N-able N-central Take Control Session Abuse (CVE-2026-18577)
Detects unauthorized remote access sessions within N-able N-central by monitoring the Windows Application log for events indicating usage of the default 'MSP Support' account or source IP addresses associated with active exploitation of CVE-2026-18577.
Microsoft Sentinel (KQL)

