CPE
critical
threat
Active Exploitation of Windows IKE Extension RCE
2 TTPs 1 CVECVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.
exploited
Windows
vulnerability
remote-code-execution
2t
1c
high
advisory
Suspicious Microsoft Office Child Process Activity
1 rule 3 TTPs 1 CVEMicrosoft Office applications are frequently abused to spawn system processes to execute malicious code, download payloads, or facilitate privilege escalation.
Microsoft Office
1r
3t
1c
high
advisory
Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)
2 rules 1 TTP 1 CVEThis rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.
Edge
privilege-escalation
cve-2021-41379
windows
2r
1t
1c