Skip to main content

July 27, 2026 – Content update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew15
Enhanced
DashboardsNew
ReportsNew

New Detections
#NameDescription
1Password Change on Directory Services Restore Mode AccountInvestigation of password change on Directory Services Restore Mode account.
2Local User Account Created by ANONYMOUS LOGONLocal User Account Created by ANONYMOUS LOGON under investigation.
3High Severity Windows Defender Threat DetectionHigh Severity Windows Defender Threat Detection under investigation.
4SAM Registry Hive Handle Request DetectionDetects unauthorized SAM registry access attempts.
5Download From Suspicious Remote SourceDetects downloads from suspicious remote sources using specific patterns.
6Sysmon Event Channel Registry TamperingSysmon Event Channel Registry Tampering under investigation.
7Active Directory Privileged Account or Group EnumerationActive Directory Privileged Account or Group Enumeration under investigation.
8Active Directory DCSync Replication Request By Non Machine AccountActive Directory DCSync Replication Request By Non Machine Account under investigation.
9Credential Dumping Tool Service Installation DetectionDetects installation of credential dumping tools on Windows systems.
10Windows Defender Virus Scanning Feature DisabledWindows Defender Virus Scanning Feature Disabled under investigation.
11Suspicious Temporary File Creation by SvchostSuspicious Temporary File Creation by Svchost under investigation.
12Kerberos Ticket Kirbi File Creation DetectionDetects creation of Kerberos Ticket Kirbi files in common directories.
13LSASS Access Via Secondary Logon Service DetectionDetects LSASS access via Secondary Logon Service on Windows.
14Kali Linux Installation or Execution via WSLDetects installation or execution of Kali Linux via WSL.
15LSA Protection Disabled Via Registry ModificationLSA Protection Disabled Via Registry Modification detected. Investigating unauthorized registry changes.