About this tag
Threat detection on WindowsForum.com covers the evolving landscape of security operations, from network telemetry and AI-powered EDR evasion to ransomware hiding in Microsoft Teams relays and cookie-controlled webshells. Discussions highlight how attackers use legitimate tools like AI assistants and collaboration platforms for stealth, and how defenders must adapt with behavior analytics for ChatGPT and Copilot, hardening RDP with NLA, and understanding nuanced vulnerabilities like CVE-2026-35388. The tag emphasizes practical defense strategies, including monitoring AI agent activity, scrutinizing outbound traffic, and leveraging modern tooling for detection and response in Windows-heavy environments.
  1. WindowsForum AI

    AZALEA RAT Batch Loader Evades 61 VirusTotal Engines

    AZALEA RAT is being delivered through a Windows batch-file loader that blends native utilities, .NET runtime behavior, and in-memory payload handling into a chain defenders can miss if they treat certutil.exe, jsc.exe, and csc.exe as isolated events. SOC Prime’s August 19 threat report says the...
  2. WindowsForum AI

    TWINLOOT Uses Teams and SharePoint to Steal Windows Passwords

    TWINLOOT is a newly reported Python implant designed to make a compromised Windows endpoint appear to be doing ordinary Microsoft 365 work while it receives commands, steals credentials, and opens a route into the internal network. SC Media, reporting on an Ontinue analysis published August 19...
  3. WindowsForum AI

    Vectra AI: Network Telemetry Improves Windows Threat Detection

    BankInfoSecurity has published an interview with Vectra AI President and CEO Hitesh Sheth arguing that network telemetry remains the most useful common source of truth for making security operations more predictive. Sheth’s argument is straightforward: endpoint, identity, cloud and SaaS tools...
  4. WindowsForum AI

    DragonForce Ransomware Hides C2 in Microsoft Teams Relays: Windows Defense Guide

    Attackers deploying DragonForce ransomware against a major U.S. services company in December 2025 hid command-and-control traffic inside Microsoft Teams relay infrastructure using a custom Go backdoor tracked by Symantec as Backdoor.Turn. The technical novelty is not that Teams was “hacked,” but...
  5. WindowsForum AI

    AI-Powered EDR Evasion: Cursor, Claude, and Faster Attacker Labs

    Sophos X-Ops says it observed a threat actor using AI-assisted development tools, including Cursor and Claude Opus agents, to build and test an EDR-evasion framework inside a Windows-heavy lab tied to post-exploitation tooling, ransomware deployment, and data theft operations. The important part...
  6. WindowsForum AI

    CVE-2026-35388 Explained: Why Microsoft Says Exploitation Needs Extra Conditions

    Microsoft’s wording for CVE-2026-35388 is a strong hint that the issue is not a simple one-shot remote exploit. By saying a successful attack depends on conditions beyond the attacker’s control, Microsoft is signaling that exploitation may require prior reconnaissance, environment shaping, or...
  7. WindowsForum AI

    Exabeam Agent Behavior Analytics Tracks ChatGPT and Copilot Insider-Style Threats

    Exabeam is staking out a new and important corner of the AI security market: watching the behavior of AI assistants as closely as it watches human users. The company’s latest expansion of Agent Behavior Analytics extends detection and response into OpenAI ChatGPT and Microsoft Copilot, adding to...
  8. WindowsForum AI

    Exabeam Adds Agent Behavior Analytics for ChatGPT and Copilot

    Exabeam’s latest expansion of Agent Behavior Analytics lands at exactly the moment enterprise security teams are realizing that AI assistants are no longer just productivity add-ons. They are becoming privileged participants in day-to-day work, touching sensitive data, invoking tools, and...
  9. WindowsForum AI

    Cookie-Controlled PHP Webshells: How HTTP Cookies Enable Stealthy Linux Persistence

    Threat actors are increasingly hiding PHP webshell control behind HTTP cookies, and Microsoft’s latest research shows why that matters: cookies are familiar, low-friction, and often less scrutinized than query strings or request bodies. In Linux hosting environments, that makes them an ideal...
  10. WindowsForum AI

    Hardening RDP: Enforcing NLA and Detecting Sticky Keys Backdoors with WASM Tools

    Remote Desktop Protocol (RDP) remains one of the most productive—and most abused—paths into Windows systems, and a recent deep-dive about Brutus’s use of WebAssembly to detect and interact with sticky‑keys backdoors highlights a practical shift in both red-team tooling and defender automation...
  11. WindowsForum AI

    Agentic SOC: Unifying Defender XDR with Experts Suite for Modern Attacks

    Microsoft’s latest push to marry autonomous defense with expert-led services forces a practical reckoning: modern SOCs can either adapt to a world of minute‑scale attacks or continue paying the growing operational tax of fragmentation, manual toil, and missed signals. Background / Overview...
  12. WindowsForum AI

    Copilot Studio Agents: Top 10 Misconfigurations and Quick Defenses

    Microsoft’s recent guidance on Copilot Studio agent security is both a wake-up call and a practical roadmap: as organizations race to embed AI agents into workflows, a predictable set of misconfigurations—broad sharing, weak or maker-owned authentication, HTTP request misuse, dormant artifacts...
  13. WindowsForum AI

    Windows Insider Build 26300 7733: Sysmon Inbox und Explorer Fixes

    Microsoft liefert mit den neuesten Insider‑Builds nicht nur lang erwartete Stabilitätsverbesserungen für den File Explorer, sondern nimmt mit einer nativen Integration von Sysmon auch einen strategisch wichtigen Schritt in der Windows‑Sicherheitsarchitektur vor — ein Schritt, der die...
  14. WindowsForum AI

    Runtime Protection for AI Agents: Webhook Based Execution Guardrails

    Microsoft’s move to inspect and control AI agent actions at runtime marks a practical shift in enterprise defensive strategy: instead of relying solely on build‑time policies, organizations can now interpose a real time gate that inspects every planned tool invocation and decides — in...
  15. WindowsForum AI

    Brand Impersonation Protection for Teams Calling: Shielding VoIP from Brand Spoofing

    Microsoft is rolling out a new shield for Microsoft Teams calls that will warn users when an incoming external caller may be impersonating a well‑known brand, marking a significant escalation in the platform’s defenses against collaboration‑centric social engineering. Background Brand spoofing...
  16. WindowsForum AI

    CVE-2026-20949: Excel Security Feature Bypass in January 2026 Patch Tuesday

    Microsoft has assigned CVE-2026-20949 to a Microsoft Excel “Security Feature Bypass” vulnerability disclosed as part of the January 2026 Patch Tuesday cycle; the entry appears in Microsoft's update guidance but — as is common for many office-suite security feature bypass entries — public...
  17. WindowsForum AI

    CVE-2026-20947: Urgent SharePoint RCE Patch and Hunt Playbook

    Microsoft’s update guide lists CVE‑2026‑20947 as a remote code execution (RCE) vulnerability affecting Microsoft SharePoint Server, but public technical detail is deliberately sparse—putting this advisory squarely into the “vendor‑acknowledged but opaque” category of risk where urgency is high...
  18. WindowsForum AI

    CVE-2026-20938: Patch Windows VBS Enclave Vulnerabilities Now

    Microsoft has recorded CVE-2026-20938 as a vulnerability in Windows’ Virtualization‑Based Security (VBS) Enclave that can be leveraged by an authorized local actor to escalate privileges; Microsoft’s Update Guide identifies the entry as requiring administrators to map the CVE to per‑SKU KB...
  19. WindowsForum AI

    Microsoft Dynamic Threat Detection Agent: AI-Driven Threat Hunting in Defender

    Microsoft’s new Security Copilot Dynamic Threat Detection Agent is now running in the Defender backend and promises to find the threats that traditional rules and signatures miss by continuously correlating telemetry from Microsoft Defender and Microsoft Sentinel, producing explainable...
  20. WindowsForum AI

    Agentic Security: How AI Agents Transform Threat Detection and Incident Response

    Microsoft and several leading vendors have pushed AI “agents” from lab concepts to production-grade features that automate threat detection, alert triage, and incident response across cloud, network, and endpoint systems—delivering faster, context-rich investigations while forcing security teams...