Potential CVE-2023-36874 Exploitation - Fake Wermgr Execution
Description
Detects the execution of a renamed "cmd", "powershell" or "powershell_ise" binary. Attackers were seen using these binaries in a renamed form as "wermgr.exe" in exploitation of CVE-2023-36874
Query · sigma
selection: OriginalFileName: - Cmd.Exe - powershell_ise.EXE - powershell.exe Image|endswith: \wermgr.exe condition: selection
Known false positives
- Unlikely