119 detection rules
+151 detection rules
auditd · sigma · yara · falco. One command emits the corpus for your SIEM. Each rule grounded in the module's own syscalls. @@ -227,7 +227,7 @@ uid=0(root) gid=0(root)
CISA KEV prioritized
- 10 of 26 CVEs in the corpus are in CISA's Known Exploited
+ 10 of 34 CVEs in the corpus are in CISA's Known Exploited
Vulnerabilities catalog — actively exploited in the wild.
Refreshed on demand via tools/refresh-cve-metadata.py.
tools/verify-vm/ spins up known-vulnerable
kernels (stock distro + mainline from kernel.ubuntu.com), runs
--explain --active per module, and records the
- verdict. 22 of 26 CVEs confirmed against
+ verdict. 28 of 34 CVEs confirmed against
real Linux across Ubuntu 18.04 / 20.04 / 22.04 + Debian 11 / 12
- + mainline 5.15.5 / 6.1.10. Records baked into the binary;
+ + mainline 5.4.0-26 / 5.15.5 / 6.1.10 / 6.19.7. Records baked into the binary;
--list shows ✓ per module.