LogScale Queries

Query

[CVE-2022-41082] ProxyNotShell Exchange Vulnerability

LogScale · Detection & Monitoring · v2 · @sebastian · 24.7.2026

All Queries

Detect suspicious command execution from Exchange w3wp.exe related to ProxyNotShell-style activity and CVE-2022-41082.

DetectionEndpointWindows

Query contentv2

Download v2
Loading editor…

Version history

Every save keeps the previous content. Open any version to view or download it.

  1. v2current

    24.7.2026, 17:17:03

  2. v1

    24.7.2026, 17:11:46