Product
high
advisory
Understanding ClickOnce Technology Abuse: Part 1
2 TTPsThreat actors are abusing Microsoft's ClickOnce deployment technology to spread malware, allowing malicious applications to be deployed easily with minimal user interaction and without requiring administrative privileges, ultimately delivering malicious payloads onto user endpoints.
ClickOnce technology +4
clickonce
malware-delivery
windows
endpoint
2t
updated
high
advisory
Microsoft Security Updates — July 2026
11 CVEs 354 IOCsRoundup of Microsoft security advisories published in July 2026.
PoC
PowerShell +511
roundup
11c
354i
updated
low
advisory
Potential Remote File Execution via MSIEXEC
2 rules 3 TTPsThe rule detects the execution of the built-in Windows Installer, msiexec.exe, to install a remote package potentially abused by adversaries for initial access and defense evasion.
Windows Installer
msiexec
remote-file-execution
initial-access
defense-evasion
windows
2r
3t
medium
advisory
MsiExec Child Process Spawning Network Connections for Defense Evasion
2 rules 1 TTPDetection of MsiExec spawning child processes that initiate network connections, potentially indicating abuse of Windows Installers for malware delivery and defense evasion.
Elastic Defend +3
defense-evasion
windows
msiexec
2r
1t