Query
CVE-2025-1146 System Scoping (OsVersionInfo with Logon Data)
LogScale · Detection & Monitoring · v2 · @sebastian · 25.7.2026
The query below will look for Linux systems (Linux, K8, Containers) that need to be updated against CVE-2025-1146. The query is based on the event OsVersionInfo which is generated every 24-hours, at sensor start, or at sensor update. It attempts to merge in LogonType 2 and 10 to determine the last logged on user.
AuthenticationDetectionEndpointKubernetesLinux
Query contentv2
Download v2Loading editor…
Version history
By default each save creates a new version. Overwrites update the current version in place. Open any version to view or download it.