CVE-2024-50623 Exploitation Attempt - Cleo

Rule Info

Name
CVE-2024-50623 Exploitation Attempt - Cleo
Author
Tanner Filip, Austin Worline, Chad Hudson, Matt Anderson
Description
Detects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.
Date
2024-12-09 00:00:00
Modified
None
Id
f007b877-02e3-45b7-8501-1b78c2864029
Tags
attack.execution attack.t1190
Type
Community Rule

Rule History

Author
Title
Date
Commit
Florian Roth
Merge PR #5116 from @Neo23x0 - Add rules and updates related to Cleo exploitation
2024-12-14