Skip to content

Copy Fail CVE-2026-31431 Sigma Rule Based on Module Loading#5971

Closed
st0pp3r wants to merge 2 commits into
SigmaHQ:masterfrom
st0pp3r:patch-2
Closed

Copy Fail CVE-2026-31431 Sigma Rule Based on Module Loading#5971
st0pp3r wants to merge 2 commits into
SigmaHQ:masterfrom
st0pp3r:patch-2

Conversation

@st0pp3r

@st0pp3r st0pp3r commented Apr 30, 2026

Copy link
Copy Markdown
Contributor

…ec.yml‎

Summary of the Pull Request

Detects the execution of the following commands within a 5-minute window: /sbin/modprobe -q -- net-pf-38, /sbin/modprobe -q -- algif-aead, /sbin/modprobe -q -- crypto-authencesn(hmac(sha256),cbc(aes)), When all three commands occur together this may indicate potential exploitation of Copy Fail (CVE-2026-31431).

Changelog

Example Log Event

image

Fixed Issues

SigmaHQ Rule Creation Conventions

  • If your PR adds new rules, please consider following and applying these conventions

@nasbench

nasbench commented May 4, 2026

Copy link
Copy Markdown
Member

Correlation are not yet accepted in this repo. Closing this and it will be revisited as part of the support for correlation in this PR #5759

@nasbench nasbench closed this May 4, 2026
@nasbench nasbench mentioned this pull request May 4, 2026
12 tasks
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants