Query
[CVE-2022-41082] ProxyNotShell Exchange Vulnerability
LogScale · Detection & Monitoring · v2 · @sebastian · 24.7.2026
Detect suspicious command execution from Exchange w3wp.exe related to ProxyNotShell-style activity and CVE-2022-41082.
DetectionEndpointWindows
Query contentv2
Download v2Loading editor…
Version history
By default each save creates a new version. Overwrites update the current version in place. Open any version to view or download it.