• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    CVE-2022-22965 Network Activity

    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Azure Sentinel@AzureSentinel
    •updated Jun 17, 2025•0•18

    The following query surface network activity associated with exploitation of CVE-2022-22965.

    Microsoft Sentinel (KQL)

    Tags

    TA0004 - Privilege EscalationT1190 - Exploit Public-Facing ApplicationT1068 - Exploitation for Privilege EscalationTA0001 - Initial AccessC0034 - 2022 Ukraine Electric Power AttackC0036 - Pikabot Distribution February 2024C0045 - ShadowRayS0648 - JSS LoaderT1101 - Security Support ProviderT1547.005 - Security Support ProviderT1036.001 - Invalid Code SignatureT1584.008 - Network DevicesDS0029 - Network TrafficM1037 - Filter Network TrafficT1020.001 - Traffic DuplicationTA0003 - PersistenceTA0005 - Defense EvasionTA0042 - Resource DevelopmentTA0010 - ExfiltrationS0106 - cmdNetwork Connection OutboundExploit AttemptNetwork GenericWindows Defender Atpkqltactic:Privilege escalationtactic:Exploit

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?