Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
productcriticalHackTool - Windows Credential Editor (WCE) Execution
productcriticalWindows Credential Editor Registry
producthighOpenCanary - MSSQL Login Attempt Via Windows Authentication
producthighWindows LAPS Credential Dump From Entra ID
producthighTamper Windows Defender - PSClassic
producthighTamper Windows Defender Remove-MpPreference - ScriptBlockLogging
Show all 20 top matches
producthighTamper Windows Defender - ScriptBlockLogging
producthighUAC Bypass Using .NET Code Profiler on MMC
producthighPotential AMSI Bypass Via .NET Reflection
producthighETW Logging Tamper In .NET Processes Via CommandLine
producthighETW Logging Disabled In .NET Processes - Registry
producthighETW Logging Disabled In .NET Processes - Sysmon Registry
productcriticalBad Opsec Powershell Code Artifacts
productcriticalSuspicious PowerShell Mailbox Export to Share - PS
productcriticalSuspicious PowerShell Mailbox Export to Share
productcriticalHackTool - Empire PowerShell UAC Bypass
productcriticalHackTool - DInjector PowerShell Cradle Execution
producthighDelete Volume Shadow Copies Via WMI With PowerShell
producthighPowerShell Called from an Executable Version Mismatch
producthighInvoke-Obfuscation Via Use Rundll32 - PowerShell Module