Potential CVE-2023-36884 Exploitation - Share Access
Description
Detects access to a file share with a naming schema seen being used during exploitation of CVE-2023-36884
Query · sigma
selection_eid:
EventID: 5140
selection_share_name:
ShareName|contains: \MSHTML_C7\
ShareName|re: '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
selection_share_path:
ShareLocalPath|contains: \MSHTML_C7\
ShareLocalPath|re: '[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}\.[0-9]{1,3}'
condition: selection_eid and 1 of selection_share_*
Known false positives
- Unknown