CPE
high
advisory
Suspicious Microsoft Office Child Process Activity
1 rule 3 TTPs 1 CVEMicrosoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.
Microsoft Office
1r
3t
1c
high
advisory
Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)
2 rules 1 TTP 1 CVEThis rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.
Edge
privilege-escalation
cve-2021-41379
windows
2r
1t
1c
high
advisory
Suspicious Rundll32 Execution Without Command-Line Arguments
2 rules 1 TTP 1 CVEThe execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.
PoC
Windows Print Spooler
defense-evasion
windows
rundll32
2r
1t
1c
updated