CPE
critical
threat
Active Exploitation of Windows IKE Extension RCE
2 TTPs 1 CVECVE-2022-34721 is a critical remote code execution vulnerability in the Windows Internet Key Exchange (IKE) extension, which is being actively exploited in the wild to gain unauthorized code execution.
exploited
Windows
vulnerability
remote-code-execution
2t
1c
critical
advisory
Computer Account Changes via Anonymous Logon Detected
2 rules 1 TTP 1 CVEDetection of Windows Event 4742 indicating a computer account change performed by an ANONYMOUS LOGON account, which is abnormal and could signify malicious activity, particularly Zerologon exploitation.
PoC
Splunk Enterprise +6
zerologon
privilege-escalation
windows
2r
1t
1c
updated