Stats
- First seen
- May 2023
- Last seen
- September 2026
Description
Detects the WinPWN Windows attack toolkit, which bundles credential dumping and privilege escalation modules. Spotting these indicators early helps contain an intrusion before cyberattackers expand access. The underlying flaw carries the identifier CVE-2020-1472.