Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
producthighUAC Bypass Using .NET Code Profiler on MMC
producthighPotential AMSI Bypass Via .NET Reflection
producthighETW Logging Tamper In .NET Processes Via CommandLine
producthighETW Logging Disabled In .NET Processes - Registry
producthighETW Logging Disabled In .NET Processes - Sysmon Registry
producthighSuspicious Microsoft Office Child Process - MacOS
Show all 20 top matches
producthighRemote Access Tool - Renamed MeshAgent Execution - MacOS
producthighBinary Padding - MacOS
productmediumSuspicious Execution via macOS Script Editor
productmediumSystem Information Discovery Via Sysctl - MacOS
productmediumNew File Exclusion Added To Time Machine Via Tmutil - MacOS
productmediumSuspicious MacOS Firmware Activity
productmediumDisk Image Mounting Via Hdiutil - MacOS
productcriticalHackTool - Windows Credential Editor (WCE) Execution
productcriticalWindows Credential Editor Registry
producthighOpenCanary - MSSQL Login Attempt Via Windows Authentication
producthighWindows LAPS Credential Dump From Entra ID
producthighTamper Windows Defender - PSClassic
producthighTamper Windows Defender Remove-MpPreference - ScriptBlockLogging
producthighTamper Windows Defender - ScriptBlockLogging