• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    Process Command Line Contains Vulnerability Keywords

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ankit Mehta@Secvyn
    •updated Jun 30, 2026•0•0•1

    Detects the creation of processes where the command line contains keywords such as 'cve' or 'vulnerability'. This could indicate attempts to exploit known vulnerabilities, perform vulnerability research, or execute tools related to vulnerability assessment.

    Microsoft Sentinel (KQL)

    Tags

    T1595.002 - Vulnerability ScanningT1588.006 - VulnerabilitiesT1210 - Exploitation of Remote ServicesDS0017 - CommandDS0009 - ProcessTA0043 - ReconnaissanceTA0042 - Resource DevelopmentTA0008 - Lateral MovementProcess CreationCommand ExecutionExploit AttemptVulnerability Scan DetectedWindowsWindows Eventlog Securitykql

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?