Microsoft Outlook Remote Code Execution Vulnerability (CVE-2025-32705)
Microsoft has patched a critical remote code execution (RCE) vulnerability in its Outlook client as part of the May 2025 Patch Tuesday updates. Tracked as CVE-2025-32705, the flaw stems from an out-of-bounds read issue that can be triggered when a user opens a malicious file within Outlook. This vulnerability could allow attackers to execute arbitrary code, potentially leading to full system compromise.
The Outlook Preview Pane is not affected — exploitation requires the user to actively open a specially crafted file.
Details
Vulnerability Details
• CVE ID: CVE-2025-32705
• Severity: Important
• Attack Vector: Local, via malicious file opened in Outlook
• Impact: Arbitrary code execution on the victim’s system
• Exploitation Prerequisites: Requires user interaction (file must be opened manually)
• Affected Products:
o Microsoft Office LTSC 2021 (32-bit and 64-bit)
o Microsoft Office LTSC 2024 (32-bit and 64-bit)
o Microsoft 365 Apps for Enterprise (32-bit and 64-bit)
This flaw was responsibly disclosed by Haifei Li of EXPMON, with credit acknowledged by Microsoft.
Mitigation/workaround
• Apply Microsoft Security Updates: Ensure all Outlook installations across the organization are patched immediately using official Microsoft update channels.
• Avoid Opening Suspicious Attachments: Users should avoid interacting with unexpected files, even if sent from known sources.
• Reinforce Endpoint Security: Ensure antivirus and EDR solutions are active and up-to-date to detect any exploitation attempts.
• Monitor Microsoft Security Advisories: Stay alert for future updates or possible exploit attempts targeting CVE-2025-32705.
References
https://cybersecuritynews.com/outlook-remote-code-execution-vulnerability/
Microsoft has patched a critical remote code execution (RCE) vulnerability in its Outlook client as part of the May 2025 Patch Tuesday updates. Tracked as CVE-2025-32705, the flaw stems from an out-of-bounds read issue that can be triggered when a user opens a malicious file within Outlook. This vulnerability could allow attackers to execute arbitrary code, potentially leading to full system compromise.
The Outlook Preview Pane is not affected — exploitation requires the user to actively open a specially crafted file.
Details
Vulnerability Details
• CVE ID: CVE-2025-32705
• Severity: Important
• Attack Vector: Local, via malicious file opened in Outlook
• Impact: Arbitrary code execution on the victim’s system
• Exploitation Prerequisites: Requires user interaction (file must be opened manually)
• Affected Products:
o Microsoft Office LTSC 2021 (32-bit and 64-bit)
o Microsoft Office LTSC 2024 (32-bit and 64-bit)
o Microsoft 365 Apps for Enterprise (32-bit and 64-bit)
This flaw was responsibly disclosed by Haifei Li of EXPMON, with credit acknowledged by Microsoft.
Mitigation/workaround
• Apply Microsoft Security Updates: Ensure all Outlook installations across the organization are patched immediately using official Microsoft update channels.
• Avoid Opening Suspicious Attachments: Users should avoid interacting with unexpected files, even if sent from known sources.
• Reinforce Endpoint Security: Ensure antivirus and EDR solutions are active and up-to-date to detect any exploitation attempts.
• Monitor Microsoft Security Advisories: Stay alert for future updates or possible exploit attempts targeting CVE-2025-32705.
References
https://cybersecuritynews.com/outlook-remote-code-execution-vulnerability/
Cyber Security News
Outlook RCE Vulnerability Allows Attackers to Execute Arbitrary Code
Microsoft addressed a significant security flaw in its Outlook email client during the May 2025 Patch Tuesday, releasing fixes for 72 vulnerabilities.
👍1
Microsoft – May 2025 Patch Tuesday
Microsoft has released security and feature updates for all supported versions of Windows as part of its May 2025 Patch Tuesday rollout. A total of 78 vulnerabilities were addressed, including five actively exploited zero-day vulnerabilities and two publicly disclosed zero-days. The updates cover critical flaws across the Windows OS, Defender, Edge, Internet Explorer, and development tools like Visual Studio.
Details
Key Vulnerability Highlights
• CVE-2025-30400 – DWM Core Library Elevation of Privilege
o Use-after-free vulnerability exploited to gain SYSTEM privileges.
• CVE-2025-32701 & CVE-2025-32706 – Common Log File System (CLFS) Driver Privilege Escalation
o Exploited in the wild; allows attackers to elevate local privileges to SYSTEM level using use-after-free and input validation flaws.
• CVE-2025-32709 – Ancillary Function Driver for WinSock Privilege Escalation
o Use-after-free issue exploited locally to escalate privileges.
• CVE-2025-30397 – Scripting Engine Memory Corruption (RCE)
o Type confusion vulnerability can be exploited via malicious Edge/IE links.
• CVE-2025-26685 – Defender for Identity Spoofing (Publicly disclosed)
o Allows an attacker with LAN access to spoof another identity.
• CVE-2025-32702 – Visual Studio Command Injection (RCE) (Publicly disclosed)
o Exploitable by unauthenticated users to run code locally via malformed commands.
Affected Platforms & Updates
• Windows 10 (22H2): 34 vulnerabilities (3 critical)
o KB5058379: Security fixes, Event Viewer bug fix, new drivers added to blocklist.
• Windows 11 (22H2/23H2): 35 vulnerabilities (3 critical)
o KB5058405: Lock screen widgets, Phone Link enhancements, UI bug fixes.
• Windows 11 (24H2): 36 vulnerabilities (3 critical)
o KB5058411: Includes Recall preview, Click to Do AI actions, natural language search.
• Windows Server (2008 to 2025): Up to 38 vulnerabilities
o Includes privilege escalation, DoS, spoofing, and remote code execution fixes.
Mitigation/workaround
• Apply the cumulative updates released for your respective Windows versions (see KB references).
• Monitor for anomalous behavior such as SYSTEM privilege elevations, unexpected scheduled tasks, or DLL injections.
• Enable behavioral analytics and audit privileged operations using EDR/SIEM platforms.
• For Visual Studio users, ensure only signed extensions and packages are trusted and executed.
References
https://msrc.microsoft.com/update-guide/releaseNote/2025-May
https://www.ghacks.net/2025/05/13/microsoft-windows-security-updates-for-may-2025-are-now-available/
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2025-patch-tuesday-fixes-5-exploited-zero-days-72-flaws/
Microsoft has released security and feature updates for all supported versions of Windows as part of its May 2025 Patch Tuesday rollout. A total of 78 vulnerabilities were addressed, including five actively exploited zero-day vulnerabilities and two publicly disclosed zero-days. The updates cover critical flaws across the Windows OS, Defender, Edge, Internet Explorer, and development tools like Visual Studio.
Details
Key Vulnerability Highlights
• CVE-2025-30400 – DWM Core Library Elevation of Privilege
o Use-after-free vulnerability exploited to gain SYSTEM privileges.
• CVE-2025-32701 & CVE-2025-32706 – Common Log File System (CLFS) Driver Privilege Escalation
o Exploited in the wild; allows attackers to elevate local privileges to SYSTEM level using use-after-free and input validation flaws.
• CVE-2025-32709 – Ancillary Function Driver for WinSock Privilege Escalation
o Use-after-free issue exploited locally to escalate privileges.
• CVE-2025-30397 – Scripting Engine Memory Corruption (RCE)
o Type confusion vulnerability can be exploited via malicious Edge/IE links.
• CVE-2025-26685 – Defender for Identity Spoofing (Publicly disclosed)
o Allows an attacker with LAN access to spoof another identity.
• CVE-2025-32702 – Visual Studio Command Injection (RCE) (Publicly disclosed)
o Exploitable by unauthenticated users to run code locally via malformed commands.
Affected Platforms & Updates
• Windows 10 (22H2): 34 vulnerabilities (3 critical)
o KB5058379: Security fixes, Event Viewer bug fix, new drivers added to blocklist.
• Windows 11 (22H2/23H2): 35 vulnerabilities (3 critical)
o KB5058405: Lock screen widgets, Phone Link enhancements, UI bug fixes.
• Windows 11 (24H2): 36 vulnerabilities (3 critical)
o KB5058411: Includes Recall preview, Click to Do AI actions, natural language search.
• Windows Server (2008 to 2025): Up to 38 vulnerabilities
o Includes privilege escalation, DoS, spoofing, and remote code execution fixes.
Mitigation/workaround
• Apply the cumulative updates released for your respective Windows versions (see KB references).
• Monitor for anomalous behavior such as SYSTEM privilege elevations, unexpected scheduled tasks, or DLL injections.
• Enable behavioral analytics and audit privileged operations using EDR/SIEM platforms.
• For Visual Studio users, ensure only signed extensions and packages are trusted and executed.
References
https://msrc.microsoft.com/update-guide/releaseNote/2025-May
https://www.ghacks.net/2025/05/13/microsoft-windows-security-updates-for-may-2025-are-now-available/
https://www.bleepingcomputer.com/news/microsoft/microsoft-may-2025-patch-tuesday-fixes-5-exploited-zero-days-72-flaws/
ghacks.net
Microsoft Windows Security Updates for May 2025 are now available
Microsoft released security updates for Windows on the May 2025 Patch Day. Read our overview for recommendations, support links, and much more.
👍1
FortiOS Authentication Bypass Vulnerability (CVE-2025-22252)
Fortinet has patched a critical authentication bypass vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager when configured with TACACS+ and ASCII authentication. The flaw allows unauthorized administrative access without valid credentials.
Details
Key Vulnerability: FortiOS Auth Bypass
• CVE: CVE-2025-22252
• Impact: Complete administrative access without authentication
• Cause: Missing authentication check for critical function using ASCII authentication
Affected Versions
• FortiOS: 7.6.0, 7.4.4–7.4.6
• FortiProxy: 7.6.0–7.6.1
• FortiSwitchManager: 7.2.5
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround • Immediate Action:
o Upgrade to the latest versions listed above
o If upgrade isn’t possible, switch to alternative TACACS+ authentication methods like PAP, MSCHAP, or CHAP
• Configuration Advice:
o Use CLI to change TACACS+ settings
o Avoid ASCII authentication until patched
References
https://cybersecuritynews.com/fortios-authentication-bypass-vulnerability/
Fortinet has patched a critical authentication bypass vulnerability affecting FortiOS, FortiProxy, and FortiSwitchManager when configured with TACACS+ and ASCII authentication. The flaw allows unauthorized administrative access without valid credentials.
Details
Key Vulnerability: FortiOS Auth Bypass
• CVE: CVE-2025-22252
• Impact: Complete administrative access without authentication
• Cause: Missing authentication check for critical function using ASCII authentication
Affected Versions
• FortiOS: 7.6.0, 7.4.4–7.4.6
• FortiProxy: 7.6.0–7.6.1
• FortiSwitchManager: 7.2.5
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround • Immediate Action:
o Upgrade to the latest versions listed above
o If upgrade isn’t possible, switch to alternative TACACS+ authentication methods like PAP, MSCHAP, or CHAP
• Configuration Advice:
o Use CLI to change TACACS+ settings
o Avoid ASCII authentication until patched
References
https://cybersecuritynews.com/fortios-authentication-bypass-vulnerability/
Cyber Security News
FortiOS Authentication Bypass Vulnerability Lets Attackers Take Full Control of Device
Fortinet has disclosed a significant security vulnerability affecting multiple Fortinet products, allowing attackers to bypass authentication and gain administrative access to affected systems.
👍1
Fortinet Zero-Day Vulnerability in FortiVoice Actively Exploited
Fortinet has disclosed a critical zero-day vulnerability actively exploited in the wild, affecting FortiVoice and other Fortinet products. The flaw, a stack-based buffer overflow, allows unauthenticated remote code execution via malicious HTTP requests. Multiple malicious activities have been observed, including credential harvesting, log tampering, and network scanning.
Details
Key Vulnerability:
FortiVoice RCE (CWE-121 - Stack-based Buffer Overflow)
• Impact: Unauthenticated remote code/command execution
• Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera
• Attack Actions Observed:
o Log manipulation to erase crash data
o FastCGI debugging to steal SSH credentials
o Malicious cron jobs extracting passwords every 12 hours
Affected Versions and Fixes
• FortiVoice: Upgrade to 7.2.1+, 7.0.7+, or 6.4.11+
• FortiMail: Upgrade to 7.6.3+, 7.4.5+, 7.2.8+, or 7.0.9+
• FortiNDR: Upgrade to 7.6.1+, 7.4.8+, 7.2.5+, 7.0.7+
• FortiRecorder: Upgrade to 7.2.4+, 7.0.6+, 6.4.6+
• FortiCamera: Upgrade to 2.1.4+ or migrate from 2.0/1.1
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround
• If patching is delayed, disable the HTTP/HTTPS administrative interface.
• Monitor FastCGI logs and system binaries for manipulation.
• Review /etc/pam.d/sshd and /etc/httpd.conf for unauthorized changes.
References
https://gbhackers.com/fortinet-fortivoice-o-day-vulnerability/
Fortinet has disclosed a critical zero-day vulnerability actively exploited in the wild, affecting FortiVoice and other Fortinet products. The flaw, a stack-based buffer overflow, allows unauthenticated remote code execution via malicious HTTP requests. Multiple malicious activities have been observed, including credential harvesting, log tampering, and network scanning.
Details
Key Vulnerability:
FortiVoice RCE (CWE-121 - Stack-based Buffer Overflow)
• Impact: Unauthenticated remote code/command execution
• Affected Products: FortiVoice, FortiMail, FortiNDR, FortiRecorder, FortiCamera
• Attack Actions Observed:
o Log manipulation to erase crash data
o FastCGI debugging to steal SSH credentials
o Malicious cron jobs extracting passwords every 12 hours
Affected Versions and Fixes
• FortiVoice: Upgrade to 7.2.1+, 7.0.7+, or 6.4.11+
• FortiMail: Upgrade to 7.6.3+, 7.4.5+, 7.2.8+, or 7.0.9+
• FortiNDR: Upgrade to 7.6.1+, 7.4.8+, 7.2.5+, 7.0.7+
• FortiRecorder: Upgrade to 7.2.4+, 7.0.6+, 6.4.6+
• FortiCamera: Upgrade to 2.1.4+ or migrate from 2.0/1.1
Fixed Versions
• FortiOS: 7.6.1+, 7.4.7+
• FortiProxy: 7.6.2+
• FortiSwitchManager: 7.2.6+
Mitigation/workaround
• If patching is delayed, disable the HTTP/HTTPS administrative interface.
• Monitor FastCGI logs and system binaries for manipulation.
• Review /etc/pam.d/sshd and /etc/httpd.conf for unauthorized changes.
References
https://gbhackers.com/fortinet-fortivoice-o-day-vulnerability/
GBHackers Security | #1 Globally Trusted Cyber Security News Platform
Fortinet FortiVoice O-Day Vulnerability Actively Exploited in The Wild
A critical zero-day vulnerability in FortiVoice systems is being actively exploited in the wild. It allows unauthenticated attackers to execute arbitrary code
🔥1
توزیع بدافزار از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی
یک گروه تهدید وابسته به ویتنام در حال توزیع بدافزارهای Noodlophile Stealer و XWorm RAT از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی است که با پستهای ویروسی در فیسبوک تبلیغ میشوند.
این سایتهای جعلی کاربران—بهویژه تولیدکنندگان محتوا و کسبوکارهای کوچک—را فریب میدهند تا فایلهای رسانهای خود را آپلود کرده و فایلهای ZIP آلوده (مانند VideoDreamAI.zip) را که بهعنوان خروجی هوش مصنوعی جا زده شدهاند، دانلود کنند.
محموله مخرب شامل موارد زیر است:
سرقت اطلاعات ورود (Credential theft)
سرقت کیف پولهای رمزارز
کنترل از راه دور با استفاده از RAT
استخراج اطلاعات از طریق Telegram
این حمله از طریق یک زنجیره آلودگی چندمرحلهای و پیچیده انجام میشود که ابزارهایی مانند CapCut.exe، certutil.exe، و RegAsm.exe را بهکار میگیرد و بهشدت مبهمسازی (Obfuscation) شده است.
این بدافزارها بهعنوان بخشی از یک عملیات بدافزار به عنوان سرویس (Malware-as-a-Service یا MaaS) ارائه میشوند.
یک گروه تهدید وابسته به ویتنام در حال توزیع بدافزارهای Noodlophile Stealer و XWorm RAT از طریق سایتهای جعلی تولید ویدیو با هوش مصنوعی است که با پستهای ویروسی در فیسبوک تبلیغ میشوند.
این سایتهای جعلی کاربران—بهویژه تولیدکنندگان محتوا و کسبوکارهای کوچک—را فریب میدهند تا فایلهای رسانهای خود را آپلود کرده و فایلهای ZIP آلوده (مانند VideoDreamAI.zip) را که بهعنوان خروجی هوش مصنوعی جا زده شدهاند، دانلود کنند.
محموله مخرب شامل موارد زیر است:
سرقت اطلاعات ورود (Credential theft)
سرقت کیف پولهای رمزارز
کنترل از راه دور با استفاده از RAT
استخراج اطلاعات از طریق Telegram
این حمله از طریق یک زنجیره آلودگی چندمرحلهای و پیچیده انجام میشود که ابزارهایی مانند CapCut.exe، certutil.exe، و RegAsm.exe را بهکار میگیرد و بهشدت مبهمسازی (Obfuscation) شده است.
این بدافزارها بهعنوان بخشی از یک عملیات بدافزار به عنوان سرویس (Malware-as-a-Service یا MaaS) ارائه میشوند.
🔥1
افشای دادههای حساس SharePoint توسط Microsoft Copilot AI
پژوهشگران چندین آسیبپذیری در Microsoft Copilot برای SharePoint کشف کردهاند که به مهاجمان امکان میدهد فایلهای حساس مانند رمزهای عبور، کلیدهای API، و اسناد محرمانه را بدون ثبت در لاگهای ممیزی یا هشدارهای دسترسی، بازیابی کنند.
مهاجمان با سوءاستفاده از Agentهای پیشفرض و سفارشی میتوانند مجوزهای “Restricted View” را دور بزنند و حتی فایلهایی با سطح دسترسی بالا را از طریق پرامپتهای فریبنده (Deceptive Prompts) شناسایی کنند.
نکته مهم اینکه تعاملات با Copilot در لاگهای دسترسی استاندارد SharePoint ثبت نمیشوند، که این امر امکان استخراج مخفیانه دادهها را فراهم میسازد.
در یکی از نمونههای سوءاستفاده، بهنام “HackerBot”، نشان داده شد که Agentها میتوانند به فایلهایی از سایتهای محدود دسترسی یابند، بدون اینکه احراز هویت مناسب صورت گیرد.
راهکارهای کاهش تهدید:
اعمال اصول بهداشتی سختگیرانه در SharePoint
محدودسازی ایجاد Agentهای جدید
آموزش کاربران در خصوص خطرات دستکاری پرامپت در هوش مصنوعی
پژوهشگران چندین آسیبپذیری در Microsoft Copilot برای SharePoint کشف کردهاند که به مهاجمان امکان میدهد فایلهای حساس مانند رمزهای عبور، کلیدهای API، و اسناد محرمانه را بدون ثبت در لاگهای ممیزی یا هشدارهای دسترسی، بازیابی کنند.
مهاجمان با سوءاستفاده از Agentهای پیشفرض و سفارشی میتوانند مجوزهای “Restricted View” را دور بزنند و حتی فایلهایی با سطح دسترسی بالا را از طریق پرامپتهای فریبنده (Deceptive Prompts) شناسایی کنند.
نکته مهم اینکه تعاملات با Copilot در لاگهای دسترسی استاندارد SharePoint ثبت نمیشوند، که این امر امکان استخراج مخفیانه دادهها را فراهم میسازد.
در یکی از نمونههای سوءاستفاده، بهنام “HackerBot”، نشان داده شد که Agentها میتوانند به فایلهایی از سایتهای محدود دسترسی یابند، بدون اینکه احراز هویت مناسب صورت گیرد.
راهکارهای کاهش تهدید:
اعمال اصول بهداشتی سختگیرانه در SharePoint
محدودسازی ایجاد Agentهای جدید
آموزش کاربران در خصوص خطرات دستکاری پرامپت در هوش مصنوعی
❤1🔥1
بدافزار Bumblebee با استفاده از آلودهسازی نتایج جستجوی Bing منتشر میشود
یک کمپین جدید از بدافزار Bumblebee در حال توزیع نرمافزارهای تروجانشده از طریق آلودهسازی سئو (SEO Poisoning) در موتور جستجوی Bing است. این کمپین کاربران را زمانی هدف قرار میدهد که به دنبال ابزارهایی مانند WinMTR یا Milestone XProtect هستند.
بازیگران تهدید دامنههایی با غلط املایی عمدی (Typo-squatted) مانند winmtr[.]org یا milestonesys[.]org ایجاد کردهاند که بهعنوان نتایج برتر جستجو ظاهر میشوند و صفحات دانلود قانونی را تقلید میکنند. زمانی که کاربران از طریق Bing به این سایتها وارد میشوند، به یک نصبکننده جعلی MSI در دامنه software-server[.]online هدایت میشوند که Bumblebee را از طریق یک فایل DLL مخرب به نام version.dll تحویل میدهد.
پس از اجرا، Bumblebee با دامنههای فرمان و کنترل (C2) با پسوند .life ارتباط برقرار میکند تا دادهها را استخراج کرده و احتمالاً بدافزارهای بیشتری را نیز روی سیستم قربانی نصب کند.
این کمپین بر استفاده روزافزون از دستکاری سئو برای توزیع بدافزار تأکید دارد و نشان میدهد که کاربران باید در مورد منابع دانلود محتاط بوده و صرفاً به رتبه نتایج موتورهای جستجو اعتماد نکنند.
یک کمپین جدید از بدافزار Bumblebee در حال توزیع نرمافزارهای تروجانشده از طریق آلودهسازی سئو (SEO Poisoning) در موتور جستجوی Bing است. این کمپین کاربران را زمانی هدف قرار میدهد که به دنبال ابزارهایی مانند WinMTR یا Milestone XProtect هستند.
بازیگران تهدید دامنههایی با غلط املایی عمدی (Typo-squatted) مانند winmtr[.]org یا milestonesys[.]org ایجاد کردهاند که بهعنوان نتایج برتر جستجو ظاهر میشوند و صفحات دانلود قانونی را تقلید میکنند. زمانی که کاربران از طریق Bing به این سایتها وارد میشوند، به یک نصبکننده جعلی MSI در دامنه software-server[.]online هدایت میشوند که Bumblebee را از طریق یک فایل DLL مخرب به نام version.dll تحویل میدهد.
پس از اجرا، Bumblebee با دامنههای فرمان و کنترل (C2) با پسوند .life ارتباط برقرار میکند تا دادهها را استخراج کرده و احتمالاً بدافزارهای بیشتری را نیز روی سیستم قربانی نصب کند.
این کمپین بر استفاده روزافزون از دستکاری سئو برای توزیع بدافزار تأکید دارد و نشان میدهد که کاربران باید در مورد منابع دانلود محتاط بوده و صرفاً به رتبه نتایج موتورهای جستجو اعتماد نکنند.
امنیت سایبری SOC
بدافزار Bumblebee با استفاده از آلودهسازی نتایج جستجوی Bing منتشر میشود یک کمپین جدید از بدافزار Bumblebee در حال توزیع نرمافزارهای تروجانشده از طریق آلودهسازی سئو (SEO Poisoning) در موتور جستجوی Bing است. این کمپین کاربران را زمانی هدف قرار میدهد که…
article-indicators(1).csv
1.5 KB
اینResecurity هست که سازمانتون رو میتونید تو سایتش اضافه کنید و اگه Data breach اتفاق بیفته اینجا جزییات داده ها و اکانت هایی که breach شدن رو میدن — https://risk.resecurity.com/user/sign-in/login
PurpleAI Sentinel One-
قابلیت جالبی هست که به سنتینل وان اضافه شده -توضیحات در مورد تهدیدات رو خودش در مورد هر تهدیدی که پیدا میکنه مینویسه و این باعث میشه که دیگه شما خیلی نیاز به دانش قبلی برای فهمیدن ریسک تهدید نداشته باشید و یک موردش هم که خیلی جالب بود برای من اینه که بهش میگی مثلا موارد مشکوک برای مثال لاگین های ناموفق یا مالور ها یا هرچیزی را نشون بده مثل چت چی پی تی -بدون نوشتن کویری شکار تهدید و نیازی به نوشتن کویری نداره🙆♀️
قابلیت جالبی هست که به سنتینل وان اضافه شده -توضیحات در مورد تهدیدات رو خودش در مورد هر تهدیدی که پیدا میکنه مینویسه و این باعث میشه که دیگه شما خیلی نیاز به دانش قبلی برای فهمیدن ریسک تهدید نداشته باشید و یک موردش هم که خیلی جالب بود برای من اینه که بهش میگی مثلا موارد مشکوک برای مثال لاگین های ناموفق یا مالور ها یا هرچیزی را نشون بده مثل چت چی پی تی -بدون نوشتن کویری شکار تهدید و نیازی به نوشتن کویری نداره🙆♀️