Detection as Code
Monthly Adversary Tradecraft Spotlight – June

Monthly Adversary Tradecraft Spotlight – June

OpenWith.exe Executes Specified Binary This technique leverages OpenWith.exe as a proxy execution mechanism to run arbitrary code while blending in with legitimate system activity. It is a trusted Windows binary that is typically used when a user selects “Open with…”...

Monthly Adversary Tradecraft Spotlight – May 2026

Monthly Adversary Tradecraft Spotlight – May 2026

Windows Recovery Environment Disabled Via Reagentc WinRE exists specifically to help users repair boot problems, restore previous system states, and troubleshoot failures when Windows can no longer start normally. Disabling the Windows Recovery Environment (WinRE) is...

Monthly Adversary Tradecraft Spotlight – April 2026

Monthly Adversary Tradecraft Spotlight – April 2026

Powershell LocalAccount Manipulation The manipulation of local user accounts with PowerShell commands (related to account management operations) can occur during legitimate administrative tasks but become suspicious when they appear unexpectedly or in an unusual...