Skip to main content

March 31, 2026 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew13
Enhanced1
DashboardsNew
ReportsNew

New Detections

#NameDescription
1PowerShell In Memory DotNet Assembly ExecutionDetects PowerShell In Memory DotNet Assembly Execution using specific script patterns.
2Unusual Use of SeIncreaseBasePriorityPrivilegeUnusual Use of SeIncreaseBasePriorityPrivilege under investigation.
3Suspicious Persistence Creation via Msiexec Using Startup or Registry Run Key ep-fileSuspicious persistence creation via msiexec using startup or registry run keys under investigation.
4NTLM Authentication Downgrade via LmCompatibilityLevelInvestigating NTLM Authentication Downgrade via LmCompatibilityLevel attack.
5Suspicious Indirect Command Execution via ForFilesSuspicious Indirect Command Execution via ForFiles under investigation.
6Windows Sandbox Misuse with Host File AccessInvestigating Windows Sandbox misuse with host file access.
7Suspicious Script Host Spawned Command ExecutionSuspicious Script Host Spawned Command Execution under investigation.
8Foxmail Email Client Exploitation via Temp Directory ExecutionFoxmail Email Client Exploitation via Temp Directory Execution under investigation.
9Notepad Markdown File Exploitation Leading to Child Process ExecutionNotepad Markdown File Exploitation Leading to Child Process Execution under investigation.
10Suspicious COM RunAs Registry ModificationSuspicious COM RunAs Registry Modification detected. Investigating potential unauthorized registry changes.
11Suspicious Persistence Creation via Msiexec Using Startup or Registry Run Keys_ep-registrySuspicious persistence creation via Msiexec using startup or registry run keys under investigation.
12Downloaded Script Execution via Windows Script InterpretersDownloaded Script Execution via Windows Script Interpreters under investigation.
13VSCode Remote Tunnel Establishment ActivityVSCode Remote Tunnel Establishment Activity under investigation.

Enhanced Detection

#NameDescription
1System Information Discovery – LINUXThis use case identifies suspicious system information discovery activities by monitoring executed processes captured byauditd. Attackers may execute commands to gather details about the system, network, and users as part of the reconnaissance phase of their attack lifecycle.