February 26, 2026 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew14
Enhanced
DashboardsNew
ReportsNew

New Detections

#NameDescription
1Active Directory Discovery via ADExplorerActive Directory Discovery via ADExplorer is under investigation.
2NetSupport Manager Execution from Unusual  PathsNetSupport Manager Execution from Unusual Paths under investigation.
3Potential Execution via FileFix Phishing AttackPotential Execution via FileFix Phishing Attack under investigation.
4Potential RCE via Malicious URL Shortcut and WebDAVPotential RCE via Malicious URL Shortcut and WebDAV under investigation.
5Potential REMCOS Remote Access Trojan ActivityPotential REMCOS Remote Access Trojan Activity under investigation.
6Potential REMCOS Remote Access Trojan Activity_ep-registryPotential REMCOS Remote Access Trojan Activity detected in registry modifications.
7Potential System Boot File Tampering via Deletion or ModificationPotential System Boot File Tampering via Deletion or Modification under investigation.
8Potential Web Shell ASPX File CreationInvestigating potential web shell ASPX file creation in Microsoft Shared Web Server Extensions.
9Suspicious DNS Communication to High-Risk TLDs by LOLBINsSuspicious DNS Communication to High-Risk TLDs by LOLBINs under investigation.
10Suspicious Modification of WINDIR  or SystemRoot Environment VariablesSuspicious modification of WINDIR or SystemRoot environment variables detected.
11Suspicious Service ImagePath Registry ModificationSuspicious modification of service ImagePath registry key.
12Suspicious System File Ownership or Permission ModificationSuspicious System File Ownership or Permission Modification investigation.
13WDAC Policy File creation by an Unusual ProcessWDAC Policy File creation by an Unusual Process under investigation.
14Windows Script Execution from Archive via Compressed FilesInvestigating Windows Script Execution from an Archive via Compressed Files.