Query
CVE-2025-1146 System Scoping (OsVersionInfo with Logon Data)
LogScale · Detection & Monitoring · v2 · @sebastian · 25.7.2026
The query below will look for Linux systems (Linux, K8, Containers) that need to be updated against CVE-2025-1146. The query is based on the event OsVersionInfo which is generated every 24-hours, at sensor start, or at sensor update. It attempts to merge in LogonType 2 and 10 to determine the last logged on user.
AuthenticationDetectionEndpointKubernetesLinux
Query contentv2
Download v2Loading editor…
Version history
Every save keeps the previous content. Open any version to view or download it.