The June 2026 Network detection newsletter includes detection highlights across our network product portfolio. In the past month, almost 300 network rules have been created across Trellix Network Security (NX), Network Detection and Response Sensor (NDRS), and Intrusion Prevention System (IPS) to identify malicious or suspicious network traffic spanning C2 communication, lateral movement as well as vulnerability exploits.
NDR detection in May focused on various areas such as
- Lateral movement: New rules cover AD Schema Modifications targeting sensitive attributes which are common precursors to persistence and privilege escalation. LDAP wildcard queries are now detected across 12 high-value attributes
-
Malware command and control
- Backdoors: ENDDOT, DRYNOTE, ERIESNAKE, JS.Generic, Linux.Generic, MAILDOT, TREEWORLD, DANABOT, GREYSHOT, POLLREGISTER, SACREDGAME, SHADYSMILE
- Trojans: AgentTesla, AMOS, AsyncRAT, CobaltStrike (DNS C2), LightRail, ShaiHulud, SmartApeSG, plus generic shellcode loaders
- Downloaders: HOTAIR, PAPERDROP
For IPS, over 230 rules were added / updated to detect various network-based exploits across multiple software platforms including:
- Command Injection (e.g., routers, security tools, and application platforms)
- Remote Code Execution (e.g., Adobe ColdFusion, Joomla, Cockpit CMS, etc.)
- Authentication Bypass (e.g., PAN-OS GlobalProtect, WordPress plugins, etc.)
- SQL Injection (e.g., Ghost CMS, Drupal, etc.)
- Path Traversal, File Upload, Buffer Overflow and other categories are part of security content.
For more details about the detections, see the Knowledge article Trellix Network Detection Newsletter - June 2026.