Detecting Suspicious RMM Tool Execution Chains in Microsoft Defender (T1219)

One of the most common initial access vectors into environments by threat actors is through use of legitimate RMM tooling, offering both hands-on-keyboard access as well as stealth. Read more below for some considerations on detecting such activity.

July 10, 2026 · 9 min · Matt Swann

Detection Deep Dive: Encoded PowerShell Commands (T1059.001)

The first entry in the Detection Deep Dive series: mapping encoded PowerShell execution to detection logic in Microsoft Defender, tuning out the false positives, and knowing what the detection can’t see.

July 7, 2026 · 4 min · Matt Swann

AppDomainManager Injection — Bend .NET Assemblies to Your Will

A deep dive into AppDomainManager injection (T1574.014): how attackers use .NET’s own extensibility model to proxy execution of malicious assemblies through legitimate signed binaries, and what defenders can — and can’t — do about it.

February 12, 2026 · 7 min · Matt Swann