logo

Microsoft Defender Adds Monitoring for RPC Protocol Abuse in Cyberattacks

ID: 8760d76f-13c1-5c93-a9d5-4a584af5cf92

STIX ID: report--8760d76f-13c1-5c93-a9d5-4a584af5cf92

Feed Name: GBHackers

Date Published: 2026-06-09

Date Updated: 2026-06-09

Author: Divya

...
...

Microsoft announced enhanced monitoring in Defender for Endpoint that inspects inbound remote RPC calls at the operation-number (OpNum) level via audit-only Windows Filtering Platform filters, providing function-level visibility into RPC activity. The feature surfaces detailed telemetry in Advanced Hunting, includes built-in detections and automated disruption for several RPC-based techniques (e.g., remote service creation, Remote Registry credential dumping, session enumeration, authentication coercion), and is available for workstations with server rollout ongoing.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.