December was another impressive month for the Threat Bounty Program, with 33 new detection rules successfully released.
Starting January 2025, the acceptance of new Threat Bounty detections has been temporarily suspended.
The SOC Prime Platform is undergoing enhancements to improve user experience and provide more opportunities for Threat Bounty Program members.
Top detection rules in December included rundll32 usage for LOLBin exploitation, possible privilege escalation attempts, suspicious TA4557/FIN6 execution, and possible persistence activities of APT35 and BlackCat Ransomware.