We are pleased to announce that our latest Trellix Endpoint Detection and Response with Forensics (EDRF) Cloud threat detection update for June 2026 is now available.
This cumulative report summarizes the detection content released throughout May 2026, adding 34 new detections to your defense stack.
Key threat coverage
-
Adversary simulation and injection tracking:
Expanded detection for Cobalt Strike Beacon executing via Rundll32.exe for keylogging / screen captures, refined filtering for System32 process injection to minimize user-directory false-positives, and new correlation logic for Chrome credential theft during red team injection scenarios.
-
macOS coverage and multi-stage defenses:
Introduced dedicated protection against the macOS "ClickFix" tech-impersonation campaign and infostealers. -
Masquerading and evasion defense:
Hardened detection capabilities against malicious files attempting to evade notice by using spoofed, legitimate-looking filenames and file paths.
These updates are fully compatible with all EDR and EDRF client versions. There is no action required.
For more details and a complete list of the changes, see the release details in the Knowledge article Trellix EDRF Cloud Threat Detection Updates – June 2026.