CVE-2026-45657 Windows Kernel tcpip.sys RCE Indicator
This rule detects potential exploitation activity related to CVE-2026-45657 involving the Windows Kernel tcpip.sys driver. It monitors for a combination of system crashes (Kernel-Power 41 or EventLog 6008) correlated with Windows Error Reporting (WER) events referencing 'tcpip.sys', or significant spikes in external authentication attempts occurring shortly before a system crash. The rule aims to identify potential remote code execution attempts manifesting as kernel instability.
Microsoft Sentinel (KQL)

