
CVE-2021-1675
Zeek script and Suricata rules to detect PrintNightmare (CVE-2021-1675) exploitation via RpcAddPrinterDriver DCE RPC events, with PCAP-based testing.
dns-analysisexploitationids-ips-evasion+3
9

Zeek script and Suricata rules to detect PrintNightmare (CVE-2021-1675) exploitation via RpcAddPrinterDriver DCE RPC events, with PCAP-based testing.

CVE-2020-16899 - Microsoft Windows TCP/IP Vulnerability Detection Logic and Rule

Blue-team lab: detecting & mitigating CVE-2025-24054 (Windows NTLM hash disclosure) with Sysmon, Wazuh SIEM, and Group Policy