Skip to main content

May 6, 2026 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This month, we are excited to announce a significant update focused on Windows.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew6
Enhanced3
DashboardsNew
ReportsNew

New Detections

#NameDescription
1WSUS Triggered PsExec Execution from SoftwareDistribution DirectoryWSUS Triggered PsExec Execution from SoftwareDistribution Directory under investigation.
2Service DACL Modification Using SC SDSET CommandService DACL Modification Using SC SDSET Command under investigation.
3Sensitive Registry Hive Access from RegBack DirectorySensitive Registry Hive Access from RegBack Directory under investigation.
4Sensitive Registry Hive Access from RegBack Directory_ep-fileSensitive Registry Hive Access from RegBack Directory under investigation.
5Active Directory NT Security Descriptor Modification on Domain ObjectActive Directory NT Security Descriptor Modification on Domain Object under investigation.
6Hidden Local User Account Created via SAM Registry ModificationHidden Local User Account Created via SAM Registry Modification under investigation.

Enhanced Detection

#NameDescription
1Foxmail Email Client Exploitation via Temp Directory ExecutionFoxmail Email Client Exploitation via Temp Directory Execution under investigation.
2Notepad Markdown File Exploitation Leading to Child Process ExecutionNotepad Markdown File Exploitation Leading to Child Process Execution under investigation.
3VSCode Remote Tunnel Establishment ActivityVSCode Remote Tunnel Establishment Activity under investigation.