Product
high
advisory
Potential Foxmail Exploitation Leading to Initial Access
2 rules 1 TTPThis rule detects potential exploitation of Foxmail client to gain initial access and execute malicious code by monitoring for Foxmail client spawning child processes with arguments pointing to user-profile AppData paths or remote shares, indicating exploitation of a Foxmail vulnerability through a malicious email.
Foxmail client
initial-access
execution
foxmail
vulnerability
2r
1t
high
advisory
Foxmail Client Exploitation Leading to Initial Access
2 rules 3 TTPsThe rule detects potential exploitation of the Foxmail email client on Windows systems, where successful exploitation allows for initial access and execution of arbitrary code.
Foxmail client
foxmail
exploitation
initial-access
execution
windows
2r
3t