LogScale Queries

Query

CVE-2025-1146 System Scoping (OsVersionInfo with Logon Data)

LogScale · Detection & Monitoring · v2 · @sebastian · 25.7.2026

All Queries

The query below will look for Linux systems (Linux, K8, Containers) that need to be updated against CVE-2025-1146. The query is based on the event OsVersionInfo which is generated every 24-hours, at sensor start, or at sensor update. It attempts to merge in LogonType 2 and 10 to determine the last logged on user.

AuthenticationDetectionEndpointKubernetesLinux

Query contentv2

Download v2
Loading editor…

Version history

Every save keeps the previous content. Open any version to view or download it.

  1. v2current

    25.7.2026, 10:15:56

  2. v1

    24.7.2026, 18:50:49

CVE-2025-1146 System Scoping (OsVersionInfo with Logon Data) | LogScale Query Exchange