Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
productcriticalWmiexec Default Output File
productcriticalHackTool - QuarksPwDump Dump File
productcriticalWmiprvse Wbemcomn DLL Hijack - File
productcriticalHackTool - Dumpert Process Dumper Default File
productcriticalHackTool - Mimikatz Kirbi File Creation
producthighOpenCanary - SMB File Open Request
Show all 16 top matches
producthighPotential Local File Read Vulnerability In JVM Based Application
producthighRemote Encrypting File System Abuse
productcriticalLinux Reverse Shell Indicator
producthighCommunication To LocaltoNet Tunneling Service Initiated - Linux
producthighPotentially Suspicious Malware Callback Communication - Linux
producthighLinux Crypto Mining Pool Connections
producthighCommunication To Ngrok Tunneling Service - Linux
producthighLinux Crypto Mining Indicators
producthighShell Execution GCC - Linux
producthighShell Execution via Rsync - Linux