ByteRay CQL Hub
← All queries

CVE-2026-32202 - Windows Shell

Exploitation of Windows Shell CVE-2026-32202

CQL · Falcon Next-Gen SIEMCopy query
setTimeInterval(start=1h, end=0h)
| in(field=#event_simpleName, values=[SmbClientShareClosedEtw, SmbClientShareLogonBruteForceLowThreshold, SmbClientShareLogonBruteForceSuspected, SmbClientShareOpenedEtw, SmbServerShareOpenedEtw, SmbServerV1AuditEtw,ProcessRollup2])
| !cidr(RemoteAddressIP4,subnet=["<<internal ip subnets>>"])
| default(field=[RemoteAddressIP4,LinkName], value="N/A", replaceEmpty=true)
| groupBy([ComputerName], function=([collect([#event_simpleName, SmbShareName, SmbClientName, ClientComputerName, DomainName, destination.ip, RemoteAddressIP4,LinkName])]), limit=20000)
|sort(RemoteAddressIP4)

ref: https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html

cve_2026_32202_windows_shell.yml
ML
Hunting, Monitoring, Detection
Endpoint, Network
2026-05-07
2026-05-07

Get this query running in your SIEM, with someone on call.

Our Managed SIEM team operates CrowdStrike Falcon Next-Gen SIEM in production, with over 350 battle-tested use cases and 24/7 incident response behind them.

Talk to the SIEM team