Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
producthighUAC Bypass Using .NET Code Profiler on MMC
producthighPotential AMSI Bypass Via .NET Reflection
producthighETW Logging Tamper In .NET Processes Via CommandLine
producthighETW Logging Disabled In .NET Processes - Registry
producthighETW Logging Disabled In .NET Processes - Sysmon Registry
productcriticalBad Opsec Powershell Code Artifacts
Show all 21 top matches
productcriticalSuspicious PowerShell Mailbox Export to Share - PS
productcriticalSuspicious PowerShell Mailbox Export to Share
productcriticalHackTool - Empire PowerShell UAC Bypass
productcriticalHackTool - DInjector PowerShell Cradle Execution
producthighDelete Volume Shadow Copies Via WMI With PowerShell
producthighPowerShell Called from an Executable Version Mismatch
producthighInvoke-Obfuscation Via Use Rundll32 - PowerShell Module
producthighSuspicious Microsoft Office Child Process - MacOS
producthighRemote Access Tool - Renamed MeshAgent Execution - MacOS
producthighBinary Padding - MacOS
productmediumSuspicious Execution via macOS Script Editor
productmediumSystem Information Discovery Via Sysctl - MacOS
productmediumNew File Exclusion Added To Time Machine Via Tmutil - MacOS
productmediumSuspicious MacOS Firmware Activity
productmediumDisk Image Mounting Via Hdiutil - MacOS