Recent updates in detection engineering include the addition and refinement of detection rules across multiple platforms and repositories. Notable changes involve new Sigma rules targeting the 'EDR-Freeze' technique, which exploits debugging libraries to suspend security processes, as well as expanded detection for server-side application exploits and malicious named pipe activity. These updates aim to improve coverage for threats such as LSASS credential dumping, suspicious child processes in Node.js and Java environments, and Linux-based threats, enhancing overall threat detection capabilities.
In parallel, there is an ongoing discussion within the detection engineering community about the design and effectiveness of atomic detection rules. Atomic detection rules are foundational elements in threat detection, focusing on identifying discrete, observable attacker behaviors. The field emphasizes balancing detection efficacy, minimizing false positives and negatives, and understanding the context in which rules operate. This conceptual framework guides the continuous improvement of detection strategies and the development of new rules to address evolving attacker techniques.

See real exploitation activity before you spend the cycle.
8 events from the most recent confirmed update back to the earliest known activity.
On 2025-12-15, Detection Engineering published an article arguing that narrowly scoped atomic detection rules are easy to deploy but brittle, noisy, and easy for attackers to evade. The piece recommends more context-rich, behavior-based detections and frames the tradeoff using the Pyramid of Pain and operational-cost examples.
Numerous existing rules were modified to improve operational use, including Linux auditd schema fixes, new investigation guides, cloud detection refinements for AWS, GitHub, and Entra ID, and migrations from EQL to ESQL. The changes were aimed at better scalability and lower alert noise.
During the Dec. 8-15 period, new and improved email detections were introduced for phishing activity including Impact Solutions PhaaS, Adobe Sign impersonation, and callback phishing using Microsoft Teams invites. These updates expanded coverage of social-engineering and service-abuse techniques.
Multiple repositories added Linux-focused YARA and behavioral detections, including rules for ELF malware families such as ZinFoq, Kaiji variants, CowTunnel, and PeerBlight. Behavioral rules were also tuned to reduce false positives in containerized and development environments.
Repositories added or expanded detections for suspicious child processes spawned by Node.js, React, and Next.js servers on Windows and Linux. They also added a Java template-injection pattern that looks for XSL/XSLT file creation followed by shell execution.
In the same update period, new Sysmon-based rules were introduced to identify suspicious named pipe activity associated with persistence and lateral movement. These additions expanded behavioral coverage for common post-compromise tradecraft.
During the Dec. 8-15, 2025 update window, repositories added Sigma detections for the "EDR-Freeze" technique abusing dbgcore.dll and dbghelp.dll to suspend security processes. Related detection logic was also added for LSASS credential-dumping behaviors.
Between 2025-12-08 and 2025-12-15, a weekly review of 11 monitored GitHub repositories recorded 31 new detection rules and 77 updated rules. The changes spanned Sigma, Sysmon, YARA, email security, cloud, and Linux-focused detections.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See real exploitation activity behind this advisory so you can triage it against everything else in the queue.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.