from systeminformation inetChecksite shell pipeline Bespoke actions · hunting DSΣP [LLM] Python interpreter reading SSH/GPG private keys (jeIlyfish key theft) Bespoke actions · hunting DSΣPCS [LLM] Rails/Ruby app worker (puma/unicorn/passenger) spawning a shell — post-eval RCE Bespoke actions · hunting DSΣPCS [LLM] FTP client / Hive (commons-net) overwrites Unix auth files via path-traversal LIST (CVE-2018-1315) Bespoke actions · alerting DSΣPCS [LLM] Node.js process spawning shell/curl to read and exfiltrate /etc/passwd (Dust.js post-exploit) Bespoke actions · alerting DSΣPDDCS
Recent articles citing Linux-targeted detections