Skip to main content

May 27, 2026 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows and Linux.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew27
Enhanced1
DashboardsNew
ReportsNew

New Detections

#NameDescription
1Masquerading Space After FilenameDetects processes with trailing spaces in filenames to evade detection.
2Tampering of Shell Command-Line HistoryTampering of Shell Command-Line History involves altering or deleting shell history to evade detection.
3Potential Traffic Tunneling using QEMUPotential Traffic Tunneling using QEMU under investigation.
4Credential Access via TruffleHog ExecutionCredential Access via TruffleHog Execution under investigation.
5PowerShell Keylogging Script DetectionPowerShell Keylogging Script Detection under investigation.
6Potential Process Injection via PowerShellPotential Process Injection via PowerShell under investigation.
7Suspicious HybridConnectionManager Service InstallationSuspicious HybridConnectionManager Service Installation under investigation. Attack targets Linux, Windows, macOS.
8Invoke-Obfuscation IEX Obfuscation via Service Installation – Security logInvestigating Invoke-Obfuscation IEX via Service Installation
9Windows Screen Capture Via PowershellInvestigating Windows screen capture via PowerShell script.
10Potential Invoke-Obfuscation STDIN PowerShell Launcher ExecutionPotential Invoke-Obfuscation STDIN+ PowerShell Launcher Execution under investigation.
11Potential Invoke-Mimikatz PowerShell Script DetectionPotential Invoke-Mimikatz PowerShell Script Detection under investigation.
12Potential PowerShell Invoke-NinjaCopy Script ExecutionPotential PowerShell Invoke-NinjaCopy Script Execution detected via specific script block text patterns.
13Invoke-Obfuscation IEX Obfuscation via Service InstallationInvoke-Obfuscation IEX Obfuscation via Service Installation under investigation.
14PowerShell Script with Audio Capture CapabilitiesPowerShell script with audio capture capabilities under investigation.
15Invoke-Obfuscation IEX Obfuscation via PowerShell Script BlockInvestigating Invoke-Obfuscation IEX via PowerShell Script Block.
16Potential Reverse Shell Activity via TerminalPotential Reverse Shell Activity via Terminal under investigation.
17Invoke-Obfuscation IEX Obfuscation via Process ExecutionInvoke-Obfuscation IEX Obfuscation via Process Execution under investigation.
18Web Server Access Log DeletionInvestigating deletion of web server access logs to evade detection.
19Invoke-Obfuscation Detection via Rundll32Detects obfuscated commands via Rundll32 on Windows systems.
20Potential Traffic Tunneling using QEMU_ep-processPotential Traffic Tunneling using QEMU under investigation.
21Suspicious Web Server Access Log InteractionSuspicious Web Server Access Log Interaction under investigation.
22Potential Invoke-Mimikatz PowerShell Process ExecutionPotential Invoke-Mimikatz PowerShell Process Execution under investigation.
23Credential Acquisition via Registry Hive DumpingCredential Acquisition via Registry Hive Dumping under investigation.
24Curl or Wget Spawned via Node JSDetects Curl or Wget commands spawned via Node.js processes.
25Modification of WDigest Security ProviderModification of WDigest Security Provider under investigation.
26Outlook Home Page Registry ModificationOutlook Home Page Registry Modification under investigation. Targets Office Suite, Windows.
27Credential Acquisition via Registry Hive Dumping_ep-registryCredential Acquisition via Registry Hive Dumping under investigation. Attack involves modifying registry objects.

Enhanced Detection

#NameDescription
1Suspicious Shell History ManipulationThis detection focuses on identifying the deletion or manipulation of the Suspicious Shell History Manipulation (.bash_history). This file logs all commands executed in the Bash shell and is often targeted by malicious actors to cover their tracks. Monitoring such activities is crucial for identifying and mitigating potential threats.