Intelligence View
ARM64 PCs can now use the Microsoft Mouse and Keyboard Center
Windows 10 on ARM users now have more control over their Microsoft keyboards and mice. What you need to know Microsoft updated its Mouse and Keyboard Center to support ARM64 PCs. The Mouse and Keyboard Center gives people more control…
What you need to know
Microsoft updated its Mouse and Keyboard Center to support ARM64 PCs.
The Mouse and Keyboard Center gives people more control over their Microsoft mice and keyboards.
The update means that devices like the Surface Pro X can use the Mouse and Keyboard Center.
Microsoft recently updated its Mouse and Keyboard Center (via Neowin). The update brings support for ARM64 PCs such as the Surface Pro X. The update brings the utility to version 12 and gives ARM64 PC owners more control over their Microsoft mice and keyboards.
The utility allows you to customize certain aspects of Microsoft-made peripherals like the Surface Precision Mouse. You can use the utility to customize what certain mouse buttons do and control other functions.
The Microsoft Mouse and Keyboard Center doesn't work with Windows 10 PCs in S Mode and didn't work with Windows 10 PCs powered by ARM processors unti...
SOC Incident Playbook: Vulnerability Remediation & Verification
title: Detect Exploitation - ARM64 PCs can now use the Microsoft Mouse and Keyboard Center
id: 529dca9e-8f60-46d4-8bc6-84d6f53dd570
status: experimental
description: Automatisch generierte SIEM-Erkennungsregel basierend auf CTI Intelligence
references:
- https://tsecurity.de/
author: iShareStuff CTI Automated Detection Engine
date: 2026-09-24
logsource:
category: network_connection
product: any
detection:
selection:
CommandLine|contains:
- 'exploit'
condition: selection
falsepositives:
- Legitime administrative Zugriffe oder Penetrationstests
level: high
tags:
- attack.initial_accessrule CTI_Threat_Indicator {
meta:
author = "iShareStuff CTI Automated Detection Engine"
date = "2026-09-24"
description = "YARA Signature for "
strings:
$str = "ARM64 PCs can now use the Micr" ascii wide
condition:
any of them
}index=security sourcetype IN ("cisco:asa", "pan:traffic", "zeek_conn", "suricata", "WinEventLog:Security")
("ARM64 PCs can now use the Microsoft Mous")
| stats count earliest(_time) as first_seen latest(_time) as last_seen by src_ip, dest_ip, dest_host, signature
| eval first_seen=strftime(first_seen, "%Y-%m-%d %H:%M:%S"), last_seen=strftime(last_seen, "%Y-%m-%d %H:%M:%S")
| sort - countmessage: "*ARM64 PCs can now use the Microsoft Mous*"CommonSecurityLog
| where Message has "ARM64 PCs can now use the Microsoft Mous"
| summarize EventCount = count(), FirstSeen = min(TimeGenerated), LastSeen = max(TimeGenerated) by SourceIP, DestinationIP, DestinationPort, Activity
| extend DetectionRule = "iShareStuff-CTI-Compiled"
| sort by EventCount descMITRE ATT&CK Matrix Navigator 14 Taktiken
tsecurity.de Cognitive Threat RAG
Kognitive Analyse für identifizierte Bedrohung: Erhöhte Bedrohungslage im Bereich ARM64 PCs can now use the Microsoft Mous.... Basierend auf 368k Vektor-Korrelationen werden sofortige Isolationsmaßnahmen für betroffene Endpunkte empfohlen.
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
- 1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
- 2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
- 3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
SOCIAL SHARE CARD GENERATOR