CVE-2023-23397 Exploitation Attempt — Detection Rule

Detects outlook initiating connection to a WebDAV or SMB share, which could be a sign of CVE-2023-23397 exploitation.

Read the full analysis on IntelFusions