CVE-2024-50623 Exploitation Attempt - Cleo — Detection Rule

Detects exploitation attempt of Cleo's CVE-2024-50623 by looking for a "cmd.exe" process spawning from the Celo software suite with suspicious Powershell commandline.

Read the full analysis on IntelFusions