Skip to main content

July 7, 2026 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew15
Enhanced
DashboardsNew
ReportsNew

New Detections

#NameDescription
1Active Directory DCSync Rights Delegation via ntSecurityDescriptor ModificationActive Directory DCSync Rights Delegation via ntSecurityDescriptor Modification under investigation.
2Detection of NTDS or SAM Database File CopiedDetection of NTDS or SAM Database File Copied under investigation.
3Microsoft Defender Endpoint Protection ExpiredMicrosoft Defender Antivirus grace period expired, disabling protection against threats.
4Potential Credential Access via Windows UtilitiesPotential Credential Access via Windows Utilities under investigation.
5Potential Firewall Defense Impairment via Rule DeletionPotential Firewall Defense Impairment via Rule Deletion under investigation.
6Potential NetNTLMv1 Downgrade Attack DetectionDetects potential NetNTLMv1 downgrade attacks by monitoring registry modifications.
7Suspicious Active Directory Replication ActivitySuspicious Active Directory Replication Activity under investigation.
8Suspicious Firewall Rule AdditionSuspicious Firewall Rule Addition under investigation.
9Suspicious Headless Browser Execution from Untrusted Parent ProcessDetects headless browser execution from untrusted parent processes.
10Suspicious Service Installation for Meterpreter and Cobalt Strike Getsystem DetectionDetects suspicious service installations indicating Meterpreter or Cobalt Strike activity.
11Suspicious Windows Audit Policy Disable ActivitySuspicious Windows Audit Policy Disable Activity under investigation.
12Suspicious Windows Defender Configuration ChangesSuspicious Windows Defender Configuration Changes detected. Investigating potential disabling of security features.
13Windows Defender Exploit Guard TamperingWindows Defender Exploit Guard Tampering under investigation.
14Windows Defender Security Features DisabledWindows Defender security features disabled by unauthorized users.
15Wireless Credential Dumping using Netsh CommandWireless Credential Dumping using Netsh Command under investigation.