Exact rules name this CVE ID. Product rules name an affected product in their title. Related rules cover techniques used by actors who exploited this CVE. Showing the most relevant matches; the complete related set is on the full drill-down.
productcriticalHackTool - Windows Credential Editor (WCE) Execution
productcriticalWindows Credential Editor Registry
producthighOpenCanary - MSSQL Login Attempt Via Windows Authentication
producthighWindows LAPS Credential Dump From Entra ID
producthighTamper Windows Defender - PSClassic
producthighTamper Windows Defender Remove-MpPreference - ScriptBlockLogging
Show all 20 top matches
producthighTamper Windows Defender - ScriptBlockLogging
productcriticalWMI Backdoor Exchange Transport Agent
productcriticalHackTool - BabyShark Agent Default URL Pattern
producthighSuspicious Windows Update Agent Empty Cmdline
producthighSuspicious BitLocker Access Agent Update Utility Execution
producthighAtera Agent Installation
producthighSuspicious Microsoft Office Child Process - MacOS
producthighRemote Access Tool - Renamed MeshAgent Execution - MacOS
producthighBinary Padding - MacOS
productmediumSuspicious Execution via macOS Script Editor
productmediumSystem Information Discovery Via Sysctl - MacOS
productmediumNew File Exclusion Added To Time Machine Via Tmutil - MacOS
productmediumSuspicious MacOS Firmware Activity
productmediumDisk Image Mounting Via Hdiutil - MacOS