Great find!
Existing Elastic coverage, plus a new detection for changelist Alternate Data Stream creation by unusual process (MRT.exe)
github.com/elastic/detect…
⚒️ BTR Reforged: Weaponizing Defender's Remediation Driver as a Kernel Operation Primitive
⚠ Trusted Remediation Primitives with Undocumented Internals.
🔓 15+ years. Unchanged. Unblockable.
🤔 What if an attacker learned its language? We did.
👇
research.checkpoint.com/2026/btr-refor…
Malicious browser extensions can be a tricky attack vector and may go unnoticed, been playing with Elastic workflow + Elastic Defend response console, daily hunt for newly installed browser extensions using file events -> reputation check -> if suspicious -> archive and delete
Quick Assist is a built-in Windows remote support tool that's increasingly abused in social engineering campaigns. Because it's installed by default on Windows clients, it's an attractive alternative to traditional RMM tools. When a user grants Full Control, Windows logs a useful
gluegate - proxy memory allocation APIs through Firefox's signed mozglue.dll (MapRemoteViewOfFile, MozVirtualAlloc).
Benifit: make the final allocating module appear as a trusted Firefox component, which some detection logic may exclude to reduce false positives.
PoC +