What's new

Enterprise Security Content Updates v4.44.0 was released on December 4, 2024 and includes the following enhancements:

Key highlights

  • Windows Defender: Two new analytics now surface and summarize alerts from Microsoft Defender Advanced Threat Protection (ATP) as well as Microsoft Defender O365 Incidents.
  • BitLockerToGo Abuse: Two new analytics search for use of the legitimate BitLockerToGo.exe Windows utility. This application has been abused by the Lumma Stealer malware to manipulate registry keys, search for cryptocurrency wallets or credentials, and exfiltrate sensitive data.
  • VaultCLI Usage: One new analytic flags suspicious usage of the VaultCLI.dll, a technique observed by Information-Stealing Malware such as Meduza. This DLL allows processes to extract sensitive credentials from the Windows Credential Vault.
  • Windows RDP Activities: Two new analytics look for potentially suspicious Windows RDP activities.
  • Windows RunMRU Modifications: One analytic monitors changes to the RunMRU registry key. This key, which stores a history of commands executed via the windows Run dialog box, may capture commands run by malware attempting to appear legitimate.
  • Analytic Stories: Three new Analytic Stories have been introduced targeting Lumma Stealer, Meduza Stealer, and PXA Stealer

Macros added

  • ms365_defender_incident_alerts
  • ms_defender_atp_alerts
  • wineventlog_rdp

Updated analytics

A number of analytics have been updated to address minor typos in the description field, make use of macros, or capture equivalent variants of commands.