CylanceMDR protection enhancements
CylanceMDR
protection enhancementsDue to some emerging threats,
CylanceMDR
has implemented the following CylanceOPTICS
rules for improved security and telemetry for analysts. These rules are already in effect and no further action is required from your organization.Latest enhancements
Threat or vulnerability | Description |
---|---|
Updated rule for advanced detection of using BCDEdit with the safeboot argument |
|
Updated rule for advanced detection of the dsquery command |
|
Updated rule for advanced detection of suspicious process launches involving cryptographic operations |
|
Updated rule for advanced detection of the execution of gsecdump for credential dumping |
|
Updated rule for advanced detection of a base64-encoded Bitstransfer download using PowerShell |
|
Updated rule for advanced detection of a base64-encoded invocation of the System.Net.Webclient class using PowerShell |
|
Updated rule for advanced detection of a base64-encoded Invoke-Restmethod command using PowerShell |
|
Updated rule for advanced detection of a base64-encoded Invoke-Webrequest command using PowerShell |
|
Updated rule for advanced detection of comprehensive UAC bypass |
|
Updated rule for advanced detection of AMSI bypass using PowerShell Command Execution |
|