Skip to main content

October 28, 2025 – Content Update

We are committed to continuously strengthening security operations for our customers through our innovative DARC Vault monthly releases. Much like Microsoft’s Patch Tuesday, the DARC Vault acts as a consistent and reliable source of enhanced security content, empowering users to stay ahead of evolving threats with fresh detections every month.

Each month, we deliver the latest Out-Of-The-Box (OOTB) content that not only introduces brand-new capabilities but also enhances existing detections. This fortnight, we are excited to announce a significant update focused on Windows, Linux, Azure, and General Threat Hunting.

Below is a summary of the new additions and improvements:

Summary of Fortnightly Improvements

Content TypeActionsCount
DetectionsNew59
Enhanced
DashboardsNew
ReportsNew

New Detections

#NameDescription
1SSH Enable on ESXi Host via VIM-CMDSSH enabled on ESXi Host via VIM-CMD command execution.
2Potential Hex-Encoded Payload Execution via Command LinePotential Hex-Encoded Payload Execution via Command Line detected and under investigation.
3Suspicious Process Spawned by kthreaddSuspicious Process Spawned by kthreadd under investigation.
4Binary File Modification Detected in System PathsInvestigating suspicious binary file changes involving critical commands.
5Unusual LD_PRELOADLD_LIBRARY_PATH Command Line Arguments editDetects unusual LD_PRELOAD or LD_LIBRARY_PATH command line arguments in executed processes.
6Suspicious SSH Daemon Remote Port Forwarding DetectedSuspicious SSH Daemon Remote Port Forwarding detected on various platforms.
7Potential Data Exfiltration Through CurlPotential data exfiltration via curl command with specific flags and patterns.
8Hex Encoding-Decoding ActivityThis detection rule identifies activities where hex encoding/decoding tools likehexdump,od, orxxdare used. These tools are commonly utilized to analyze or modify binary data, and in some cases, could indicate malicious actions such as the preparation of obfuscated data for exfiltration.
9Suspicious SUDO PASSWD Command ExecutionInvestigating suspicious SUDO PASSWD command execution on various platforms.
10DNS Queries to trycloudflare with Fast-Flux PatternsDNS Queries to trycloudflare with Fast-Flux Patterns under investigation.
11High-Risk Domain TLDs Threat Intelligence MonitoringHigh-Risk Domain TLDs Threat Intelligence Monitoring under investigation. Monitoring domains with risky TLDs.
12Detection of Android Banking Malware Anatsa C2 CommunicationsDetection of Android Banking Malware Anatsa C2 Communications under investigation.
13Detection of CVE-2025-53770 Exploitation Attempt – POST to ToolPane aspxDetection of CVE-2025-53770 Exploitation Attempt – POST to ToolPane aspx under investigation.
14Detect Access and Modification of BitLocker CLSID KeyDetect access and modification of BitLocker CLSID Key in Windows registry.
15Windows System Shutdown or Unexpected Shutdown by Non-System UsersInvestigating unexpected Windows system shutdowns by non-system users.
16Scheduled Task Deletion – UpdaterScheduled Task Deletion – Updater under investigation. Detects deletion of scheduled tasks named ‘Updater’.
17Rhadamanthys – Suspicious Dropper File CreationRhadamanthys – Suspicious Dropper File Creation under investigation.
18Potential Host Escape via Cgroup Release Agent-CVE_2022_0492Investigating potential host escape via Cgroup release agent (CVE-2022-0492).
19Creation or Access of spinstall0 aspx Web ShellDetection of CVE-2025-53770 Exploitation Attempt – Creation or Access of spinstall0 aspx Web Shell under investigation.
20Executable File Creation with Multiple ExtensionsExecutable File Creation with Multiple Extensions under investigation.
21Detection of Windows Defender Driver UnloadingDetection of Windows Defender Driver Unloading under investigation.
22Suspicious DLL Loads for BOF Dynamic API ResolutionSuspicious DLL Loads for BOF Dynamic API Resolution under investigation.
23Windows Gather Victim Network Info Through IP Check Web ServicesWindows Gather Victim Network Info Through IP Check Web Services under investigation.
24Remote File Download via PowerShellDetects potentially malicious remote file download activity executed via PowerShell
25Program Files Directory MasqueradingProgram Files Directory Masquerading under investigation. This attack involves hiding malicious files in legitimate directories.
26Suspicious Browser Child Process CreationSuspicious Browser Child Process Creation under investigation.
27Suspicious Userinit Child ProcessInvestigating suspicious child processes of userinit.exe excluding known safe processes.
28PHP Execution from Non-Standard PathDetects PHP execution from non-standard paths to identify potential masquerading attacks.
29Suspicious LSASS Access via Direct Syscalls – SysWhispers BehaviorSuspicious LSASS Access via Direct Syscalls – SysWhispers Behavior under investigation.
30Potential PrintNightmare Exploitation via Spoolsv AccessPotential PrintNightmare Exploitation via Spoolsv Access under investigation.
31Detect Credential Dumping through LSASS accessThis detection identifies suspicious access to the LSASS (Local Security Authority Subsystem Service) process, which is commonly targeted by attackers to extract credentials stored in memory. Unauthorized access to LSASS is a key indicator of credential dumping attempts using tools like Mimikatz, procdump, and others.
32Cryptocurrency Miner Process ExecutionCryptocurrency Miner Process Execution detected via process creation and command line patterns.
33Proxy Execution via Console Window HostInvestigating Proxy Execution via Console Window Host on Windows platforms.
34Unusual Web Config File AccessInvestigating unusual access to web config files.
35Suspicious WMI Event Subscription CreatedSuspicious WMI Event Subscription Created under investigation. Detects malicious WMI event subscriptions.
36Script Execution via Microsoft HTML ApplicationScript Execution via Microsoft HTML Application under investigation.
37Hidden PowerShell Execution with Suspicious FlagsHidden PowerShell Execution with Suspicious Flags detected. Investigating potential malicious activity.
38Suspicious Process Access via Direct Syscalls – SysWhispers BehaviorSuspicious Process Access via Direct Syscalls – SysWhispers Behavior under investigation.
39Suspicious Remote Process Access by BOFSuspicious Remote Process Access by BOF under investigation.
40LittleCorporal Maldoc InjectionLittleCorporal Maldoc Injection involves process injection via Office apps and memory manipulation.
41Potential File Transfer via CurlPotential File Transfer via Curl under investigation. Detects suspicious curl usage.
42Renamed Automation Script InterpreterRenamed Automation Script Interpreter under investigation.
43Credential Dumping Activity By Python Based ToolCredential Dumping Activity By Python Based Tool under investigation.
44UAC Bypass via WOW64 Logger DLL HijackUAC Bypass via WOW64 Logger DLL Hijack under investigation.
45Suspicious Svchost Process Access via MSBuildSuspicious Svchost Process Access via MSBuild under investigation.
46Potential CobaltStrike BOF Injection via CallTrace PatternPotential CobaltStrike BOF Injection via CallTrace Pattern under investigation.
47Application Installation Detected on Windows SystemInvestigating application installations on Windows using specific command patterns.
48Potential Suspicious Mofcomp ExecutionPotential Suspicious Mofcomp Execution under investigation.
49Suspicious Scripting in a WMI ConsumerSuspicious scripting in WMI Consumer detected. Investigating potential malicious scripting activities.
50Execution via Windows Command Debugging UtilityInvestigating execution via Windows Command Debugging Utility using cdb.exe.
51Detection of Remote Registry Service EnablementDetection of Remote Registry Service Enablement under investigation.
52Persistence via WMI Standard Registry ProviderInvestigating persistence via WMI Standard Registry Provider.
53Code Signing Policy Modification Through RegistryInvestigating Code Signing Policy Modification through registry changes.
54PowerShell Script Block Logging DisabledInvestigating PowerShell Script Block Logging Disabled attack on Windows systems.
55Suspicious Certificate AuthenticationInvestigating suspicious certificate authentication using Kerberos ticket requests.
56High Volume Cloud Storage Uploads MonitoringMonitoring high volume cloud storage uploads excluding OneDrive.
57Azure Key Vault ModifiedThis detection identifies modifications to an Azure Key Vault, such as changes to access policies, network settings, or other configurations. Azure Key Vault is used to store sensitive information like encryption keys, secrets, and certificates. Unauthorized modifications may indicate an attempt to weaken security controls, exfiltrate sensitive data, or establish persistence. Analysts should verify if the change was expected, review the associated user or service principal, and check for privilege escalation or unauthorized access.
58Successful User Removed from Windows GroupSuccessful User Removed from Windows Group under investigation.
59Office 365 Successful Logins Outside of Expected GeolocationsOffice 365 Successful Logins Outside of Expected Geolocations under investigation..