type: trigger #debug: true name: crowdsecurity/CVE-2022-41082 description: "Detect CVE-2022-41082 exploits" filter: | Upper(evt.Meta.http_path) contains Upper('/autodiscover/autodiscover.json') && Upper(evt.Parsed.http_args) contains Upper('powershell') blackhole: 1m groupby: "evt.Meta.source_ip" labels: type: exploit remediation: true