- Product
Kindling
Product Overview
Sophisticated security with unmatched simplicityCloud SIEM
Pre-configured detections across your environmentHoneypots
Deception technology to detect lateral movementEndpoint Visibility
Real-time monitoring with added detection & responseSecurity Reports
Data visualizations, compliance reports, and executive summariesAutomated Response
Detect, prioritize, and neutralize threats around the clockIntegrations
Cloud, on-prem, and open API connectionsXDR Platform
A complete view to identify risk, and things operational
- Pricing
- Why Blumira
Why Blumira
The Security Operations platform IT teams loveWatch A Demo
See Blumira in action and how it builds operational resilienceUse Cases
A unified security solution for every challengePricing
Unlimited data and predictable pricing structureCompany
Our human-centered approach to cybersecurityCompare Blumira
Find out how Blumira stacks up to similar security toolsIntegrations
Cloud, on-prem, and open API connectionsCustomer Stories
Learn how others like you found success with Blumira
- Solutions
- Partners
- Resources
Two new Windows detections landed this month, both aimed at persistence techniques: one flags Node.js-based malware writing Registry Run keys to survive reboots, the other catches suspicious javaw.exe and regedit.exe execution from ProgramData paths — a location attackers favor because it’s writable without elevation and rarely watched as closely as Program Files. We also wrapped up the phased retirement of the older indicator-based Connection from Public IP conditions now that the replacement method has cleared its soak period. On the integration side, four new log sources are now parsed: Cisco Secure Endpoint, Untangle firewalls, Barracuda CloudGen firewalls, and HP/Aruba AOS-CX switches. Webhooks for finding event forwarding are now available to all customers on an active paid license.
Detection Updates
| Log Type | Details |
|---|---|
| Windows |
NEW - Node.js Spawning Command Processor to Add Registry Run Key This detection identifies a node.exe process spawning cmd.exe to add a Windows Registry Run key. Node.js-based remote access trojans use this technique to establish persistence, re-executing their payload every time the user logs in as part of a paste-and-run initial access chain that can lead to ransomware. While node.exe can legitimately spawn cmd.exe, creating a Run key from that process tree is not expected behavior and warrants immediate investigation.Default state: Disabled |
| Windows |
NEW - Suspicious Process Execution from ProgramData This detection identifies javaw.exe or regedit.exe launching from ProgramData paths, a pattern seen in a real customer incident involving a Java-based dropper disguised as mail server setup software. Attackers favor ProgramData because it’s writable without elevated privileges and rarely monitored as closely as Program Files. Execution from this location by these processes is unusual and worth investigating.Default state: Disabled |
| Multiple |
UPDATE - Connection from Public IP We retired the older indicator-based Connection from Public IP conditions now that the replacement detection method has cleared its testing period, reducing noise while preserving coverage. |
Bug Fixes and Improvements
Bug Fixes
- JUNOS Parser - Data Plane Logs: We fixed an issue where JUNOS data plane logs weren’t being parsed, so those events weren’t reaching detections and search.
Improvements
- Cisco Secure Endpoint Log Parsing: Cisco Secure Endpoint (formerly Cisco AMP) logs sent via HTTP Ingest are now parsed, making their events available for detections and search.
- Untangle Firewall Log Parsing: Untangle firewall logs are now parsed, making their events available for detections and search.
- Barracuda CloudGen Firewall Log Parsing: Barracuda CloudGen Firewall logs are now parsed, making their events available for detections and search.
- HP/Aruba AOS-CX Switch Log Parsing: HP and Aruba AOS-CX switch logs are now parsed, making their events available for detections and search.
- Webhooks - Expanded Access: Webhooks for finding event forwarding are now available to all customers on an active paid license, expanding beyond the limited early rollout.
June 2026 Release Notes
In case you missed the June updates, you can find and review those notes here.
Amanda Berlin
Amanda Berlin is the Senior Product Manager of Cybersecurity at Blumira, bringing nearly two decades of experience to her position. At Blumira she leads a team of incident detection engineers who are responsible for creating new detections based on threat intelligence and research for the Blumira platform. An...
More from the blog
View All PostsSubscribe to email updates
Stay up-to-date on what's happening at this blog and get additional content about the benefits of subscribing.