π Key Highlights
π Malicious Python Package Installation
Introduced a new analytic story with four detections focused on abuse of the Python package installation lifecycle. New coverage identifies unexpected network connections during package builds, creation of executable .pth configuration files and Python site hooks, and manipulation of the PYTHONPATH environment variable. These analytics help defenders uncover supply-chain compromises that execute code during installation or establish persistence across subsequent Python sessions, improving visibility into threats targeting developer workstations and build environments.
π΅οΈ Vidar Stealer Detection Coverage
Introduced a new analytic story for the Vidar information stealer, combining a new detection for uncommon processes reading sensitive cloud profile files with existing analytics covering unauthorized browser credential-store access and suspicious process behavior. This coverage helps identify attempts to collect saved credentials, cookies, Azure CLI profile metadata, and other information that could support account takeover, cloud reconnaissance, or data exfiltration, giving defenders an earlier opportunity to contain compromised Windows endpoints.
πͺ RoguePlanet and ShieldBreak Privilege Escalation
Expanded the RoguePlanet analytic story with six new detections targeting Windows Defender race-condition exploitation and related ShieldBreak techniques. The new analytics identify alternate data streams created through local shares, suspicious use of Defender components, threat events referencing kernel object paths, manually staged Windows Error Reports, phantom DLL creation, and Windows Error Reporting processes spawning SYSTEM-integrity children. This provides stronger visibility into Defender scanning abuse, DLL hijacking, and attempts to escalate from a low-privileged context to SYSTEM.
π‘οΈ EDR Defense Evasion Detection
Added two behavioral analytics for EDRSilencer-style tampering through the Windows Filtering Platform. The detections identify custom outbound filters and filtering rules designed to block security processes from communicating with their management infrastructure, helping defenders recognize attempts to suppress endpoint telemetry or disrupt response capabilities before attackers continue post-compromise activity.
π― Cross-Platform Detection Refinements
Updated 46 analytics across Windows, Linux, macOS, ESXi, and AWS Bedrock to improve detection fidelity and behavioral coverage. The refinements strengthen visibility into AI infrastructure abuse, credential access, browser data theft, process injection, persistence, privilege escalation, reconnaissance, security-tool tampering, and destructive activity, helping security teams investigate suspicious behavior across a broader range of endpoint, virtualization, and cloud telemetry.
ποΈ Legacy F5 Detection Retirement
Scheduled the experimental detection for F5 TMUI remote code execution (CVE-2020-5902) for removal in a future release. The analytic targets an older platform version that is no longer supported by F5 and has remained experimental since 2020, allowing the content library to prioritize relevant, supportable detection coverage.
New Analytic Story - [2]
Updated Analytic Story - [1]
New Analytics - [13]
- Python Network Traffic During Package Build
- Python PTH File Creation During Package Installation
- Python PYTHONPATH Modification During Package Installation
- Python Site Hooks Creation During Package Installation
- Windows Alternate Data Stream Created Over Local Share
- Windows Cloud Sensitive File Read Access By Uncommon Process
- Windows Defender MpClient.dll Loaded by Non-Defender Process
- Windows Defender Threat Detected on Kernel Object Path
- Windows EDRSilencer Custom Outbound Filter Added
- Windows Error Report Created in ReportQueue Manually
- Windows Filtering Platform Filter Added To Block EDR Process
- Windows Phantom DLL Created on Disk
- Windows Wermgr Spawning System Integrity Process
Updated Analytics - [46]
- AWS Bedrock Claude Cross Region Possible Inference Abuse
- AWS Bedrock Claude Hostile Prompt Sentiment
- AWS Bedrock Claude Possible Prompt Injection
- AWS Bedrock Claude Sensitive Data in Prompts
- AWS Bedrock Claude Unusually Large Prompts
- ESXi Encryption Settings Modified
- Excessive Usage of NSLOOKUP App
- Executables Or Script Creation In Suspicious Path
- Executables Or Script Creation In Temp Path
- Linux Auditd Unix Shell Configuration Modification
- Linux Binary Launched Process with Null Argv
- Linux Malformed Auth Entry
- Linux PF_ALG Registration Outside of Boot Window
- Linux Possible Append Command To Profile Config File
- Linux Suspicious Namespace Creation
- MacOS List Firewall Rules
- Msmpeng Application DLL Side Loading
- Non Chrome Process Accessing Chrome Default Dir
- Non Firefox Process Access Firefox Profile Dir
- Ping Sleep Batch Command
- Windows Access Token Manipulation SeDebugPrivilege
- Windows Admin Password Changed by Non-Admin
- Windows App Layer Protocol Wermgr Connect To NamedPipe
- Windows Cloud Files Filter Log Created by Non-System Process
- Windows Credentials from Password Stores Chrome Extension Access
- Windows Credentials from Password Stores Chrome LocalState Access
- Windows Credentials from Password Stores Chrome Login Data Access
- Windows Disable or Stop Browser Process
- Windows Indicator Removal Via Rmdir
- Windows Modify Registry Configure BitLocker
- Windows Modify Registry Disable RDP
- Windows MsMpEng Writing to System32
- Windows Non-System Process Querying Definition Update
- Windows Powershell Commands from DNS TXT
- Windows Process Injection Remote Thread
- Windows Process Injection Wermgr Child Process
- Windows Query Registry UnInstall Program List
- Windows Screen Capture in TEMP folder
- Windows Set Account Password Policy To Unlimited Via Net
- Windows Suspicious Burst of Password Changes
- Windows Suspicious Child Process of TieringEngineService.exe
- Windows Suspicious Defender Engine or Signature Files Created
- Windows Suspicious Defender Update Activity in INetCache
- Windows Suspicious Process File Path
- Windows Unsigned MS DLL Side-Loading
- Windows VSSVC Process Accessing Defender Engine
Content Scheduled for Removal in Future Releases
| Content | Content Type | Removed in Version | Reason | Replacement Content |
|---|---|---|---|---|
| Detect F5 TMUI RCE CVE-2020-5902 | Detection | 6.8.0 | Detection deprecated as it is targeting a 6 years old CVE that is no longer relevant, since the OS version targeted is no longer supported by F5. As well, the fact that the detection has been set to experimental since 2020. | None |