CVE-2026-32202 - Windows Shell
Exploitation of Windows Shell CVE-2026-32202
CQL · Falcon Next-Gen SIEMCopy query
setTimeInterval(start=1h, end=0h)
| in(field=#event_simpleName, values=[SmbClientShareClosedEtw, SmbClientShareLogonBruteForceLowThreshold, SmbClientShareLogonBruteForceSuspected, SmbClientShareOpenedEtw, SmbServerShareOpenedEtw, SmbServerV1AuditEtw,ProcessRollup2])
| !cidr(RemoteAddressIP4,subnet=["<<internal ip subnets>>"])
| default(field=[RemoteAddressIP4,LinkName], value="N/A", replaceEmpty=true)
| groupBy([ComputerName], function=([collect([#event_simpleName, SmbShareName, SmbClientName, ClientComputerName, DomainName, destination.ip, RemoteAddressIP4,LinkName])]), limit=20000)
|sort(RemoteAddressIP4)ref: https://thehackernews.com/2026/04/microsoft-confirms-active-exploitation.html
cve_2026_32202_windows_shell.yml
ML
Hunting, Monitoring, Detection
Endpoint, Network
2026-05-07
2026-05-07
