Process Creation with Exploit/Vulnerability Keywords
This rule detects the creation of new processes where the command line contains keywords such as 'exploit' or 'vulnerability'. This could indicate an attempt to execute an exploit or leverage a known vulnerability, potentially as part of an attack.
Microsoft Sentinel (KQL)

