The May 2026 Network detection newsletter includes detection highlights across our network product portfolio. In the past month, almost 150 network rules have been created across Trellix Network Security (NX), Network Detection and Response Sensor (NDRS), and Intrusion Prevention System (IPS) to identify malicious or suspicious network traffic spanning C2 communication, lateral movement, as well as vulnerability exploits.
The May NDR detection focused on various areas, including:
- Data Exfiltration Tradecraft — Living Off Trusted Infrastructure:
- Detection for Rclone/MEGA, Discord, and Telegram
- Microsoft Patch Tuesday vulnerabilities
- Notable Malware and Threat Actor Signals:
- Trojan.TigerRat — Attributed to Lazarus Group (DPRK)
- Trojan.Shamoon — Iranian-linked destructive wiper responsible for the 2012 Saudi Aramco attack
- Backdoor.AdaptixC2 — A newer open-source offensive C2 framework
For IPS, almost 65 rules were added/updated to detect various network-based exploits across multiple software platforms, including:
- Various vulnerabilities across the following categories:
- Router/IoT Device Vulnerabilities
- WordPress Plugin Vulnerabilities
- Windows Privilege Escalation
- Windows RCE / Active Directory
- Web Application Injection
- Authentication & Authorization Failures
- Unauthenticated RCE — Web Apps
Patch Tuesday vulnerabilities include, but are not limited to, the following:
- HTTP: Microsoft Windows Kernel Elevation of Privilege Vulnerability (CVE-2026-33841)
- LDAP: Microsoft Windows Netlogon Remote Code Execution Vulnerability (CVE-2026-41089)
- HTTP: Microsoft Windows Win32k Elevation of Privilege Vulnerability (CVE-2026-35417)
For more details about the detections, see the Knowledge article Trellix Network Detection Newsletter - May 2026.