CPE
Microsoft Dataverse Privilege Escalation Vulnerability
1 TTP 1 CVEA vulnerability in Microsoft Dataverse identified as CVE-2024-38064 allows a remote, unauthenticated attacker to escalate privileges and potentially gain administrative access to the service.
Multiple Privilege Escalation Vulnerabilities in Microsoft Authenticator and Xbox Gaming Services
1 TTP 2 CVEsLocal attackers can exploit multiple vulnerabilities in Microsoft Authenticator and Xbox Gaming Services to achieve elevated privileges on Windows systems.
Active Exploitation of Windows IKE Extension RCE
2 TTPs 1 CVECVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.
Potential Privileged Escalation via SamAccountName Spoofing (CVE-2021-42278)
2 rules 1 TTP 1 CVEThis rule detects potential privilege escalation attempts by exploiting CVE-2021-42278, which involves spoofing the samAccountName attribute to impersonate a domain controller and elevate privileges from a standard domain user to a domain administrator by identifying suspicious computer account name rename events where a machine account name is renamed to a user-like account name.
Potential Privilege Escalation via InstallerFileTakeOver (CVE-2021-41379)
2 rules 1 TTP 1 CVEThis rule detects potential exploitation of the InstallerTakeOver vulnerability (CVE-2021-41379), where successful exploitation allows an unprivileged user to escalate privileges to SYSTEM.
Computer Account Changes via Anonymous Logon Detected
2 rules 1 TTP 1 CVEDetection of Windows Event 4742 indicating a computer account change performed by an ANONYMOUS LOGON account, which is abnormal and could signify malicious activity, particularly Zerologon exploitation.
Suspicious Rundll32 Execution Without Command-Line Arguments
2 rules 1 TTP 1 CVEThe execution of rundll32.exe without command-line arguments is detected via endpoint telemetry, a behavior indicative of potential malicious activity such as Cobalt Strike, leading to arbitrary code execution and system compromise.
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 4 CVEs 4 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.