Unpatched OpenVPN binaries below 2.7.7 (CVE-2026-84732 et al.)
This rule identifies instances of OpenVPN-related executables (openvpn.exe, openvpnserv.exe, tapctl.exe) running on endpoints where the version is below the threshold considered patched (2.7.7). It uses file metadata and certificate information to verify the binary version and flag legacy, potentially vulnerable installations.
Microsoft Sentinel (KQL)

