CPE
Microsoft Dataverse Privilege Escalation Vulnerability
1 TTP 1 CVEA vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.
Denial of Service Vulnerability in libarchive
1 TTP 1 CVEA memory corruption vulnerability in libarchive (CVE-2024-20696) allows a local attacker to cause a Denial of Service condition through the processing of specially crafted archive files.
Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services
1 TTP 2 CVEsLocal attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.
Information Disclosure Vulnerability in Microsoft 365 Copilot
1 TTP 1 CVEA vulnerability identified as CVE-2024-38148 in Microsoft 365 Copilot allows remote, unauthenticated attackers to potentially access unauthorized sensitive information within the service environment.
Privilege Escalation Vulnerability in Microsoft Windows Package Manager
1 CVEA local privilege escalation vulnerability in the Microsoft Windows Package Manager allows an authenticated local attacker to gain elevated privileges on the host system.
Suspicious Child Processes of consent.exe
1 rule 3 TTPs 1 CVEDetection of unauthorized child process creation by the Windows UAC consent.exe binary, a common indicator of UAC bypass and privilege escalation activity.
Suspicious Microsoft Office Child Process Activity
1 rule 3 TTPs 1 CVEMicrosoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.
Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)
2 rules 1 TTP 1 CVEThis rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.
Suspicious Rundll32 Execution Without Command-Line Arguments
2 rules 1 TTP 1 CVEThe execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.