Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
producthighSuspicious File Created in Outlook Temporary Directory
producthighSuspicious Outlook Macro Created
producthighPotential Persistence Via Outlook Form
producthighSuspicious Execution From Outlook Temporary Folder
producthighSuspicious Remote Child Process From Outlook
producthighSuspicious Outlook Child Process
Show all 19 top matches
producthighOutlook EnableUnsafeClientMailRules Setting Enabled
producthighPotential Persistence Via Outlook LoadMacroProviderOnBoot Setting
productlowBitbucket Project Secret Scanning Allowlist Added
producthighVisual Basic Command Line Compiler Usage
productmediumWow6432Node Windows NT CurrentVersion Autorun Keys Modification
producthighSuspicious Microsoft Office Child Process - MacOS
producthighCode Executed Via Office Add-in XLL File
producthighPotential Persistence Via Microsoft Office Add-In
producthighPotential Persistence Via Microsoft Office Startup Folder
producthighFile With Uncommon Extension Created By An Office Application
producthighOffice Macro File Creation From Suspicious Process
producthighUncommon File Created In Office Startup Folder
producthighPotentially Suspicious Office Document Executed From Trusted Location