Emerging Threats

CVEs, malware, and threat actor detections

Sigma emerging-threat folders collected into investigation-ready threat cards.

254Threat cards
457Rules
13Years
2026Latest
CVEs

Exploit-focused detections organized by public vulnerability identifier.

125 folder cards ยท 189 related detections

Search rules
CVE

CVE-2026-33829

CVE-2026-33829 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2026. Coverage centers on windows / process_creation.

1 rules2026
x.com
CVE

CVE-2025-31324

CVE-2025-31324 is tracked here through 6 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on webserver, linux / file_event, linux / process_creation +2.

6 rules2025
blog.eclecticiq.comcve.mitre.orgonapsis.com
CVE

CVE-2025-33053

CVE-2025-33053 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / image_load, windows / process_access, windows / process_creation.

3 rules2025
msrc.microsoft.comresearch.checkpoint.com
CVE

CVE-2025-53770

CVE-2025-53770 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on webserver, windows / file_event, windows / process_creation.

3 rules2025
linkedin.commsrc.microsoft.comresearch.eye.security
CVE

CVE-2025-55182

CVE-2025-55182 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on linux / process_creation, windows / process_creation.

2 rules2025
gist.github.comgithub.comnodejs.org
CVE

CVE-2025-59287

CVE-2025-59287 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / application, windows / process_creation.

2 rules2025
github.comhawktrace.comhuntress.com
CVE

CVE-2025-10035

CVE-2025-10035 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
microsoft.com
CVE

CVE-2025-20333

CVE-2025-20333 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on proxy.

1 rules2025
x.com
CVE

CVE-2025-24054

CVE-2025-24054 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / file_event.

1 rules2025
msrc.microsoft.comresearch.checkpoint.com
CVE

CVE-2025-30406

CVE-2025-30406 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
blackpointcyber.combleepingcomputer.comgladinetsupport.s3.us-east-1.amazonaws.com
CVE

CVE-2025-31161

CVE-2025-31161 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
attackerkb.comcrushftp.comnvd.nist.gov
CVE

CVE-2025-32463

CVE-2025-32463 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on linux / file_event.

1 rules2025
github.com
CVE

CVE-2025-40551

CVE-2025-40551 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
documentation.solarwinds.comhuntress.commicrosoft.com
CVE

CVE-2025-4427

CVE-2025-4427 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on webserver.

1 rules2025
labs.watchtowr.com
CVE

CVE-2025-49144

CVE-2025-49144 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
cve.mitre.orgx.com
CVE

CVE-2025-54309

CVE-2025-54309 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
firecompass.compwn.guidereliaquest.com
CVE

CVE-2025-57788

CVE-2025-57788 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
labs.watchtowr.com
CVE

CVE-2025-57790

CVE-2025-57790 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
labs.watchtowr.com
CVE

CVE-2025-57791

CVE-2025-57791 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2025. Coverage centers on windows / process_creation.

1 rules2025
labs.watchtowr.com
CVE

CVE-2024-1709

CVE-2024-1709 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on webserver, windows / file_event, windows / security.

3 rules2024
connectwise.comcve.orghuntress.com
CVE

CVE-2024-1708

CVE-2024-1708 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on windows / file_event, windows / security.

2 rules2024
connectwise.comcve.orghuntress.com
CVE

CVE-2024-3400

CVE-2024-3400 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on paloalto / appliance / globalprotect, paloalto / file_event / globalprotect.

2 rules2024
attackerkb.comlabs.watchtowr.comnvd.nist.gov
CVE

CVE-2024-37085

CVE-2024-37085 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on windows / process_creation, windows / security.

2 rules2024
microsoft.com
CVE

CVE-2024-1212

CVE-2024-1212 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on webserver.

1 rules2024
github.comrhinosecuritylabs.com
CVE

CVE-2024-3094

CVE-2024-3094 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on linux / process_creation.

1 rules2024
github.com
CVE

CVE-2024-35250

CVE-2024-35250 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on windows / image_load.

1 rules2024
cisa.govdevco.regithub.com
CVE

CVE-2024-49113

CVE-2024-49113 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on windows / application.

1 rules2024
gist.github.comlinkedin.com
CVE

CVE-2024-50623

CVE-2024-50623 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2024. Coverage centers on windows / process_creation.

1 rules2024
huntress.com
CVE

CVE-2023-36884

CVE-2023-36884 is tracked here through 6 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on proxy, windows / file_event, windows / security.

6 rules2023
blogs.blackberry.comtwitter.com
CVE

CVE-2023-22518

CVE-2023-22518 is tracked here through 4 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on linux / process_creation, proxy, webserver +1.

4 rules2023
confluence.atlassian.comgithub.comhuntress.com
CVE

CVE-2023-4966

CVE-2023-4966 is tracked here through 4 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on proxy, webserver.

4 rules2023
assetnote.ioattackerkb.comgithub.com
CVE

CVE-2023-23397

CVE-2023-23397 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / registry_set, windows / security, windows / smbclient-connectivity.

3 rules2023
github.commicrosoft.comtrustedsec.com
CVE

CVE-2023-36874

CVE-2023-36874 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / file_event, windows / process_creation.

3 rules2023
crowdstrike.comgithub.com
CVE

CVE-2023-38831

CVE-2023-38831 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / file_event, windows / process_creation.

2 rules2023
github.comgroup-ib.com
CVE

CVE-2023-40477

CVE-2023-40477 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / application, windows / file_event.

2 rules2023
github.comrarlab.comwildptr.io
CVE

CVE-2023-43261

CVE-2023-43261 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on proxy, webserver.

2 rules2023
github.commedium.comthehackernews.com
CVE

CVE-2023-46214

CVE-2023-46214 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on webserver.

2 rules2023
advisory.splunk.comblog.hrncirik.netgithub.com
CVE

CVE-2023-46747

CVE-2023-46747 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on proxy, webserver.

2 rules2023
github.commp.weixin.qq.compraetorian.com
CVE

CVE-2023-1389

CVE-2023-1389 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on proxy.

1 rules2023
github.comtenable.comzerodayinitiative.com
CVE

CVE-2023-20198

CVE-2023-20198 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on cisco / syslog.

1 rules2023
sec.cloudapps.cisco.comthestack.technology
CVE

CVE-2023-21554

CVE-2023-21554 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / application.

1 rules2023
randori.com
CVE

CVE-2023-2283

CVE-2023-2283 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on linux / sshd.

1 rules2023
blumira.comgit.libssh.orggithub.com
CVE

CVE-2023-23752

CVE-2023-23752 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on webserver.

1 rules2023
twitter.comxz.aliyun.com
CVE

CVE-2023-25157

CVE-2023-25157 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on webserver.

1 rules2023
github.comtwitter.com
CVE

CVE-2023-25717

CVE-2023-25717 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on webserver.

1 rules2023
cybir.com
CVE

CVE-2023-27363

CVE-2023-27363 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on windows / file_event.

1 rules2023
github.comtarlogic.comzerodayinitiative.com
CVE

CVE-2023-27997

CVE-2023-27997 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2023. Coverage centers on webserver.

1 rules2023
blog.lexfo.frlabs.watchtowr.comresearch.kudelskisecurity.com
CVE

CVE-2022-41082

CVE-2022-41082 is tracked here through 4 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on proxy, webserver.

4 rules2022
crowdstrike.comrapid7.comtwitter.com
CVE

CVE-2022-33891

CVE-2022-33891 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on linux / process_creation, webserver.

2 rules2022
github.comsumsec.me
CVE

CVE-2022-21554

CVE-2022-21554 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / process_creation.

1 rules2022
research.checkpoint.com
CVE

CVE-2022-21587

CVE-2022-21587 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
attackerkb.comblog.viettelcybersecurity.comgithub.com
CVE

CVE-2022-21919

CVE-2022-21919 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / application.

1 rules2022
packetstormsecurity.com
CVE

CVE-2022-22954

CVE-2022-22954 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / process_creation.

1 rules2022
blog.morphisec.comgithub.com
CVE

CVE-2022-24527

CVE-2022-24527 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / file_event.

1 rules2022
rapid7.com
CVE

CVE-2022-26134

CVE-2022-26134 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on linux / process_creation.

1 rules2022
volexity.com
CVE

CVE-2022-26809

CVE-2022-26809 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / process_creation.

1 rules2022
bleepingcomputer.commsrc.microsoft.comsecuronix.com
CVE

CVE-2022-27925

CVE-2022-27925 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
github.comvolexity.comyang99.top
CVE

CVE-2022-29072

CVE-2022-29072 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / process_creation.

1 rules2022
github.comtwitter.com
CVE

CVE-2022-29799

CVE-2022-29799 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on linux.

1 rules2022
github.commicrosoft.com
CVE

CVE-2022-30190

CVE-2022-30190 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / registry_set.

1 rules2022
msrc-blog.microsoft.commsrc.microsoft.com
CVE

CVE-2022-31656

CVE-2022-31656 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
petrusviet.medium.com
CVE

CVE-2022-31659

CVE-2022-31659 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
petrusviet.medium.com
CVE

CVE-2022-36804

CVE-2022-36804 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
blog.assetnote.ioconfluence.atlassian.comrapid7.com
CVE

CVE-2022-37966

CVE-2022-37966 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / system.

1 rules2022
support.microsoft.com
CVE

CVE-2022-41120

CVE-2022-41120 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on windows / process_creation.

1 rules2022
msrc.microsoft.comtwitter.com
CVE

CVE-2022-42475

CVE-2022-42475 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on fortios / sslvpnd.

1 rules2022
bleepingcomputer.comcommunity.fortinet.comdeepwatch.com
CVE

CVE-2022-44877

CVE-2022-44877 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
rapid7.comseclists.org
CVE

CVE-2022-46169

CVE-2022-46169 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2022. Coverage centers on webserver.

1 rules2022
github.com
CVE

CVE-2021-1675

CVE-2021-1675 is tracked here through 9 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on antivirus, windows / file_delete, windows / file_event +3.

9 rules2021
crowdstrike.comgithub.comlearn.microsoft.com
CVE

CVE-2021-40444

CVE-2021-40444 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / process_creation, windows / file_event.

3 rules2021
joesandbox.commsrc.microsoft.comtwitter.com
CVE

CVE-2021-41379

CVE-2021-41379 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / application, windows / file_event, windows / process_creation.

3 rules2021
bleepingcomputer.comlogpoint.comweb.archive.org
CVE

CVE-2021-44228

CVE-2021-44228 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver, windows / process_creation.

3 rules2021
gist.github.comgithub.comnews.ycombinator.com
CVE

CVE-2021-26084

CVE-2021-26084 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver, windows / process_creation.

2 rules2021
confluence.atlassian.comgithub.commraddon.blog
CVE

CVE-2021-26858

CVE-2021-26858 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver, windows / file_event.

2 rules2021
bi-zone.medium.commicrosoft.com
CVE

CVE-2021-33771

CVE-2021-33771 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / file_event, windows / registry_set.

2 rules2021
citizenlab.camicrosoft.com
CVE

CVE-2021-40539

CVE-2021-40539 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

2 rules2021
manageengine.comtherecord.mediaus-cert.cisa.gov
CVE

CVE-2021-42287

CVE-2021-42287 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / security, windows / system.

2 rules2021
cloudbrothers.infomedium.com
CVE

CVE-2021-20090

CVE-2021-20090 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
blogs.juniper.netmedium.comtenable.com
CVE

CVE-2021-2109

CVE-2021-2109 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
mp.weixin.qq.comtwitter.com
CVE

CVE-2021-21972

CVE-2021-21972 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
f5.pmswarm.ptsecurity.comvmware.com
CVE

CVE-2021-21978

CVE-2021-21978 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
paper.seebug.orgtwitter.com
CVE

CVE-2021-22005

CVE-2021-22005 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
kb.vmware.comtenable.com
CVE

CVE-2021-22123

CVE-2021-22123 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
rapid7.com
CVE

CVE-2021-22893

CVE-2021-22893 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
fireeye.comkb.pulsesecure.net
CVE

CVE-2021-26814

CVE-2021-26814 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
github.com
CVE

CVE-2021-26857

CVE-2021-26857 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / process_creation.

1 rules2021
microsoft.com
CVE

CVE-2021-27905

CVE-2021-27905 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
github.commp.weixin.qq.comnsfocusglobal.com
CVE

CVE-2021-28480

CVE-2021-28480 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
twitter.com
CVE

CVE-2021-33766

CVE-2021-33766 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
zerodayinitiative.com
CVE

CVE-2021-35211

CVE-2021-35211 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / process_creation.

1 rules2021
microsoft.com
CVE

CVE-2021-38647

CVE-2021-38647 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on zeek / http.

1 rules2021
twitter.comwiz.io
CVE

CVE-2021-4034

CVE-2021-4034 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on linux / auth.

1 rules2021
twitter.com
CVE

CVE-2021-41773

CVE-2021-41773 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
github.comnvd.nist.govtwitter.com
CVE

CVE-2021-42237

CVE-2021-42237 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
blog.assetnote.iosupport.sitecore.com
CVE

CVE-2021-42278

CVE-2021-42278 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / system.

1 rules2021
cloudbrothers.info
CVE

CVE-2021-42321

CVE-2021-42321 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / msexchange-management.

1 rules2021
msrc.microsoft.com
CVE

CVE-2021-43798

CVE-2021-43798 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on webserver.

1 rules2021
github.comgrafana.com
CVE

CVE-2021-44077

CVE-2021-44077 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2021. Coverage centers on windows / file_event.

1 rules2021
github.comthedfirreport.com
CVE

CVE-2020-0688

CVE-2020-0688 is tracked here through 3 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver, windows / application.

3 rules2020
cyberpolygon.comgithub.comtrustedsec.com
CVE

CVE-2020-1048

CVE-2020-1048 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on windows / process_creation, windows / registry_set.

2 rules2020
windows-internals.com
CVE

CVE-2020-10148

CVE-2020-10148 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
kb.cert.org
CVE

CVE-2020-10189

CVE-2020-10189 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on windows / process_creation.

1 rules2020
fireeye.comvulmon.com
CVE

CVE-2020-1350

CVE-2020-1350 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on windows / process_creation.

1 rules2020
research.checkpoint.comweb.archive.org
CVE

CVE-2020-1472

CVE-2020-1472 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on windows / process_creation.

1 rules2020
thedfirreport.com
CVE

CVE-2020-14882

CVE-2020-14882 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
isc.sans.edutwitter.com
CVE

CVE-2020-28188

CVE-2020-28188 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
ihteam.netresearch.checkpoint.com
CVE

CVE-2020-3452

CVE-2020-3452 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
github.comtwitter.com
CVE

CVE-2020-5902

CVE-2020-5902 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
criticalstart.comptsecurity.comsupport.f5.com
CVE

CVE-2020-8193

CVE-2020-8193 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2020. Coverage centers on webserver.

1 rules2020
dmaasland.github.ioresearch.nccgroup.comsupport.citrix.com
CVE

CVE-2019-0708

CVE-2019-0708 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on windows / security, windows / system.

2 rules2019
github.comtwitter.comweb.archive.org
CVE

CVE-2019-14287

CVE-2019-14287 is tracked here through 2 Sigma detections for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on linux / process_creation, linux / sudo.

2 rules2019
access.redhat.comopenwall.comtwitter.com
CVE

CVE-2019-11510

CVE-2019-11510 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on webserver.

1 rules2019
exploit-db.com
CVE

CVE-2019-1378

CVE-2019-1378 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on windows / process_creation.

1 rules2019
web.archive.org
CVE

CVE-2019-1388

CVE-2019-1388 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on windows / process_creation.

1 rules2019
portal.msrc.microsoft.comzerodayinitiative.com
CVE

CVE-2019-19781

CVE-2019-19781 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on webserver.

1 rules2019
github.comisc.sans.edusupport.citrix.com
CVE

CVE-2019-3398

CVE-2019-3398 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2019. Coverage centers on webserver.

1 rules2019
devcentral.f5.com
CVE

CVE-2018-13379

CVE-2018-13379 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2018. Coverage centers on webserver.

1 rules2018
devco.re
CVE

CVE-2018-15473

CVE-2018-15473 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2018. Coverage centers on linux / sshd.

1 rules2018
github.com
CVE

CVE-2018-2894

CVE-2018-2894 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2018. Coverage centers on webserver.

1 rules2018
github.comtwitter.com
CVE

CVE-2017-0261

CVE-2017-0261 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2017. Coverage centers on windows / process_creation.

1 rules2017
fireeye.com
CVE

CVE-2017-11882

CVE-2017-11882 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2017. Coverage centers on windows / process_creation.

1 rules2017
github.comhybrid-analysis.comlinkedin.com
CVE

CVE-2017-8759

CVE-2017-8759 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2017. Coverage centers on windows / process_creation.

1 rules2017
hybrid-analysis.comreverse.it
CVE

CVE-2015-1641

CVE-2015-1641 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2015. Coverage centers on windows / process_creation.

1 rules2015
hybrid-analysis.comvirustotal.com
CVE

CVE-2014-6287

CVE-2014-6287 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2014. Coverage centers on webserver.

1 rules2014
exploit-db.comgithub.comvk9-sec.com
CVE

CVE-2010-5278

CVE-2010-5278 is tracked here through 1 Sigma detection for exploitation attempts and related post-exploitation behavior observed in 2010. Coverage centers on webserver.

1 rules2010
github.com