> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name.md).

# Alerts by name

Every Analytics alert that Cortex can raise, listed alphabetically. Select an alert to see what it means and what you should do about it.

| Alert                                                                                                                                                                                                                                            |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ |
| [A Backup vault policy was modified](/analytics-alerts/alerts-by-name/a-backup-vault-policy-was-modified.md)                                                                                                                                     |
| [A browser extension was installed or loaded in an uncommon way](/analytics-alerts/alerts-by-name/a-browser-extension-was-installed-or-loaded-in-an-uncommon-way.md)                                                                             |
| [A browser was opened in private mode](/analytics-alerts/alerts-by-name/a-browser-was-opened-in-private-mode.md)                                                                                                                                 |
| [A Cloud DB instance was exported to an unknown destination](/analytics-alerts/alerts-by-name/a-cloud-db-instance-was-exported-to-an-unknown-destination.md)                                                                                     |
| [A cloud function was created with an unusual runtime](/analytics-alerts/alerts-by-name/a-cloud-function-was-created-with-an-unusual-runtime.md)                                                                                                 |
| [A cloud identity created or modified a security group](/analytics-alerts/alerts-by-name/a-cloud-identity-created-or-modified-a-security-group.md)                                                                                               |
| [A cloud identity executed an API call from an unusual country](/analytics-alerts/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country.md)                                                                               |
| [A cloud identity had escalated its permissions](/analytics-alerts/alerts-by-name/a-cloud-identity-had-escalated-its-permissions.md)                                                                                                             |
| [A cloud identity invoked IAM related persistence operations](/analytics-alerts/alerts-by-name/a-cloud-identity-invoked-iam-related-persistence-operations.md)                                                                                   |
| [A cloud identity performed multiple unusual activities](/analytics-alerts/alerts-by-name/a-cloud-identity-performed-multiple-unusual-activities.md)                                                                                             |
| [A cloud identity started a Cloud Shell session](/analytics-alerts/alerts-by-name/a-cloud-identity-started-a-cloud-shell-session.md)                                                                                                             |
| [A cloud instance was stopped](/analytics-alerts/alerts-by-name/a-cloud-instance-was-stopped.md)                                                                                                                                                 |
| [A cloud snapshot of AWS database or storage was modified or shared](/analytics-alerts/alerts-by-name/a-cloud-snapshot-of-aws-database-or-storage-was-modified-or-shared.md)                                                                     |
| [A cloud storage configuration was modified](/analytics-alerts/alerts-by-name/a-cloud-storage-configuration-was-modified.md)                                                                                                                     |
| [A cloud storage object was copied to a foreign cloud account](/analytics-alerts/alerts-by-name/a-cloud-storage-object-was-copied-to-a-foreign-cloud-account.md)                                                                                 |
| [A Command Line Interface (CLI) command was executed from a GCP serverless compute service](/analytics-alerts/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-a-gcp-serverless-compute-service.md)                         |
| [A Command Line Interface (CLI) command was executed from an AWS serverless compute service](/analytics-alerts/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-an-aws-serverless-compute-service.md)                       |
| [A commonly abused process connected to a rare cloud resource](/analytics-alerts/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-cloud-resource.md)                                                                                 |
| [A commonly abused process connected to a rare external host](/analytics-alerts/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-external-host.md)                                                                                   |
| [A compiled HTML help file wrote a script file to the disk](/analytics-alerts/alerts-by-name/a-compiled-html-help-file-wrote-a-script-file-to-the-disk.md)                                                                                       |
| [A compressed file was exfiltrated over SSH](/analytics-alerts/alerts-by-name/a-compressed-file-was-exfiltrated-over-ssh.md)                                                                                                                     |
| [A compromised process accessed a rare cloud resource](/analytics-alerts/alerts-by-name/a-compromised-process-accessed-a-rare-cloud-resource.md)                                                                                                 |
| [A compromised process accessed a rare external host](/analytics-alerts/alerts-by-name/a-compromised-process-accessed-a-rare-external-host.md)                                                                                                   |
| [A compute-attached identity executed API calls outside the instance's region](/analytics-alerts/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region.md)                                                 |
| [A computer account was promoted to DC](/analytics-alerts/alerts-by-name/a-computer-account-was-promoted-to-dc.md)                                                                                                                               |
| [A contained executable from a mounted share initiated a suspicious outbound network connection](/analytics-alerts/alerts-by-name/a-contained-executable-from-a-mounted-share-initiated-a-suspicious-outbound-network-connection.md)             |
| [A contained executable was executed by an unusual process](/analytics-alerts/alerts-by-name/a-contained-executable-was-executed-by-an-unusual-process.md)                                                                                       |
| [A contained process attempted to escape using the 'notify on release' feature](/analytics-alerts/alerts-by-name/a-contained-process-attempted-to-escape-using-the-notify-on-release-feature.md)                                                 |
| [A container registry was created or deleted](/analytics-alerts/alerts-by-name/a-container-registry-was-created-or-deleted.md)                                                                                                                   |
| [A disabled user attempted to authenticate via SSO](/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-authenticate-via-sso.md)                                                                                                       |
| [A disabled user attempted to log in](/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-log-in.md)                                                                                                                                   |
| [A disabled user attempted to log in to a VPN](/analytics-alerts/alerts-by-name/a-disabled-user-attempted-to-log-in-to-a-vpn.md)                                                                                                                 |
| [A domain was added to the trusted domains list](/analytics-alerts/alerts-by-name/a-domain-was-added-to-the-trusted-domains-list.md)                                                                                                             |
| [A GCP Cloud SQL DB instance was exported from a production account](/analytics-alerts/alerts-by-name/a-gcp-cloud-sql-db-instance-was-exported-from-a-production-account.md)                                                                     |
| [A GCP service account was delegated domain-wide authority in Google Workspace](/analytics-alerts/alerts-by-name/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspace.md)                                               |
| [A Google Workspace identity created, assigned or modified a role](/analytics-alerts/alerts-by-name/a-google-workspace-identity-created-assigned-or-modified-a-role.md)                                                                          |
| [A Google Workspace identity performed an unusual admin console activity](/analytics-alerts/alerts-by-name/a-google-workspace-identity-performed-an-unusual-admin-console-activity.md)                                                           |
| [A Google Workspace identity used the security investigation tool](/analytics-alerts/alerts-by-name/a-google-workspace-identity-used-the-security-investigation-tool.md)                                                                         |
| [A Google Workspace Role privilege was deleted](/analytics-alerts/alerts-by-name/a-google-workspace-role-privilege-was-deleted.md)                                                                                                               |
| [A Google Workspace service was configured as unrestricted](/analytics-alerts/alerts-by-name/a-google-workspace-service-was-configured-as-unrestricted.md)                                                                                       |
| [A Google Workspace user was added to a group](/analytics-alerts/alerts-by-name/a-google-workspace-user-was-added-to-a-group.md)                                                                                                                 |
| [A Google Workspace user was removed from a group](/analytics-alerts/alerts-by-name/a-google-workspace-user-was-removed-from-a-group.md)                                                                                                         |
| [A Kubernetes API operation was successfully invoked by an anonymous user](/analytics-alerts/alerts-by-name/a-kubernetes-api-operation-was-successfully-invoked-by-an-anonymous-user.md)                                                         |
| [A Kubernetes cluster role binding was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-cluster-role-binding-was-created-or-deleted.md)                                                                                         |
| [A Kubernetes cluster role was created](/analytics-alerts/alerts-by-name/a-kubernetes-cluster-role-was-created.md)                                                                                                                               |
| [A Kubernetes cluster was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-cluster-was-created-or-deleted.md)                                                                                                                   |
| [A Kubernetes ConfigMap was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-configmap-was-created-or-deleted.md)                                                                                                               |
| [A Kubernetes Cronjob was created](/analytics-alerts/alerts-by-name/a-kubernetes-cronjob-was-created.md)                                                                                                                                         |
| [A Kubernetes DaemonSet was created](/analytics-alerts/alerts-by-name/a-kubernetes-daemonset-was-created.md)                                                                                                                                     |
| [A Kubernetes dashboard service account was used outside the cluster](/analytics-alerts/alerts-by-name/a-kubernetes-dashboard-service-account-was-used-outside-the-cluster.md)                                                                   |
| [A Kubernetes deployment was created](/analytics-alerts/alerts-by-name/a-kubernetes-deployment-was-created.md)                                                                                                                                   |
| [A Kubernetes ephemeral container was created](/analytics-alerts/alerts-by-name/a-kubernetes-ephemeral-container-was-created.md)                                                                                                                 |
| [A Kubernetes namespace was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-namespace-was-created-or-deleted.md)                                                                                                               |
| [A Kubernetes node service account activity from external IP](/analytics-alerts/alerts-by-name/a-kubernetes-node-service-account-activity-from-external-ip.md)                                                                                   |
| [A Kubernetes Pod was created with a sidecar container](/analytics-alerts/alerts-by-name/a-kubernetes-pod-was-created-with-a-sidecar-container.md)                                                                                               |
| [A Kubernetes Pod was deleted](/analytics-alerts/alerts-by-name/a-kubernetes-pod-was-deleted.md)                                                                                                                                                 |
| [A Kubernetes ReplicaSet was created](/analytics-alerts/alerts-by-name/a-kubernetes-replicaset-was-created.md)                                                                                                                                   |
| [A Kubernetes role binding was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-role-binding-was-created-or-deleted.md)                                                                                                         |
| [A Kubernetes secret was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-secret-was-created-or-deleted.md)                                                                                                                     |
| [A Kubernetes service account executed an unusual API call](/analytics-alerts/alerts-by-name/a-kubernetes-service-account-executed-an-unusual-api-call.md)                                                                                       |
| [A Kubernetes service account has enumerated its permissions](/analytics-alerts/alerts-by-name/a-kubernetes-service-account-has-enumerated-its-permissions.md)                                                                                   |
| [A Kubernetes service account was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-service-account-was-created-or-deleted.md)                                                                                                   |
| [A Kubernetes service was created or deleted](/analytics-alerts/alerts-by-name/a-kubernetes-service-was-created-or-deleted.md)                                                                                                                   |
| [A Kubernetes StatefulSet was created](/analytics-alerts/alerts-by-name/a-kubernetes-statefulset-was-created.md)                                                                                                                                 |
| [A LOLBIN was copied to a different location](/analytics-alerts/alerts-by-name/a-lolbin-was-copied-to-a-different-location.md)                                                                                                                   |
| [A machine certificate was issued with a mismatch](/analytics-alerts/alerts-by-name/a-machine-certificate-was-issued-with-a-mismatch.md)                                                                                                         |
| [A mail forwarding rule was configured in Google Workspace](/analytics-alerts/alerts-by-name/a-mail-forwarding-rule-was-configured-in-google-workspace.md)                                                                                       |
| [A Microsoft Teams application was installed](/analytics-alerts/alerts-by-name/a-microsoft-teams-application-was-installed.md)                                                                                                                   |
| [A Microsoft Teams bot was added to a team](/analytics-alerts/alerts-by-name/a-microsoft-teams-bot-was-added-to-a-team.md)                                                                                                                       |
| [A new Azure email domain verification was requested](/analytics-alerts/alerts-by-name/a-new-azure-email-domain-verification-was-requested.md)                                                                                                   |
| [A new machine attempted Kerberos delegation](/analytics-alerts/alerts-by-name/a-new-machine-attempted-kerberos-delegation.md)                                                                                                                   |
| [A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment](/analytics-alerts/alerts-by-name/a-new-server-was-added-to-an-azure-active-directory-hybrid-health-adfs-environment.md)                                     |
| [A non-browser process accessed a website UI](/analytics-alerts/alerts-by-name/a-non-browser-process-accessed-a-website-ui.md)                                                                                                                   |
| [A Possible crypto miner was detected on a host](/analytics-alerts/alerts-by-name/a-possible-crypto-miner-was-detected-on-a-host.md)                                                                                                             |
| [A possible risky login to Azure](/analytics-alerts/alerts-by-name/a-possible-risky-login-to-azure.md)                                                                                                                                           |
| [A process connected to a rare cloud resource](/analytics-alerts/alerts-by-name/a-process-connected-to-a-rare-cloud-resource.md)                                                                                                                 |
| [A process connected to a rare external host](/analytics-alerts/alerts-by-name/a-process-connected-to-a-rare-external-host.md)                                                                                                                   |
| [A process connected to rare external host](/analytics-alerts/alerts-by-name/a-process-connected-to-rare-external-host.md)                                                                                                                       |
| [A process is masquerading as a common Microsoft product](/analytics-alerts/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product.md)                                                                                           |
| [A process modified an SSH authorized\_keys file](/analytics-alerts/alerts-by-name/a-process-modified-an-ssh-authorized-keys-file.md)                                                                                                            |
| [A process queried the ADFS database decryption key via LDAP](/analytics-alerts/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap.md)                                                                                   |
| [A process was executed with a command line obfuscated by Unicode character substitution](/analytics-alerts/alerts-by-name/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitution.md)                           |
| [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](/analytics-alerts/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process.md)                                             |
| [A rare file path was added to the AppInit\_DLLs registry value](/analytics-alerts/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value.md)                                                                              |
| [A rare FTP user has been detected on an existing FTP server](/analytics-alerts/alerts-by-name/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-server.md)                                                                                   |
| [A rare local administrator login](/analytics-alerts/alerts-by-name/a-rare-local-administrator-login.md)                                                                                                                                         |
| [A remote service was created via RPC over SMB](/analytics-alerts/alerts-by-name/a-remote-service-was-created-via-rpc-over-smb.md)                                                                                                               |
| [A Service Principal was created in Azure](/analytics-alerts/alerts-by-name/a-service-principal-was-created-in-azure.md)                                                                                                                         |
| [A Service Principal was removed from Azure](/analytics-alerts/alerts-by-name/a-service-principal-was-removed-from-azure.md)                                                                                                                     |
| [A service was disabled](/analytics-alerts/alerts-by-name/a-service-was-disabled.md)                                                                                                                                                             |
| [A Successful login from TOR](/analytics-alerts/alerts-by-name/a-successful-login-from-tor.md)                                                                                                                                                   |
| [A successful SSO sign-in from TOR](/analytics-alerts/alerts-by-name/a-successful-sso-sign-in-from-tor.md)                                                                                                                                       |
| [A Successful VPN connection from TOR](/analytics-alerts/alerts-by-name/a-successful-vpn-connection-from-tor.md)                                                                                                                                 |
| [A suspicious direct syscall was executed](/analytics-alerts/alerts-by-name/a-suspicious-direct-syscall-was-executed.md)                                                                                                                         |
| [A suspicious executable with multiple file extensions was created](/analytics-alerts/alerts-by-name/a-suspicious-executable-with-multiple-file-extensions-was-created.md)                                                                       |
| [A suspicious process enrolled for a certificate](/analytics-alerts/alerts-by-name/a-suspicious-process-enrolled-for-a-certificate.md)                                                                                                           |
| [A suspicious process queried AD CS objects via LDAP](/analytics-alerts/alerts-by-name/a-suspicious-process-queried-ad-cs-objects-via-ldap.md)                                                                                                   |
| [A TCP stream was created directly in a shell](/analytics-alerts/alerts-by-name/a-tcp-stream-was-created-directly-in-a-shell.md)                                                                                                                 |
| [A third-party application was authorized to access the Google Workspace APIs](/analytics-alerts/alerts-by-name/a-third-party-application-was-authorized-to-access-the-google-workspace-apis.md)                                                 |
| [A third-party application's access to the Google Workspace domain's resources was revoked](/analytics-alerts/alerts-by-name/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revoked.md)                       |
| [A third-party utility was copied to a different location](/analytics-alerts/alerts-by-name/a-third-party-utility-was-copied-to-a-different-location.md)                                                                                         |
| [A Torrent client was detected on a host](/analytics-alerts/alerts-by-name/a-torrent-client-was-detected-on-a-host.md)                                                                                                                           |
| [A user accessed an abnormal number of files on a remote shared folder](/analytics-alerts/alerts-by-name/a-user-accessed-an-abnormal-number-of-files-on-a-remote-shared-folder.md)                                                               |
| [A user accessed an abnormal number of remote shared folders](/analytics-alerts/alerts-by-name/a-user-accessed-an-abnormal-number-of-remote-shared-folders.md)                                                                                   |
| [A user accessed an uncommon AppID](/analytics-alerts/alerts-by-name/a-user-accessed-an-uncommon-appid.md)                                                                                                                                       |
| [A user accessed multiple time-consuming websites](/analytics-alerts/alerts-by-name/a-user-accessed-multiple-time-consuming-websites.md)                                                                                                         |
| [A user accessed multiple unusual resources via SSO](/analytics-alerts/alerts-by-name/a-user-accessed-multiple-unusual-resources-via-sso.md)                                                                                                     |
| [A user accessed Okta's admin application](/analytics-alerts/alerts-by-name/a-user-accessed-okta-s-admin-application.md)                                                                                                                         |
| [A user account was modified to password never expires](/analytics-alerts/alerts-by-name/a-user-account-was-modified-to-password-never-expires.md)                                                                                               |
| [A user added a Windows firewall rule](/analytics-alerts/alerts-by-name/a-user-added-a-windows-firewall-rule.md)                                                                                                                                 |
| [A user attempted to bypass Okta MFA](/analytics-alerts/alerts-by-name/a-user-attempted-to-bypass-okta-mfa.md)                                                                                                                                   |
| [A user authenticated with weak NTLM to multiple hosts](/analytics-alerts/alerts-by-name/a-user-authenticated-with-weak-ntlm-to-multiple-hosts.md)                                                                                               |
| [A user certificate was issued with a mismatch](/analytics-alerts/alerts-by-name/a-user-certificate-was-issued-with-a-mismatch.md)                                                                                                               |
| [A user changed the Windows system time](/analytics-alerts/alerts-by-name/a-user-changed-the-windows-system-time.md)                                                                                                                             |
| [A user connected a new USB storage device to a host](/analytics-alerts/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-a-host.md)                                                                                                   |
| [A user connected a new USB storage device to multiple hosts](/analytics-alerts/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-multiple-hosts.md)                                                                                   |
| [A user connected a USB storage device for the first time](/analytics-alerts/alerts-by-name/a-user-connected-a-usb-storage-device-for-the-first-time.md)                                                                                         |
| [A user connected from a new country](/analytics-alerts/alerts-by-name/a-user-connected-from-a-new-country.md)                                                                                                                                   |
| [A user connected to a VPN from a new country](/analytics-alerts/alerts-by-name/a-user-connected-to-a-vpn-from-a-new-country.md)                                                                                                                 |
| [A user created a pfx file for the first time](/analytics-alerts/alerts-by-name/a-user-created-a-pfx-file-for-the-first-time.md)                                                                                                                 |
| [A user created an abnormal password-protected archive](/analytics-alerts/alerts-by-name/a-user-created-an-abnormal-password-protected-archive.md)                                                                                               |
| [A user enabled a default local account](/analytics-alerts/alerts-by-name/a-user-enabled-a-default-local-account.md)                                                                                                                             |
| [A user established an SMB connection to multiple hosts](/analytics-alerts/alerts-by-name/a-user-established-an-smb-connection-to-multiple-hosts.md)                                                                                             |
| [A user executed multiple LDAP enumeration queries](/analytics-alerts/alerts-by-name/a-user-executed-multiple-ldap-enumeration-queries.md)                                                                                                       |
| [A user logged in at an unusual time via SSO](/analytics-alerts/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-sso.md)                                                                                                                   |
| [A user logged in at an unusual time via VPN](/analytics-alerts/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-vpn.md)                                                                                                                   |
| [A user logged in from an abnormal country or ASN](/analytics-alerts/alerts-by-name/a-user-logged-in-from-an-abnormal-country-or-asn.md)                                                                                                         |
| [A user logged in to the AWS console for the first time](/analytics-alerts/alerts-by-name/a-user-logged-in-to-the-aws-console-for-the-first-time.md)                                                                                             |
| [A user logged on to multiple workstations via Schannel](/analytics-alerts/alerts-by-name/a-user-logged-on-to-multiple-workstations-via-schannel.md)                                                                                             |
| [A user modified an Okta MFA factor](/analytics-alerts/alerts-by-name/a-user-modified-an-okta-mfa-factor.md)                                                                                                                                     |
| [A user modified an Okta network zone](/analytics-alerts/alerts-by-name/a-user-modified-an-okta-network-zone.md)                                                                                                                                 |
| [A user modified an Okta policy rule](/analytics-alerts/alerts-by-name/a-user-modified-an-okta-policy-rule.md)                                                                                                                                   |
| [A user modified the CA audit policy](/analytics-alerts/alerts-by-name/a-user-modified-the-ca-audit-policy.md)                                                                                                                                   |
| [A user observed and reported unusual activity in Okta](/analytics-alerts/alerts-by-name/a-user-observed-and-reported-unusual-activity-in-okta.md)                                                                                               |
| [A user performed suspiciously massive file activity](/analytics-alerts/alerts-by-name/a-user-performed-suspiciously-massive-file-activity.md)                                                                                                   |
| [A user printed an unusual number of files](/analytics-alerts/alerts-by-name/a-user-printed-an-unusual-number-of-files.md)                                                                                                                       |
| [A user queried AD CS objects via LDAP](/analytics-alerts/alerts-by-name/a-user-queried-ad-cs-objects-via-ldap.md)                                                                                                                               |
| [A user received multiple weakly encrypted service tickets](/analytics-alerts/alerts-by-name/a-user-received-multiple-weakly-encrypted-service-tickets.md)                                                                                       |
| [A user rejected an SSO request from an unusual country](/analytics-alerts/alerts-by-name/a-user-rejected-an-sso-request-from-an-unusual-country.md)                                                                                             |
| [A user requested multiple service tickets](/analytics-alerts/alerts-by-name/a-user-requested-multiple-service-tickets.md)                                                                                                                       |
| [A user sent multiple TGT requests to irregular service](/analytics-alerts/alerts-by-name/a-user-sent-multiple-tgt-requests-to-irregular-service.md)                                                                                             |
| [A user took numerous screenshots](/analytics-alerts/alerts-by-name/a-user-took-numerous-screenshots.md)                                                                                                                                         |
| [A user uploaded malware to SharePoint or OneDrive](/analytics-alerts/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive.md)                                                                                                       |
| [A user was added to a Windows security group](/analytics-alerts/alerts-by-name/a-user-was-added-to-a-windows-security-group.md)                                                                                                                 |
| [A WMI subscriber was created](/analytics-alerts/alerts-by-name/a-wmi-subscriber-was-created.md)                                                                                                                                                 |
| [Abnormal Allocation of compute resources in multiple regions](/analytics-alerts/alerts-by-name/abnormal-allocation-of-compute-resources-in-multiple-regions.md)                                                                                 |
| [Abnormal Communication to a Rare Domain](/analytics-alerts/alerts-by-name/abnormal-communication-to-a-rare-domain.md)                                                                                                                           |
| [Abnormal communication with a rare combination of TLS and HTTP User Agent](/analytics-alerts/alerts-by-name/abnormal-communication-with-a-rare-combination-of-tls-and-http-user-agent.md)                                                       |
| [Abnormal connections to a dormant host from a newly seen endpoint](/analytics-alerts/alerts-by-name/abnormal-connections-to-a-dormant-host-from-a-newly-seen-endpoint.md)                                                                       |
| [Abnormal File Activity in SCCMContentLib Shared Folder by user](/analytics-alerts/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user.md)                                                                             |
| [Abnormal ICMP echo (PING) to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-icmp-echo-ping-to-multiple-hosts.md)                                                                                                                     |
| [Abnormal increase in network-related alerts on the same host](/analytics-alerts/alerts-by-name/abnormal-increase-in-network-related-alerts-on-the-same-host.md)                                                                                 |
| [Abnormal network communication through TOR using an uncommon port](/analytics-alerts/alerts-by-name/abnormal-network-communication-through-tor-using-an-uncommon-port.md)                                                                       |
| [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](/analytics-alerts/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server.md)                       |
| [Abnormal process connection to default Meterpreter port](/analytics-alerts/alerts-by-name/abnormal-process-connection-to-default-meterpreter-port.md)                                                                                           |
| [Abnormal RDP connections to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts.md)                                                                                                                     |
| [Abnormal RDP connections to multiple hosts from a rarely seen host](/analytics-alerts/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts-from-a-rarely-seen-host.md)                                                                     |
| [Abnormal RDP session to a remote host from a rarely seen host](/analytics-alerts/alerts-by-name/abnormal-rdp-session-to-a-remote-host-from-a-rarely-seen-host.md)                                                                               |
| [Abnormal Recurring Communications to a Rare Domain](/analytics-alerts/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain.md)                                                                                                     |
| [Abnormal RPC traffic to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-rpc-traffic-to-multiple-hosts.md)                                                                                                                             |
| [Abnormal sensitive RPC traffic to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts.md)                                                                                                         |
| [Abnormal sensitive RPC traffic to multiple hosts from a rarely seen host](/analytics-alerts/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts-from-a-rarely-seen-host.md)                                                         |
| [Abnormal SMB activity to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-smb-activity-to-multiple-hosts.md)                                                                                                                           |
| [Abnormal SMB scanning activity to multiple hosts](/analytics-alerts/alerts-by-name/abnormal-smb-scanning-activity-to-multiple-hosts.md)                                                                                                         |
| [Abnormal User Login to Domain Controller](/analytics-alerts/alerts-by-name/abnormal-user-login-to-domain-controller.md)                                                                                                                         |
| [Access to kubelet credentials file](/analytics-alerts/alerts-by-name/access-to-kubelet-credentials-file.md)                                                                                                                                     |
| [Access to Kubernetes CA certificate file](/analytics-alerts/alerts-by-name/access-to-kubernetes-ca-certificate-file.md)                                                                                                                         |
| [Access to Kubernetes configuration file](/analytics-alerts/alerts-by-name/access-to-kubernetes-configuration-file.md)                                                                                                                           |
| [Access to sensitive host files from within a Kubernetes pod](/analytics-alerts/alerts-by-name/access-to-sensitive-host-files-from-within-a-kubernetes-pod.md)                                                                                   |
| [Account probing](/analytics-alerts/alerts-by-name/account-probing.md)                                                                                                                                                                           |
| [Adding execution privileges](/analytics-alerts/alerts-by-name/adding-execution-privileges.md)                                                                                                                                                   |
| [ADFS DKM Key Access](/analytics-alerts/alerts-by-name/adfs-dkm-key-access.md)                                                                                                                                                                   |
| [Admin privileges were granted to a Google Workspace user](/analytics-alerts/alerts-by-name/admin-privileges-were-granted-to-a-google-workspace-user.md)                                                                                         |
| [Administrator groups enumerated via LDAP](/analytics-alerts/alerts-by-name/administrator-groups-enumerated-via-ldap.md)                                                                                                                         |
| [AI model discovery](/analytics-alerts/alerts-by-name/ai-model-discovery.md)                                                                                                                                                                     |
| [AI safeguards deletion attempt](/analytics-alerts/alerts-by-name/ai-safeguards-deletion-attempt.md)                                                                                                                                             |
| [AI safeguards were modified](/analytics-alerts/alerts-by-name/ai-safeguards-were-modified.md)                                                                                                                                                   |
| [AI-determined combination of risky alerts under the same actor process](/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-actor-process.md)                                                             |
| [AI-determined combination of risky alerts under the same causality](/analytics-alerts/alerts-by-name/ai-determined-combination-of-risky-alerts-under-the-same-causality.md)                                                                     |
| [Allocation of multiple cloud compute resources](/analytics-alerts/alerts-by-name/allocation-of-multiple-cloud-compute-resources.md)                                                                                                             |
| [An app was added to Google Marketplace](/analytics-alerts/alerts-by-name/an-app-was-added-to-google-marketplace.md)                                                                                                                             |
| [An app was added to the Google Workspace trusted OAuth apps list](/analytics-alerts/alerts-by-name/an-app-was-added-to-the-google-workspace-trusted-oauth-apps-list.md)                                                                         |
| [An app was removed from a blocked list in Google Workspace](/analytics-alerts/alerts-by-name/an-app-was-removed-from-a-blocked-list-in-google-workspace.md)                                                                                     |
| [An AWS database service master user password was changed](/analytics-alerts/alerts-by-name/an-aws-database-service-master-user-password-was-changed.md)                                                                                         |
| [An AWS EC2 instance containing sensitive data was exported](/analytics-alerts/alerts-by-name/an-aws-ec2-instance-containing-sensitive-data-was-exported.md)                                                                                     |
| [An AWS EC2 instance was exported from a production account](/analytics-alerts/alerts-by-name/an-aws-ec2-instance-was-exported-from-a-production-account.md)                                                                                     |
| [An AWS EC2 instance was exported into an unknown S3 bucket](/analytics-alerts/alerts-by-name/an-aws-ec2-instance-was-exported-into-an-unknown-s3-bucket.md)                                                                                     |
| [An AWS EFS File-share mount was deleted](/analytics-alerts/alerts-by-name/an-aws-efs-file-share-mount-was-deleted.md)                                                                                                                           |
| [An AWS EFS file-share was deleted](/analytics-alerts/alerts-by-name/an-aws-efs-file-share-was-deleted.md)                                                                                                                                       |
| [An AWS EKS cluster was created or deleted](/analytics-alerts/alerts-by-name/an-aws-eks-cluster-was-created-or-deleted.md)                                                                                                                       |
| [An AWS GuardDuty IP set was created](/analytics-alerts/alerts-by-name/an-aws-guardduty-ip-set-was-created.md)                                                                                                                                   |
| [An AWS Lambda Function was created](/analytics-alerts/alerts-by-name/an-aws-lambda-function-was-created.md)                                                                                                                                     |
| [An AWS Lambda function was modified](/analytics-alerts/alerts-by-name/an-aws-lambda-function-was-modified.md)                                                                                                                                   |
| [An AWS RDS Global Cluster Deletion](/analytics-alerts/alerts-by-name/an-aws-rds-global-cluster-deletion.md)                                                                                                                                     |
| [An AWS RDS instance was created from a snapshot](/analytics-alerts/alerts-by-name/an-aws-rds-instance-was-created-from-a-snapshot.md)                                                                                                           |
| [An AWS Route 53 domain was transferred to another AWS account](/analytics-alerts/alerts-by-name/an-aws-route-53-domain-was-transferred-to-another-aws-account.md)                                                                               |
| [An AWS S3 bucket configuration was modified](/analytics-alerts/alerts-by-name/an-aws-s3-bucket-configuration-was-modified.md)                                                                                                                   |
| [An AWS SAML provider was modified](/analytics-alerts/alerts-by-name/an-aws-saml-provider-was-modified.md)                                                                                                                                       |
| [An AWS SES identity was deleted](/analytics-alerts/alerts-by-name/an-aws-ses-identity-was-deleted.md)                                                                                                                                           |
| [An Azure application reached a throttling API rate](/analytics-alerts/alerts-by-name/an-azure-application-reached-a-throttling-api-rate.md)                                                                                                     |
| [An Azure DNS Zone was modified](/analytics-alerts/alerts-by-name/an-azure-dns-zone-was-modified.md)                                                                                                                                             |
| [An Azure Firewall policy deletion](/analytics-alerts/alerts-by-name/an-azure-firewall-policy-deletion.md)                                                                                                                                       |
| [An Azure Firewall rule collection group was modified or deleted](/analytics-alerts/alerts-by-name/an-azure-firewall-rule-collection-group-was-modified-or-deleted.md)                                                                           |
| [An Azure firewall rule group was modified](/analytics-alerts/alerts-by-name/an-azure-firewall-rule-group-was-modified.md)                                                                                                                       |
| [An Azure Firewall was modified](/analytics-alerts/alerts-by-name/an-azure-firewall-was-modified.md)                                                                                                                                             |
| [An Azure identity performed multiple actions that were denied](/analytics-alerts/alerts-by-name/an-azure-identity-performed-multiple-actions-that-were-denied.md)                                                                               |
| [An Azure Key Vault key was modified](/analytics-alerts/alerts-by-name/an-azure-key-vault-key-was-modified.md)                                                                                                                                   |
| [An Azure Key Vault was modified](/analytics-alerts/alerts-by-name/an-azure-key-vault-was-modified.md)                                                                                                                                           |
| [An Azure Kubernetes Cluster was created or deleted](/analytics-alerts/alerts-by-name/an-azure-kubernetes-cluster-was-created-or-deleted.md)                                                                                                     |
| [An Azure Kubernetes Role or Cluster-Role was modified](/analytics-alerts/alerts-by-name/an-azure-kubernetes-role-or-cluster-role-was-modified.md)                                                                                               |
| [An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted](/analytics-alerts/alerts-by-name/an-azure-kubernetes-role-binding-or-cluster-role-binding-was-modified-or-deleted.md)                                         |
| [An Azure Kubernetes Service Account was modified or deleted](/analytics-alerts/alerts-by-name/an-azure-kubernetes-service-account-was-modified-or-deleted.md)                                                                                   |
| [An Azure Network Security Group was modified](/analytics-alerts/alerts-by-name/an-azure-network-security-group-was-modified.md)                                                                                                                 |
| [An Azure Point-to-Site VPN was modified](/analytics-alerts/alerts-by-name/an-azure-point-to-site-vpn-was-modified.md)                                                                                                                           |
| [An Azure SQL database was exported from a production subscription](/analytics-alerts/alerts-by-name/an-azure-sql-database-was-exported-from-a-production-subscription.md)                                                                       |
| [An Azure Suppression Rule was created](/analytics-alerts/alerts-by-name/an-azure-suppression-rule-was-created.md)                                                                                                                               |
| [An Azure virtual network Device was modified](/analytics-alerts/alerts-by-name/an-azure-virtual-network-device-was-modified.md)                                                                                                                 |
| [An Azure virtual network was modified](/analytics-alerts/alerts-by-name/an-azure-virtual-network-was-modified.md)                                                                                                                               |
| [An Azure VM snapshot SAS URL was generated](/analytics-alerts/alerts-by-name/an-azure-vm-snapshot-sas-url-was-generated.md)                                                                                                                     |
| [An Azure VM snapshot SAS URL was generated for export from a production subscription](/analytics-alerts/alerts-by-name/an-azure-vm-snapshot-sas-url-was-generated-for-export-from-a-production-subscription.md)                                 |
| [An Azure VPN Connection was modified](/analytics-alerts/alerts-by-name/an-azure-vpn-connection-was-modified.md)                                                                                                                                 |
| [An EBS snapshot block was downloaded](/analytics-alerts/alerts-by-name/an-ebs-snapshot-block-was-downloaded.md)                                                                                                                                 |
| [An Email address was added to AWS SES](/analytics-alerts/alerts-by-name/an-email-address-was-added-to-aws-ses.md)                                                                                                                               |
| [An executable was written and executed by a web server](/analytics-alerts/alerts-by-name/an-executable-was-written-and-executed-by-a-web-server.md)                                                                                             |
| [An IAM group was created](/analytics-alerts/alerts-by-name/an-iam-group-was-created.md)                                                                                                                                                         |
| [An identity accessed a backup cloud storage](/analytics-alerts/alerts-by-name/an-identity-accessed-a-backup-cloud-storage.md)                                                                                                                   |
| [An identity accessed a cloud storage for the first time](/analytics-alerts/alerts-by-name/an-identity-accessed-a-cloud-storage-for-the-first-time.md)                                                                                           |
| [An identity accessed Azure Kubernetes Secrets](/analytics-alerts/alerts-by-name/an-identity-accessed-azure-kubernetes-secrets.md)                                                                                                               |
| [An identity attached an administrative policy to an IAM user or role](/analytics-alerts/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role.md)                                                                 |
| [An identity created or updated password for an IAM user](/analytics-alerts/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user.md)                                                                                           |
| [An identity disabled bucket logging](/analytics-alerts/alerts-by-name/an-identity-disabled-bucket-logging.md)                                                                                                                                   |
| [An identity initiated a download of multiple cloud objects](/analytics-alerts/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects.md)                                                                                     |
| [An identity performed a suspicious download of multiple cloud storage objects](/analytics-alerts/alerts-by-name/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objects.md)                                               |
| [An identity started an AWS SSM session](/analytics-alerts/alerts-by-name/an-identity-started-an-aws-ssm-session.md)                                                                                                                             |
| [An identity successfully extracted multiple secrets within the organization](/analytics-alerts/alerts-by-name/an-identity-successfully-extracted-multiple-secrets-within-the-organization.md)                                                   |
| [An identity was granted permissions to manage user access to Azure resources](/analytics-alerts/alerts-by-name/an-identity-was-granted-permissions-to-manage-user-access-to-azure-resources.md)                                                 |
| [An internal Cloud resource performed port scan on external networks](/analytics-alerts/alerts-by-name/an-internal-cloud-resource-performed-port-scan-on-external-networks.md)                                                                   |
| [An operation was performed by an identity from a domain that was not seen in the organization](/analytics-alerts/alerts-by-name/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organization.md)               |
| [An RDS snapshot containing sensitive data was exported](/analytics-alerts/alerts-by-name/an-rds-snapshot-containing-sensitive-data-was-exported.md)                                                                                             |
| [An RDS snapshot was exported from a production account](/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-from-a-production-account.md)                                                                                             |
| [An RDS snapshot was exported to an unknown bucket](/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-bucket.md)                                                                                                       |
| [An RDS snapshot was exported to an unknown S3 bucket](/analytics-alerts/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-s3-bucket.md)                                                                                                 |
| [An S3 replication policy to an unknown bucket was created](/analytics-alerts/alerts-by-name/an-s3-replication-policy-to-an-unknown-bucket-was-created.md)                                                                                       |
| [An uncommon executable was remotely written over SMB to an uncommon destination](/analytics-alerts/alerts-by-name/an-uncommon-executable-was-remotely-written-over-smb-to-an-uncommon-destination.md)                                           |
| [An uncommon file added to startup-related Registry keys](/analytics-alerts/alerts-by-name/an-uncommon-file-added-to-startup-related-registry-keys.md)                                                                                           |
| [An uncommon file was created in the startup folder](/analytics-alerts/alerts-by-name/an-uncommon-file-was-created-in-the-startup-folder.md)                                                                                                     |
| [An uncommon lolbin execution by scheduled task](/analytics-alerts/alerts-by-name/an-uncommon-lolbin-execution-by-scheduled-task.md)                                                                                                             |
| [An uncommon RDP session from a managed host](/analytics-alerts/alerts-by-name/an-uncommon-rdp-session-from-a-managed-host.md)                                                                                                                   |
| [An uncommon RDP session was established](/analytics-alerts/alerts-by-name/an-uncommon-rdp-session-was-established.md)                                                                                                                           |
| [An uncommon service was started](/analytics-alerts/alerts-by-name/an-uncommon-service-was-started.md)                                                                                                                                           |
| [An unknown account was invited to the AWS organization](/analytics-alerts/alerts-by-name/an-unknown-account-was-invited-to-the-aws-organization.md)                                                                                             |
| [An unpopular process accessed the microphone on the host](/analytics-alerts/alerts-by-name/an-unpopular-process-accessed-the-microphone-on-the-host.md)                                                                                         |
| [An unsigned process created scheduled task and performed an injection](/analytics-alerts/alerts-by-name/an-unsigned-process-created-scheduled-task-and-performed-an-injection.md)                                                               |
| [An unusual archive file creation by a user](/analytics-alerts/alerts-by-name/an-unusual-archive-file-creation-by-a-user.md)                                                                                                                     |
| [An unusual cloud identity was granted permissions to a BigQuery resource](/analytics-alerts/alerts-by-name/an-unusual-cloud-identity-was-granted-permissions-to-a-bigquery-resource.md)                                                         |
| [An unusual process in ingress-nginx has accessed a service-account token file](/analytics-alerts/alerts-by-name/an-unusual-process-in-ingress-nginx-has-accessed-a-service-account-token-file.md)                                               |
| [An unusual read activity of cloud object](/analytics-alerts/alerts-by-name/an-unusual-read-activity-of-cloud-object.md)                                                                                                                         |
| [Analytics enhanced - Rare Internal Firewall Vulnerability Threat Alert](/analytics-alerts/alerts-by-name/analytics-enhanced-rare-internal-firewall-vulnerability-threat-alert.md)                                                               |
| [AppleScript executed a shell script](/analytics-alerts/alerts-by-name/applescript-executed-a-shell-script.md)                                                                                                                                   |
| [AppleScript interpreter dynamic library loaded into a process](/analytics-alerts/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process.md)                                                                               |
| [AppleScript process executed with a rare command line](/analytics-alerts/alerts-by-name/applescript-process-executed-with-a-rare-command-line.md)                                                                                               |
| [Attempt to execute a command on a remote host using PsExec.exe](/analytics-alerts/alerts-by-name/attempt-to-execute-a-command-on-a-remote-host-using-psexec-exe.md)                                                                             |
| [Attempted Azure application access from unknown tenant](/analytics-alerts/alerts-by-name/attempted-azure-application-access-from-unknown-tenant.md)                                                                                             |
| [Aurora DB cluster stopped](/analytics-alerts/alerts-by-name/aurora-db-cluster-stopped.md)                                                                                                                                                       |
| [Authentication attempt by a honey user](/analytics-alerts/alerts-by-name/authentication-attempt-by-a-honey-user.md)                                                                                                                             |
| [Authentication Attempt From a Dormant Account](/analytics-alerts/alerts-by-name/authentication-attempt-from-a-dormant-account.md)                                                                                                               |
| [Authentication method added to an Azure account](/analytics-alerts/alerts-by-name/authentication-method-added-to-an-azure-account.md)                                                                                                           |
| [Authentication method was added to Azure account](/analytics-alerts/alerts-by-name/authentication-method-was-added-to-azure-account.md)                                                                                                         |
| [Autorun.inf created in root C drive](/analytics-alerts/alerts-by-name/autorun-inf-created-in-root-c-drive.md)                                                                                                                                   |
| [AWS Backup recovery point deletion](/analytics-alerts/alerts-by-name/aws-backup-recovery-point-deletion.md)                                                                                                                                     |
| [AWS Backup vault was deleted](/analytics-alerts/alerts-by-name/aws-backup-vault-was-deleted.md)                                                                                                                                                 |
| [AWS Bedrock AI infrastructure enumeration activity](/analytics-alerts/alerts-by-name/aws-bedrock-ai-infrastructure-enumeration-activity.md)                                                                                                     |
| [AWS Bedrock model invocation logging deletion](/analytics-alerts/alerts-by-name/aws-bedrock-model-invocation-logging-deletion.md)                                                                                                               |
| [AWS CloudTrail has been stopped](/analytics-alerts/alerts-by-name/aws-cloudtrail-has-been-stopped.md)                                                                                                                                           |
| [AWS CloudTrail modification](/analytics-alerts/alerts-by-name/aws-cloudtrail-modification.md)                                                                                                                                                   |
| [AWS CloudWatch log group deletion](/analytics-alerts/alerts-by-name/aws-cloudwatch-log-group-deletion.md)                                                                                                                                       |
| [AWS CloudWatch log stream deletion](/analytics-alerts/alerts-by-name/aws-cloudwatch-log-stream-deletion.md)                                                                                                                                     |
| [AWS Config Recorder stopped](/analytics-alerts/alerts-by-name/aws-config-recorder-stopped.md)                                                                                                                                                   |
| [AWS config resource deletion](/analytics-alerts/alerts-by-name/aws-config-resource-deletion.md)                                                                                                                                                 |
| [AWS console login without MFA](/analytics-alerts/alerts-by-name/aws-console-login-without-mfa.md)                                                                                                                                               |
| [AWS data asset shared public](/analytics-alerts/alerts-by-name/aws-data-asset-shared-public.md)                                                                                                                                                 |
| [AWS EBS enumeration activity](/analytics-alerts/alerts-by-name/aws-ebs-enumeration-activity.md)                                                                                                                                                 |
| [AWS EBS snapshot deletion](/analytics-alerts/alerts-by-name/aws-ebs-snapshot-deletion.md)                                                                                                                                                       |
| [AWS EC2 infrastructure enumeration activity](/analytics-alerts/alerts-by-name/aws-ec2-infrastructure-enumeration-activity.md)                                                                                                                   |
| [AWS EC2 instance exported into S3](/analytics-alerts/alerts-by-name/aws-ec2-instance-exported-into-s3.md)                                                                                                                                       |
| [AWS Flow Logs deletion](/analytics-alerts/alerts-by-name/aws-flow-logs-deletion.md)                                                                                                                                                             |
| [AWS Guard-Duty detector deletion](/analytics-alerts/alerts-by-name/aws-guard-duty-detector-deletion.md)                                                                                                                                         |
| [AWS IAM resource group deletion](/analytics-alerts/alerts-by-name/aws-iam-resource-group-deletion.md)                                                                                                                                           |
| [AWS IAM Role Created with Cross-Account Access](/analytics-alerts/alerts-by-name/aws-iam-role-created-with-cross-account-access.md)                                                                                                             |
| [AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access](/analytics-alerts/alerts-by-name/aws-iam-role-s-trusted-policy-modification-allows-cross-account-access.md)                                                             |
| [AWS Lambda Cross-Account sensitive permissions configured](/analytics-alerts/alerts-by-name/aws-lambda-cross-account-sensitive-permissions-configured.md)                                                                                       |
| [AWS Lambda infrastructure enumeration activity](/analytics-alerts/alerts-by-name/aws-lambda-infrastructure-enumeration-activity.md)                                                                                                             |
| [AWS network ACL rule creation](/analytics-alerts/alerts-by-name/aws-network-acl-rule-creation.md)                                                                                                                                               |
| [AWS network ACL rule deletion](/analytics-alerts/alerts-by-name/aws-network-acl-rule-deletion.md)                                                                                                                                               |
| [AWS Password Policy Discovery](/analytics-alerts/alerts-by-name/aws-password-policy-discovery.md)                                                                                                                                               |
| [AWS principals discovery](/analytics-alerts/alerts-by-name/aws-principals-discovery.md)                                                                                                                                                         |
| [AWS RDS cluster deletion](/analytics-alerts/alerts-by-name/aws-rds-cluster-deletion.md)                                                                                                                                                         |
| [AWS resource discovery](/analytics-alerts/alerts-by-name/aws-resource-discovery.md)                                                                                                                                                             |
| [AWS root account activity](/analytics-alerts/alerts-by-name/aws-root-account-activity.md)                                                                                                                                                       |
| [AWS S3 bucket data retention policy change through S3 Lifecycle rule](/analytics-alerts/alerts-by-name/aws-s3-bucket-data-retention-policy-change-through-s3-lifecycle-rule.md)                                                                 |
| [AWS S3 bucket was exposed to public access](/analytics-alerts/alerts-by-name/aws-s3-bucket-was-exposed-to-public-access.md)                                                                                                                     |
| [AWS S3 Buckets enumeration activity](/analytics-alerts/alerts-by-name/aws-s3-buckets-enumeration-activity.md)                                                                                                                                   |
| [AWS Secrets Manager discovery](/analytics-alerts/alerts-by-name/aws-secrets-manager-discovery.md)                                                                                                                                               |
| [AWS Security Group remote access allowed from an unknown external IP address](/analytics-alerts/alerts-by-name/aws-security-group-remote-access-allowed-from-an-unknown-external-ip-address.md)                                                 |
| [AWS Security Service Enumeration](/analytics-alerts/alerts-by-name/aws-security-service-enumeration.md)                                                                                                                                         |
| [AWS SecurityHub findings were modified](/analytics-alerts/alerts-by-name/aws-securityhub-findings-were-modified.md)                                                                                                                             |
| [AWS SES account sending settings modified](/analytics-alerts/alerts-by-name/aws-ses-account-sending-settings-modified.md)                                                                                                                       |
| [AWS SSM association created with inventory collection document](/analytics-alerts/alerts-by-name/aws-ssm-association-created-with-inventory-collection-document.md)                                                                             |
| [AWS SSM parameters discovery](/analytics-alerts/alerts-by-name/aws-ssm-parameters-discovery.md)                                                                                                                                                 |
| [AWS SSM parameters retrieval](/analytics-alerts/alerts-by-name/aws-ssm-parameters-retrieval.md)                                                                                                                                                 |
| [AWS SSM send command attempt](/analytics-alerts/alerts-by-name/aws-ssm-send-command-attempt.md)                                                                                                                                                 |
| [AWS Storage Gateway enumeration](/analytics-alerts/alerts-by-name/aws-storage-gateway-enumeration.md)                                                                                                                                           |
| [AWS Storage Gateway file share enumeration](/analytics-alerts/alerts-by-name/aws-storage-gateway-file-share-enumeration.md)                                                                                                                     |
| [AWS STS temporary credentials were generated](/analytics-alerts/alerts-by-name/aws-sts-temporary-credentials-were-generated.md)                                                                                                                 |
| [AWS support case creation](/analytics-alerts/alerts-by-name/aws-support-case-creation.md)                                                                                                                                                       |
| [AWS Systems Manager hosts enumeration](/analytics-alerts/alerts-by-name/aws-systems-manager-hosts-enumeration.md)                                                                                                                               |
| [AWS Transfer Family server created](/analytics-alerts/alerts-by-name/aws-transfer-family-server-created.md)                                                                                                                                     |
| [AWS user creation](/analytics-alerts/alerts-by-name/aws-user-creation.md)                                                                                                                                                                       |
| [AWS web ACL deletion](/analytics-alerts/alerts-by-name/aws-web-acl-deletion.md)                                                                                                                                                                 |
| [Azure account creation by a non-standard account](/analytics-alerts/alerts-by-name/azure-account-creation-by-a-non-standard-account.md)                                                                                                         |
| [Azure account deletion by a non-standard account](/analytics-alerts/alerts-by-name/azure-account-deletion-by-a-non-standard-account.md)                                                                                                         |
| [Azure AD account unlock/password reset attempt](/analytics-alerts/alerts-by-name/azure-ad-account-unlock-password-reset-attempt.md)                                                                                                             |
| [Azure AD PIM alert disabled](/analytics-alerts/alerts-by-name/azure-ad-pim-alert-disabled.md)                                                                                                                                                   |
| [Azure AD PIM elevation request](/analytics-alerts/alerts-by-name/azure-ad-pim-elevation-request.md)                                                                                                                                             |
| [Azure AD PIM role settings change](/analytics-alerts/alerts-by-name/azure-ad-pim-role-settings-change.md)                                                                                                                                       |
| [Azure application consent](/analytics-alerts/alerts-by-name/azure-application-consent.md)                                                                                                                                                       |
| [Azure application credentials added](/analytics-alerts/alerts-by-name/azure-application-credentials-added.md)                                                                                                                                   |
| [Azure application removed](/analytics-alerts/alerts-by-name/azure-application-removed.md)                                                                                                                                                       |
| [Azure application URI modification](/analytics-alerts/alerts-by-name/azure-application-uri-modification.md)                                                                                                                                     |
| [Azure Automation Account Creation](/analytics-alerts/alerts-by-name/azure-automation-account-creation.md)                                                                                                                                       |
| [Azure Automation Runbook Creation/Modification](/analytics-alerts/alerts-by-name/azure-automation-runbook-creation-modification.md)                                                                                                             |
| [Azure Automation Runbook Deletion](/analytics-alerts/alerts-by-name/azure-automation-runbook-deletion.md)                                                                                                                                       |
| [Azure Automation Webhook creation](/analytics-alerts/alerts-by-name/azure-automation-webhook-creation.md)                                                                                                                                       |
| [Azure Blob Container Access Level Modification](/analytics-alerts/alerts-by-name/azure-blob-container-access-level-modification.md)                                                                                                             |
| [Azure conditional access policy creation or modification](/analytics-alerts/alerts-by-name/azure-conditional-access-policy-creation-or-modification.md)                                                                                         |
| [Azure device code authentication flow used](/analytics-alerts/alerts-by-name/azure-device-code-authentication-flow-used.md)                                                                                                                     |
| [Azure diagnostic configuration deletion](/analytics-alerts/alerts-by-name/azure-diagnostic-configuration-deletion.md)                                                                                                                           |
| [Azure domain federation settings modification attempt](/analytics-alerts/alerts-by-name/azure-domain-federation-settings-modification-attempt.md)                                                                                               |
| [Azure enumeration activity using Microsoft Graph API](/analytics-alerts/alerts-by-name/azure-enumeration-activity-using-microsoft-graph-api.md)                                                                                                 |
| [Azure Event Hub Authorization rule creation/modification](/analytics-alerts/alerts-by-name/azure-event-hub-authorization-rule-creation-modification.md)                                                                                         |
| [Azure Event Hub Deletion](/analytics-alerts/alerts-by-name/azure-event-hub-deletion.md)                                                                                                                                                         |
| [Azure group creation/deletion](/analytics-alerts/alerts-by-name/azure-group-creation-deletion.md)                                                                                                                                               |
| [Azure Key Vault modification](/analytics-alerts/alerts-by-name/azure-key-vault-modification.md)                                                                                                                                                 |
| [Azure Key Vault Secrets were modified](/analytics-alerts/alerts-by-name/azure-key-vault-secrets-were-modified.md)                                                                                                                               |
| [Azure Kubernetes events were deleted](/analytics-alerts/alerts-by-name/azure-kubernetes-events-were-deleted.md)                                                                                                                                 |
| [Azure mailbox rule creation](/analytics-alerts/alerts-by-name/azure-mailbox-rule-creation.md)                                                                                                                                                   |
| [Azure Monitor alert rule deleted](/analytics-alerts/alerts-by-name/azure-monitor-alert-rule-deleted.md)                                                                                                                                         |
| [Azure Network Watcher Deletion](/analytics-alerts/alerts-by-name/azure-network-watcher-deletion.md)                                                                                                                                             |
| [Azure permission delegation granted](/analytics-alerts/alerts-by-name/azure-permission-delegation-granted.md)                                                                                                                                   |
| [Azure Privilege Escalation Using an Application](/analytics-alerts/alerts-by-name/azure-privilege-escalation-using-an-application.md)                                                                                                           |
| [Azure Resource Group Deletion](/analytics-alerts/alerts-by-name/azure-resource-group-deletion.md)                                                                                                                                               |
| [Azure route table creation or modification](/analytics-alerts/alerts-by-name/azure-route-table-creation-or-modification.md)                                                                                                                     |
| [Azure service principal assigned app role](/analytics-alerts/alerts-by-name/azure-service-principal-assigned-app-role.md)                                                                                                                       |
| [Azure Service principal/Application creation](/analytics-alerts/alerts-by-name/azure-service-principal-application-creation.md)                                                                                                                 |
| [Azure storage account blob anonymous access is enabled](/analytics-alerts/alerts-by-name/azure-storage-account-blob-anonymous-access-is-enabled.md)                                                                                             |
| [Azure storage account cross-tenant object replication was enabled](/analytics-alerts/alerts-by-name/azure-storage-account-cross-tenant-object-replication-was-enabled.md)                                                                       |
| [Azure Storage Account key generated](/analytics-alerts/alerts-by-name/azure-storage-account-key-generated.md)                                                                                                                                   |
| [Azure storage account was publicly shared](/analytics-alerts/alerts-by-name/azure-storage-account-was-publicly-shared.md)                                                                                                                       |
| [Azure Temporary Access Pass (TAP) registered to an account](/analytics-alerts/alerts-by-name/azure-temporary-access-pass-tap-registered-to-an-account.md)                                                                                       |
| [Azure user creation/deletion](/analytics-alerts/alerts-by-name/azure-user-creation-deletion.md)                                                                                                                                                 |
| [Azure user password reset](/analytics-alerts/alerts-by-name/azure-user-password-reset.md)                                                                                                                                                       |
| [Azure virtual machine commands execution](/analytics-alerts/alerts-by-name/azure-virtual-machine-commands-execution.md)                                                                                                                         |
| [Azure VM extension abuse attempt](/analytics-alerts/alerts-by-name/azure-vm-extension-abuse-attempt.md)                                                                                                                                         |
| [Bedrock model shared with a foreign account](/analytics-alerts/alerts-by-name/bedrock-model-shared-with-a-foreign-account.md)                                                                                                                   |
| [BigQuery table or query results exfiltrated to a foreign project](/analytics-alerts/alerts-by-name/bigquery-table-or-query-results-exfiltrated-to-a-foreign-project.md)                                                                         |
| [Billing admin role was removed](/analytics-alerts/alerts-by-name/billing-admin-role-was-removed.md)                                                                                                                                             |
| [BitLocker key retrieval](/analytics-alerts/alerts-by-name/bitlocker-key-retrieval.md)                                                                                                                                                           |
| [Bitsadmin.exe persistence using command-line callback](/analytics-alerts/alerts-by-name/bitsadmin-exe-persistence-using-command-line-callback.md)                                                                                               |
| [Broker Collection Error](/analytics-alerts/alerts-by-name/broker-collection-error.md)                                                                                                                                                           |
| [Bronze-Bit exploit](/analytics-alerts/alerts-by-name/bronze-bit-exploit.md)                                                                                                                                                                     |
| [Browser bookmark files accessed by a rare non-browser process](/analytics-alerts/alerts-by-name/browser-bookmark-files-accessed-by-a-rare-non-browser-process.md)                                                                               |
| [Browser Extension Installed](/analytics-alerts/alerts-by-name/browser-extension-installed.md)                                                                                                                                                   |
| [Brute-force attempt on a local account](/analytics-alerts/alerts-by-name/brute-force-attempt-on-a-local-account.md)                                                                                                                             |
| [Bucket's block public access setting turned off](/analytics-alerts/alerts-by-name/bucket-s-block-public-access-setting-turned-off.md)                                                                                                           |
| [Bucket's object ownership controls were modified](/analytics-alerts/alerts-by-name/bucket-s-object-ownership-controls-were-modified.md)                                                                                                         |
| [Cached credentials discovery with cmdkey](/analytics-alerts/alerts-by-name/cached-credentials-discovery-with-cmdkey.md)                                                                                                                         |
| [Certutil pfx parsing](/analytics-alerts/alerts-by-name/certutil-pfx-parsing.md)                                                                                                                                                                 |
| [Change of sudo caching configuration](/analytics-alerts/alerts-by-name/change-of-sudo-caching-configuration.md)                                                                                                                                 |
| [Chrome Extension Installed By User](/analytics-alerts/alerts-by-name/chrome-extension-installed-by-user.md)                                                                                                                                     |
| [Chrome OS Remote Access policy was modified in Google Workspace](/analytics-alerts/alerts-by-name/chrome-os-remote-access-policy-was-modified-in-google-workspace.md)                                                                           |
| [ClickFix - PowerShell executed through the run application](/analytics-alerts/alerts-by-name/clickfix-powershell-executed-through-the-run-application.md)                                                                                       |
| [Cloud access key creation](/analytics-alerts/alerts-by-name/cloud-access-key-creation.md)                                                                                                                                                       |
| [Cloud activity from a high-risk IP address](/analytics-alerts/alerts-by-name/cloud-activity-from-a-high-risk-ip-address.md)                                                                                                                     |
| [Cloud AI agent was modified](/analytics-alerts/alerts-by-name/cloud-ai-agent-was-modified.md)                                                                                                                                                   |
| [Cloud compute instance user data script modification](/analytics-alerts/alerts-by-name/cloud-compute-instance-user-data-script-modification.md)                                                                                                 |
| [Cloud compute serial console access](/analytics-alerts/alerts-by-name/cloud-compute-serial-console-access.md)                                                                                                                                   |
| [Cloud compute volume creation attempt](/analytics-alerts/alerts-by-name/cloud-compute-volume-creation-attempt.md)                                                                                                                               |
| [Cloud email infrastructure enumeration activity](/analytics-alerts/alerts-by-name/cloud-email-infrastructure-enumeration-activity.md)                                                                                                           |
| [Cloud email sending was enabled](/analytics-alerts/alerts-by-name/cloud-email-sending-was-enabled.md)                                                                                                                                           |
| [Cloud email service activity](/analytics-alerts/alerts-by-name/cloud-email-service-activity.md)                                                                                                                                                 |
| [Cloud identity reached a throttling API rate](/analytics-alerts/alerts-by-name/cloud-identity-reached-a-throttling-api-rate.md)                                                                                                                 |
| [Cloud IMDS access followed by remote token usage](/analytics-alerts/alerts-by-name/cloud-imds-access-followed-by-remote-token-usage.md)                                                                                                         |
| [Cloud impersonation attempt by unusual identity type](/analytics-alerts/alerts-by-name/cloud-impersonation-attempt-by-unusual-identity-type.md)                                                                                                 |
| [Cloud infrastructure discovery across multiple regions](/analytics-alerts/alerts-by-name/cloud-infrastructure-discovery-across-multiple-regions.md)                                                                                             |
| [Cloud infrastructure enumeration activity](/analytics-alerts/alerts-by-name/cloud-infrastructure-enumeration-activity.md)                                                                                                                       |
| [Cloud instance creation attempt](/analytics-alerts/alerts-by-name/cloud-instance-creation-attempt.md)                                                                                                                                           |
| [Cloud instance deletion attempt](/analytics-alerts/alerts-by-name/cloud-instance-deletion-attempt.md)                                                                                                                                           |
| [Cloud Organizational policy was created or modified](/analytics-alerts/alerts-by-name/cloud-organizational-policy-was-created-or-modified.md)                                                                                                   |
| [Cloud penetration testing tool activity](/analytics-alerts/alerts-by-name/cloud-penetration-testing-tool-activity.md)                                                                                                                           |
| [Cloud resource logging was disabled](/analytics-alerts/alerts-by-name/cloud-resource-logging-was-disabled.md)                                                                                                                                   |
| [Cloud snapshot created or modified](/analytics-alerts/alerts-by-name/cloud-snapshot-created-or-modified.md)                                                                                                                                     |
| [Cloud snapshot of a database or storage instance was publicly shared](/analytics-alerts/alerts-by-name/cloud-snapshot-of-a-database-or-storage-instance-was-publicly-shared.md)                                                                 |
| [Cloud storage automatic backup disabled](/analytics-alerts/alerts-by-name/cloud-storage-automatic-backup-disabled.md)                                                                                                                           |
| [Cloud storage delete protection disabled](/analytics-alerts/alerts-by-name/cloud-storage-delete-protection-disabled.md)                                                                                                                         |
| [Cloud user performed multiple actions that were denied](/analytics-alerts/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied.md)                                                                                             |
| [Cloud Watch alarm deletion](/analytics-alerts/alerts-by-name/cloud-watch-alarm-deletion.md)                                                                                                                                                     |
| [CloudTrail logging deletion](/analytics-alerts/alerts-by-name/cloudtrail-logging-deletion.md)                                                                                                                                                   |
| [Collection error](/analytics-alerts/alerts-by-name/collection-error.md)                                                                                                                                                                         |
| [Command execution in a Kubernetes pod](/analytics-alerts/alerts-by-name/command-execution-in-a-kubernetes-pod.md)                                                                                                                               |
| [Command execution via AWS SSM](/analytics-alerts/alerts-by-name/command-execution-via-aws-ssm.md)                                                                                                                                               |
| [Command execution via wmiexec](/analytics-alerts/alerts-by-name/command-execution-via-wmiexec.md)                                                                                                                                               |
| [Command running with COMSPEC in the command line argument](/analytics-alerts/alerts-by-name/command-running-with-comspec-in-the-command-line-argument.md)                                                                                       |
| [Common third-party software name masquerading](/analytics-alerts/alerts-by-name/common-third-party-software-name-masquerading.md)                                                                                                               |
| [Commonly abused AutoIT script connects to an external domain](/analytics-alerts/alerts-by-name/commonly-abused-autoit-script-connects-to-an-external-domain.md)                                                                                 |
| [Commonly abused AutoIT script drops an executable file to disk](/analytics-alerts/alerts-by-name/commonly-abused-autoit-script-drops-an-executable-file-to-disk.md)                                                                             |
| [Commonly abused process launched as a system service](/analytics-alerts/alerts-by-name/commonly-abused-process-launched-as-a-system-service.md)                                                                                                 |
| [Compressing data using python](/analytics-alerts/alerts-by-name/compressing-data-using-python.md)                                                                                                                                               |
| [Compute activity in dormant cloud region](/analytics-alerts/alerts-by-name/compute-activity-in-dormant-cloud-region.md)                                                                                                                         |
| [Conditional Access policy removed](/analytics-alerts/alerts-by-name/conditional-access-policy-removed.md)                                                                                                                                       |
| [Conhost.exe spawned a suspicious cmd process](/analytics-alerts/alerts-by-name/conhost-exe-spawned-a-suspicious-cmd-process.md)                                                                                                                 |
| [Contained process execution with a rare GitHub URL](/analytics-alerts/alerts-by-name/contained-process-execution-with-a-rare-github-url.md)                                                                                                     |
| [Copy a process memory file](/analytics-alerts/alerts-by-name/copy-a-process-memory-file.md)                                                                                                                                                     |
| [Copy a user's GnuPG directory with rsync](/analytics-alerts/alerts-by-name/copy-a-user-s-gnupg-directory-with-rsync.md)                                                                                                                         |
| [Correlation rule error](/analytics-alerts/alerts-by-name/correlation-rule-error.md)                                                                                                                                                             |
| [Creation or modification of the default command executed when opening an application](/analytics-alerts/alerts-by-name/creation-or-modification-of-the-default-command-executed-when-opening-an-application.md)                                 |
| [Credentials were added to Azure application](/analytics-alerts/alerts-by-name/credentials-were-added-to-azure-application.md)                                                                                                                   |
| [Data encryption was disabled](/analytics-alerts/alerts-by-name/data-encryption-was-disabled.md)                                                                                                                                                 |
| [Data exfiltration from cloud database](/analytics-alerts/alerts-by-name/data-exfiltration-from-cloud-database.md)                                                                                                                               |
| [Data Sharing between GCP and Google Workspace was disabled](/analytics-alerts/alerts-by-name/data-sharing-between-gcp-and-google-workspace-was-disabled.md)                                                                                     |
| [Delayed Deletion of Files](/analytics-alerts/alerts-by-name/delayed-deletion-of-files.md)                                                                                                                                                       |
| [Deletion of AD CS certificate database entries](/analytics-alerts/alerts-by-name/deletion-of-ad-cs-certificate-database-entries.md)                                                                                                             |
| [Deletion of multiple cloud resources](/analytics-alerts/alerts-by-name/deletion-of-multiple-cloud-resources.md)                                                                                                                                 |
| [Denied API call by a Kubernetes service account](/analytics-alerts/alerts-by-name/denied-api-call-by-a-kubernetes-service-account.md)                                                                                                           |
| [Device Registration Policy modification](/analytics-alerts/alerts-by-name/device-registration-policy-modification.md)                                                                                                                           |
| [Disable AWS audit logs through Event Selectors](/analytics-alerts/alerts-by-name/disable-aws-audit-logs-through-event-selectors.md)                                                                                                             |
| [Disable encryption operations](/analytics-alerts/alerts-by-name/disable-encryption-operations.md)                                                                                                                                               |
| [Disable Microsoft Defender Antivirus via registry](/analytics-alerts/alerts-by-name/disable-microsoft-defender-antivirus-via-registry.md)                                                                                                       |
| [Discovery of accounts with pre-authentication disabled via LDAP](/analytics-alerts/alerts-by-name/discovery-of-accounts-with-pre-authentication-disabled-via-ldap.md)                                                                           |
| [Discovery of host users via WMIC](/analytics-alerts/alerts-by-name/discovery-of-host-users-via-wmic.md)                                                                                                                                         |
| [Discovery of misconfigured certificate templates using LDAP](/analytics-alerts/alerts-by-name/discovery-of-misconfigured-certificate-templates-using-ldap.md)                                                                                   |
| [Display text URL differs from actual URL](/analytics-alerts/alerts-by-name/display-text-url-differs-from-actual-url.md)                                                                                                                         |
| [DLP sensitive data exposed to external users](/analytics-alerts/alerts-by-name/dlp-sensitive-data-exposed-to-external-users.md)                                                                                                                 |
| [DNS Tunneling](/analytics-alerts/alerts-by-name/dns-tunneling.md)                                                                                                                                                                               |
| [Download a script using the python requests module](/analytics-alerts/alerts-by-name/download-a-script-using-the-python-requests-module.md)                                                                                                     |
| [Download pattern that resembles Peer to Peer traffic](/analytics-alerts/alerts-by-name/download-pattern-that-resembles-peer-to-peer-traffic.md)                                                                                                 |
| [DSC (Desired State Configuration) lateral movement using PowerShell](/analytics-alerts/alerts-by-name/dsc-desired-state-configuration-lateral-movement-using-powershell.md)                                                                     |
| [EBS snapshots were created from an EC2 instance](/analytics-alerts/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance.md)                                                                                                           |
| [EBS volume attachment attempt](/analytics-alerts/alerts-by-name/ebs-volume-attachment-attempt.md)                                                                                                                                               |
| [EBS volume detachment attempt](/analytics-alerts/alerts-by-name/ebs-volume-detachment-attempt.md)                                                                                                                                               |
| [EC2 backdoor created with newly added external SSH or RDP access](/analytics-alerts/alerts-by-name/ec2-backdoor-created-with-newly-added-external-ssh-or-rdp-access.md)                                                                         |
| [EC2 instance Amazon machine image was created](/analytics-alerts/alerts-by-name/ec2-instance-amazon-machine-image-was-created.md)                                                                                                               |
| [Elevation to SYSTEM via services](/analytics-alerts/alerts-by-name/elevation-to-system-via-services.md)                                                                                                                                         |
| [Email attachment with a potentially malicious file extension](/analytics-alerts/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension.md)                                                                                 |
| [Email attachment with multiple extensions](/analytics-alerts/alerts-by-name/email-attachment-with-multiple-extensions.md)                                                                                                                       |
| [Email attachment with Right-to-Left Override Unicode character](/analytics-alerts/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character.md)                                                                             |
| [Email attachment(s) with potentially malicious MIME type](/analytics-alerts/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type.md)                                                                                          |
| [Email containing a link with an IP address convention was detected](/analytics-alerts/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected.md)                                                                     |
| [Email containing a redirected link](/analytics-alerts/alerts-by-name/email-containing-a-redirected-link.md)                                                                                                                                     |
| [Email contains URL delivering high-risk file type](/analytics-alerts/alerts-by-name/email-contains-url-delivering-high-risk-file-type.md)                                                                                                       |
| [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](/analytics-alerts/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values.md)                 |
| [Email mimics replies or forwards without an actual ongoing conversation](/analytics-alerts/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation.md)                                                           |
| [Email sent using an automated system or script detected](/analytics-alerts/alerts-by-name/email-sent-using-an-automated-system-or-script-detected.md)                                                                                           |
| [Email was received from an unknown address using a public provider domain](/analytics-alerts/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain.md)                                                       |
| [Email was received from an unknown sender using a disposable domain](/analytics-alerts/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain.md)                                                                   |
| [Email with file-sharing link containing auto-download parameter](/analytics-alerts/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter.md)                                                                           |
| [Email with URL shortener detected](/analytics-alerts/alerts-by-name/email-with-url-shortener-detected.md)                                                                                                                                       |
| [Encoded information using Windows certificate management tool](/analytics-alerts/alerts-by-name/encoded-information-using-windows-certificate-management-tool.md)                                                                               |
| [Error in event forwarding](/analytics-alerts/alerts-by-name/error-in-event-forwarding.md)                                                                                                                                                       |
| [Excessive user account lockouts](/analytics-alerts/alerts-by-name/excessive-user-account-lockouts.md)                                                                                                                                           |
| [Exchange anti-phish policy disabled or removed](/analytics-alerts/alerts-by-name/exchange-anti-phish-policy-disabled-or-removed.md)                                                                                                             |
| [Exchange audit log disabled](/analytics-alerts/alerts-by-name/exchange-audit-log-disabled.md)                                                                                                                                                   |
| [Exchange compliance search created](/analytics-alerts/alerts-by-name/exchange-compliance-search-created.md)                                                                                                                                     |
| [Exchange DKIM signing configuration disabled](/analytics-alerts/alerts-by-name/exchange-dkim-signing-configuration-disabled.md)                                                                                                                 |
| [Exchange email-hiding inbox rule](/analytics-alerts/alerts-by-name/exchange-email-hiding-inbox-rule.md)                                                                                                                                         |
| [Exchange email-hiding transport rule](/analytics-alerts/alerts-by-name/exchange-email-hiding-transport-rule.md)                                                                                                                                 |
| [Exchange inbox forwarding rule configured](/analytics-alerts/alerts-by-name/exchange-inbox-forwarding-rule-configured.md)                                                                                                                       |
| [Exchange mailbox audit bypass](/analytics-alerts/alerts-by-name/exchange-mailbox-audit-bypass.md)                                                                                                                                               |
| [Exchange mailbox delegation permissions added](/analytics-alerts/alerts-by-name/exchange-mailbox-delegation-permissions-added.md)                                                                                                               |
| [Exchange mailbox folder permission modification](/analytics-alerts/alerts-by-name/exchange-mailbox-folder-permission-modification.md)                                                                                                           |
| [Exchange malware filter policy removed](/analytics-alerts/alerts-by-name/exchange-malware-filter-policy-removed.md)                                                                                                                             |
| [Exchange Safe Attachment policy disabled or removed](/analytics-alerts/alerts-by-name/exchange-safe-attachment-policy-disabled-or-removed.md)                                                                                                   |
| [Exchange Safe Link policy disabled or removed](/analytics-alerts/alerts-by-name/exchange-safe-link-policy-disabled-or-removed.md)                                                                                                               |
| [Exchange transport forwarding rule configured](/analytics-alerts/alerts-by-name/exchange-transport-forwarding-rule-configured.md)                                                                                                               |
| [Exchange user mailbox forwarding](/analytics-alerts/alerts-by-name/exchange-user-mailbox-forwarding.md)                                                                                                                                         |
| [Executable created to disk by lsass.exe](/analytics-alerts/alerts-by-name/executable-created-to-disk-by-lsass-exe.md)                                                                                                                           |
| [Executable moved to Windows system folder](/analytics-alerts/alerts-by-name/executable-moved-to-windows-system-folder.md)                                                                                                                       |
| [Executable or Script file written by a web server process](/analytics-alerts/alerts-by-name/executable-or-script-file-written-by-a-web-server-process.md)                                                                                       |
| [Execution of an uncommon process at an early startup stage](/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage.md)                                                                                     |
| [Execution of an uncommon process at an early startup stage by Windows system binary](/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary.md)                                   |
| [Execution of an uncommon process with a local/domain user SID at an early startup stage](/analytics-alerts/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage.md)                           |
| Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary                                                                                                                                 |
| [Execution of command from within a Kubernetes pod using kubelet credentials](/analytics-alerts/alerts-by-name/execution-of-command-from-within-a-kubernetes-pod-using-kubelet-credentials.md)                                                   |
| [Execution of dllhost.exe with an empty command line](/analytics-alerts/alerts-by-name/execution-of-dllhost-exe-with-an-empty-command-line.md)                                                                                                   |
| [Execution of masqueraded third-party utility](/analytics-alerts/alerts-by-name/execution-of-masqueraded-third-party-utility.md)                                                                                                                 |
| [Execution of renamed lolbin](/analytics-alerts/alerts-by-name/execution-of-renamed-lolbin.md)                                                                                                                                                   |
| [External email display name impersonation of internal personnel](/analytics-alerts/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel.md)                                                                           |
| [External email with a single internal recipient hidden in BCC](/analytics-alerts/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc.md)                                                                               |
| [External Login Password Spray](/analytics-alerts/alerts-by-name/external-login-password-spray.md)                                                                                                                                               |
| [External SaaS file-sharing activity](/analytics-alerts/alerts-by-name/external-saas-file-sharing-activity.md)                                                                                                                                   |
| [External Sharing was turned on for Google Drive](/analytics-alerts/alerts-by-name/external-sharing-was-turned-on-for-google-drive.md)                                                                                                           |
| [External user added a link to a Microsoft Teams chat](/analytics-alerts/alerts-by-name/external-user-added-a-link-to-a-microsoft-teams-chat.md)                                                                                                 |
| [External user call via Microsoft Teams](/analytics-alerts/alerts-by-name/external-user-call-via-microsoft-teams.md)                                                                                                                             |
| [External user created a Microsoft Teams conversation with suspicious operations](/analytics-alerts/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations.md)                                           |
| [External user invitation to Azure tenant](/analytics-alerts/alerts-by-name/external-user-invitation-to-azure-tenant.md)                                                                                                                         |
| [External user started a Microsoft Teams conversation](/analytics-alerts/alerts-by-name/external-user-started-a-microsoft-teams-conversation.md)                                                                                                 |
| [Extracting credentials from Unix files](/analytics-alerts/alerts-by-name/extracting-credentials-from-unix-files.md)                                                                                                                             |
| [Failed Connections](/analytics-alerts/alerts-by-name/failed-connections.md)                                                                                                                                                                     |
| [Failed DNS](/analytics-alerts/alerts-by-name/failed-dns.md)                                                                                                                                                                                     |
| [Failed Login For a Long Username With Special Characters](/analytics-alerts/alerts-by-name/failed-login-for-a-long-username-with-special-characters.md)                                                                                         |
| [Failed Login For Locked-Out Account](/analytics-alerts/alerts-by-name/failed-login-for-locked-out-account.md)                                                                                                                                   |
| [File transfer from unusual IP using known tools](/analytics-alerts/alerts-by-name/file-transfer-from-unusual-ip-using-known-tools.md)                                                                                                           |
| [First Azure AD PowerShell operation for a user](/analytics-alerts/alerts-by-name/first-azure-ad-powershell-operation-for-a-user.md)                                                                                                             |
| [First connection from a country in organization](/analytics-alerts/alerts-by-name/first-connection-from-a-country-in-organization.md)                                                                                                           |
| [First SSO access from ASN for user](/analytics-alerts/alerts-by-name/first-sso-access-from-asn-for-user.md)                                                                                                                                     |
| [First SSO access from ASN in organization](/analytics-alerts/alerts-by-name/first-sso-access-from-asn-in-organization.md)                                                                                                                       |
| [First SSO Resource Access in the Organization](/analytics-alerts/alerts-by-name/first-sso-resource-access-in-the-organization.md)                                                                                                               |
| [First VPN access attempt from a country in organization](/analytics-alerts/alerts-by-name/first-vpn-access-attempt-from-a-country-in-organization.md)                                                                                           |
| [First VPN access from ASN for user](/analytics-alerts/alerts-by-name/first-vpn-access-from-asn-for-user.md)                                                                                                                                     |
| [First VPN access from ASN in organization](/analytics-alerts/alerts-by-name/first-vpn-access-from-asn-in-organization.md)                                                                                                                       |
| [First-seen email from mailbox owner to external recipient's address in the last 30 days](/analytics-alerts/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days.md)                           |
| [First-time attachment exchange](/analytics-alerts/alerts-by-name/first-time-attachment-exchange.md)                                                                                                                                             |
| [First-time directory sync of an on-premises domain user to an existing cloud account](/analytics-alerts/alerts-by-name/first-time-directory-sync-of-an-on-premises-domain-user-to-an-existing-cloud-account.md)                                 |
| [Fodhelper.exe UAC bypass](/analytics-alerts/alerts-by-name/fodhelper-exe-uac-bypass.md)                                                                                                                                                         |
| [Foreign account was granted permissions to S3 bucket via resource-based policy](/analytics-alerts/alerts-by-name/foreign-account-was-granted-permissions-to-s3-bucket-via-resource-based-policy.md)                                             |
| [FTP Connection Using an Anonymous Login or Default Credentials](/analytics-alerts/alerts-by-name/ftp-connection-using-an-anonymous-login-or-default-credentials.md)                                                                             |
| [GCP administrative role granted to a cloud identity](/analytics-alerts/alerts-by-name/gcp-administrative-role-granted-to-a-cloud-identity.md)                                                                                                   |
| [GCP data asset shared public](/analytics-alerts/alerts-by-name/gcp-data-asset-shared-public.md)                                                                                                                                                 |
| [GCP Firewall Rule creation](/analytics-alerts/alerts-by-name/gcp-firewall-rule-creation.md)                                                                                                                                                     |
| [GCP Firewall Rule Modification](/analytics-alerts/alerts-by-name/gcp-firewall-rule-modification.md)                                                                                                                                             |
| [GCP IAM deny policy creation](/analytics-alerts/alerts-by-name/gcp-iam-deny-policy-creation.md)                                                                                                                                                 |
| [GCP IAM Role Deletion](/analytics-alerts/alerts-by-name/gcp-iam-role-deletion.md)                                                                                                                                                               |
| [GCP IAM Service Account Key Deletion](/analytics-alerts/alerts-by-name/gcp-iam-service-account-key-deletion.md)                                                                                                                                 |
| [GCP Logging Bucket Deletion](/analytics-alerts/alerts-by-name/gcp-logging-bucket-deletion.md)                                                                                                                                                   |
| [GCP logging sink deletion](/analytics-alerts/alerts-by-name/gcp-logging-sink-deletion.md)                                                                                                                                                       |
| [GCP logging sink modification](/analytics-alerts/alerts-by-name/gcp-logging-sink-modification.md)                                                                                                                                               |
| [GCP Pub/Sub Subscription Deletion](/analytics-alerts/alerts-by-name/gcp-pub-sub-subscription-deletion.md)                                                                                                                                       |
| [GCP Pub/Sub Topic Deletion](/analytics-alerts/alerts-by-name/gcp-pub-sub-topic-deletion.md)                                                                                                                                                     |
| [GCP sensitive Cloud Run role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-cloud-run-role-granted.md)                                                                                                                                 |
| [GCP sensitive compute role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-compute-role-granted.md)                                                                                                                                     |
| [GCP sensitive Deployment Manager role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-deployment-manager-role-granted.md)                                                                                                               |
| [GCP sensitive Functions role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-functions-role-granted.md)                                                                                                                                 |
| [GCP sensitive IAM role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-iam-role-granted.md)                                                                                                                                             |
| [GCP sensitive role granted to group](/analytics-alerts/alerts-by-name/gcp-sensitive-role-granted-to-group.md)                                                                                                                                   |
| [GCP sensitive Secret Manager role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-secret-manager-role-granted.md)                                                                                                                       |
| [GCP sensitive storage role granted](/analytics-alerts/alerts-by-name/gcp-sensitive-storage-role-granted.md)                                                                                                                                     |
| [GCP Service Account creation](/analytics-alerts/alerts-by-name/gcp-service-account-creation.md)                                                                                                                                                 |
| [GCP Service Account Deletion](/analytics-alerts/alerts-by-name/gcp-service-account-deletion.md)                                                                                                                                                 |
| [GCP Service Account Disable](/analytics-alerts/alerts-by-name/gcp-service-account-disable.md)                                                                                                                                                   |
| [GCP service account impersonation attempt](/analytics-alerts/alerts-by-name/gcp-service-account-impersonation-attempt.md)                                                                                                                       |
| [GCP Service Account key creation](/analytics-alerts/alerts-by-name/gcp-service-account-key-creation.md)                                                                                                                                         |
| [GCP set IAM policy activity](/analytics-alerts/alerts-by-name/gcp-set-iam-policy-activity.md)                                                                                                                                                   |
| [GCP Storage Bucket Configuration Modification](/analytics-alerts/alerts-by-name/gcp-storage-bucket-configuration-modification.md)                                                                                                               |
| [GCP Storage Bucket deletion](/analytics-alerts/alerts-by-name/gcp-storage-bucket-deletion.md)                                                                                                                                                   |
| [GCP Storage Bucket Permissions Modification](/analytics-alerts/alerts-by-name/gcp-storage-bucket-permissions-modification.md)                                                                                                                   |
| [GCP Virtual Private Cloud (VPC) Network Deletion](/analytics-alerts/alerts-by-name/gcp-virtual-private-cloud-vpc-network-deletion.md)                                                                                                           |
| [GCP Virtual Private Network Route Creation](/analytics-alerts/alerts-by-name/gcp-virtual-private-network-route-creation.md)                                                                                                                     |
| [GCP Virtual Private Network Route Deletion](/analytics-alerts/alerts-by-name/gcp-virtual-private-network-route-deletion.md)                                                                                                                     |
| [GCP VPC Firewall Rule Deletion](/analytics-alerts/alerts-by-name/gcp-vpc-firewall-rule-deletion.md)                                                                                                                                             |
| [Globally uncommon high entropy module was loaded](/analytics-alerts/alerts-by-name/globally-uncommon-high-entropy-module-was-loaded.md)                                                                                                         |
| [Globally uncommon high entropy process was executed](/analytics-alerts/alerts-by-name/globally-uncommon-high-entropy-process-was-executed.md)                                                                                                   |
| [Globally uncommon image load from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-image-load-from-a-signed-process.md)                                                                                                     |
| [Globally uncommon injection from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-injection-from-a-signed-process.md)                                                                                                       |
| [Globally uncommon IP address by a common process (sha256)](/analytics-alerts/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256.md)                                                                                         |
| [Globally uncommon IP address connection from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-ip-address-connection-from-a-signed-process.md)                                                                               |
| [Globally uncommon process execution from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-process-execution-from-a-signed-process.md)                                                                                       |
| [Globally uncommon root domain from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-from-a-signed-process.md)                                                                                                   |
| [Globally uncommon root-domain port combination by a common process (sha256)](/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-port-combination-by-a-common-process-sha256.md)                                                     |
| [Globally uncommon root-domain port combination from a signed process](/analytics-alerts/alerts-by-name/globally-uncommon-root-domain-port-combination-from-a-signed-process.md)                                                                 |
| [Gmail delegation was turned on for the organization](/analytics-alerts/alerts-by-name/gmail-delegation-was-turned-on-for-the-organization.md)                                                                                                   |
| [Gmail routing settings changed](/analytics-alerts/alerts-by-name/gmail-routing-settings-changed.md)                                                                                                                                             |
| [Google Marketplace restrictions were modified](/analytics-alerts/alerts-by-name/google-marketplace-restrictions-were-modified.md)                                                                                                               |
| [Google Workspace automation was created](/analytics-alerts/alerts-by-name/google-workspace-automation-was-created.md)                                                                                                                           |
| [Google Workspace organizational unit was modified](/analytics-alerts/alerts-by-name/google-workspace-organizational-unit-was-modified.md)                                                                                                       |
| [Google Workspace third-party application's security settings were changed](/analytics-alerts/alerts-by-name/google-workspace-third-party-application-s-security-settings-were-changed.md)                                                       |
| [Google Workspace user authentication information changed](/analytics-alerts/alerts-by-name/google-workspace-user-authentication-information-changed.md)                                                                                         |
| [Granting Access to an Account](/analytics-alerts/alerts-by-name/granting-access-to-an-account.md)                                                                                                                                               |
| [Hidden Attribute was added to a file using attrib.exe](/analytics-alerts/alerts-by-name/hidden-attribute-was-added-to-a-file-using-attrib-exe.md)                                                                                               |
| [HTTP with suspicious characteristics](/analytics-alerts/alerts-by-name/http-with-suspicious-characteristics.md)                                                                                                                                 |
| [Hydra Password Brute-Force Tool Execution](/analytics-alerts/alerts-by-name/hydra-password-brute-force-tool-execution.md)                                                                                                                       |
| [IAM Enumeration sequence](/analytics-alerts/alerts-by-name/iam-enumeration-sequence.md)                                                                                                                                                         |
| [IAM inline policy was added to group](/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-group.md)                                                                                                                                 |
| [IAM inline policy was added to role](/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-role.md)                                                                                                                                   |
| [IAM inline policy was added to user](/analytics-alerts/alerts-by-name/iam-inline-policy-was-added-to-user.md)                                                                                                                                   |
| [IAM instance profile associations were described](/analytics-alerts/alerts-by-name/iam-instance-profile-associations-were-described.md)                                                                                                         |
| [IAM instance profile was associated with EC2 instance](/analytics-alerts/alerts-by-name/iam-instance-profile-was-associated-with-ec2-instance.md)                                                                                               |
| [IAM instance profile was created](/analytics-alerts/alerts-by-name/iam-instance-profile-was-created.md)                                                                                                                                         |
| [IAM instance profile was replaced for EC2 instance](/analytics-alerts/alerts-by-name/iam-instance-profile-was-replaced-for-ec2-instance.md)                                                                                                     |
| [IAM policy default version was changed](/analytics-alerts/alerts-by-name/iam-policy-default-version-was-changed.md)                                                                                                                             |
| [IAM policy version was created](/analytics-alerts/alerts-by-name/iam-policy-version-was-created.md)                                                                                                                                             |
| [IAM policy was attached to group](/analytics-alerts/alerts-by-name/iam-policy-was-attached-to-group.md)                                                                                                                                         |
| [IAM policy was attached to role](/analytics-alerts/alerts-by-name/iam-policy-was-attached-to-role.md)                                                                                                                                           |
| [IAM role trust policy modification](/analytics-alerts/alerts-by-name/iam-role-trust-policy-modification.md)                                                                                                                                     |
| [IAM role was created](/analytics-alerts/alerts-by-name/iam-role-was-created.md)                                                                                                                                                                 |
| [IAM role-attached managed policies were listed](/analytics-alerts/alerts-by-name/iam-role-attached-managed-policies-were-listed.md)                                                                                                             |
| [IAM User added to an IAM group](/analytics-alerts/alerts-by-name/iam-user-added-to-an-iam-group.md)                                                                                                                                             |
| [Identity assigned an Azure AD Administrator Role](/analytics-alerts/alerts-by-name/identity-assigned-an-azure-ad-administrator-role.md)                                                                                                         |
| [Image file execution options (IFEO) registry key set](/analytics-alerts/alerts-by-name/image-file-execution-options-ifeo-registry-key-set.md)                                                                                                   |
| [Impossible travel by a cloud identity](/analytics-alerts/alerts-by-name/impossible-travel-by-a-cloud-identity.md)                                                                                                                               |
| [Impossible traveler - SSO](/analytics-alerts/alerts-by-name/impossible-traveler-sso.md)                                                                                                                                                         |
| [Impossible traveler - VPN](/analytics-alerts/alerts-by-name/impossible-traveler-vpn.md)                                                                                                                                                         |
| [Increase in Job-Related Site Visits](/analytics-alerts/alerts-by-name/increase-in-job-related-site-visits.md)                                                                                                                                   |
| [Indicator blocking](/analytics-alerts/alerts-by-name/indicator-blocking.md)                                                                                                                                                                     |
| [Indirect command execution using the Program Compatibility Assistant](/analytics-alerts/alerts-by-name/indirect-command-execution-using-the-program-compatibility-assistant.md)                                                                 |
| [Initial person-to-person email contact](/analytics-alerts/alerts-by-name/initial-person-to-person-email-contact.md)                                                                                                                             |
| [Injection into rundll32.exe](/analytics-alerts/alerts-by-name/injection-into-rundll32-exe.md)                                                                                                                                                   |
| [Installation of a new System-V service](/analytics-alerts/alerts-by-name/installation-of-a-new-system-v-service.md)                                                                                                                             |
| [Intense SSO failures](/analytics-alerts/alerts-by-name/intense-sso-failures.md)                                                                                                                                                                 |
| [Interactive at.exe privilege escalation method](/analytics-alerts/alerts-by-name/interactive-at-exe-privilege-escalation-method.md)                                                                                                             |
| [Interactive local account enumeration](/analytics-alerts/alerts-by-name/interactive-local-account-enumeration.md)                                                                                                                               |
| [Interactive login by a machine account](/analytics-alerts/alerts-by-name/interactive-login-by-a-machine-account.md)                                                                                                                             |
| [Interactive login by a service account](/analytics-alerts/alerts-by-name/interactive-login-by-a-service-account.md)                                                                                                                             |
| [Interactive login from a shared user account](/analytics-alerts/alerts-by-name/interactive-login-from-a-shared-user-account.md)                                                                                                                 |
| [Internal Login Password Spray](/analytics-alerts/alerts-by-name/internal-login-password-spray.md)                                                                                                                                               |
| [Invalid SAML Detected](/analytics-alerts/alerts-by-name/invalid-saml-detected.md)                                                                                                                                                               |
| [IP Rotation Pattern in SSO Spray](/analytics-alerts/alerts-by-name/ip-rotation-pattern-in-sso-spray.md)                                                                                                                                         |
| [Iptables configuration command was executed](/analytics-alerts/alerts-by-name/iptables-configuration-command-was-executed.md)                                                                                                                   |
| [Kerberos Pre-Auth Failures by Host](/analytics-alerts/alerts-by-name/kerberos-pre-auth-failures-by-host.md)                                                                                                                                     |
| [Kerberos Pre-Auth Failures by User and Host](/analytics-alerts/alerts-by-name/kerberos-pre-auth-failures-by-user-and-host.md)                                                                                                                   |
| [Kerberos Traffic from Non-Standard Process](/analytics-alerts/alerts-by-name/kerberos-traffic-from-non-standard-process.md)                                                                                                                     |
| [Kerberos User Enumeration](/analytics-alerts/alerts-by-name/kerberos-user-enumeration.md)                                                                                                                                                       |
| [Key credential attribute modification](/analytics-alerts/alerts-by-name/key-credential-attribute-modification.md)                                                                                                                               |
| [Keylogging using system commands](/analytics-alerts/alerts-by-name/keylogging-using-system-commands.md)                                                                                                                                         |
| [Known service display name with uncommon image-path](/analytics-alerts/alerts-by-name/known-service-display-name-with-uncommon-image-path.md)                                                                                                   |
| [Known service name with an uncommon image-path](/analytics-alerts/alerts-by-name/known-service-name-with-an-uncommon-image-path.md)                                                                                                             |
| [Kubelet server communication from a pod](/analytics-alerts/alerts-by-name/kubelet-server-communication-from-a-pod.md)                                                                                                                           |
| [Kubernetes admission controller activity](/analytics-alerts/alerts-by-name/kubernetes-admission-controller-activity.md)                                                                                                                         |
| [Kubernetes API server communication from within a pod](/analytics-alerts/alerts-by-name/kubernetes-api-server-communication-from-within-a-pod.md)                                                                                               |
| [Kubernetes cluster events deletion](/analytics-alerts/alerts-by-name/kubernetes-cluster-events-deletion.md)                                                                                                                                     |
| [Kubernetes enumeration activity](/analytics-alerts/alerts-by-name/kubernetes-enumeration-activity.md)                                                                                                                                           |
| [Kubernetes environment enumeration activity](/analytics-alerts/alerts-by-name/kubernetes-environment-enumeration-activity.md)                                                                                                                   |
| [Kubernetes network policy modification](/analytics-alerts/alerts-by-name/kubernetes-network-policy-modification.md)                                                                                                                             |
| [Kubernetes nsenter container escape](/analytics-alerts/alerts-by-name/kubernetes-nsenter-container-escape.md)                                                                                                                                   |
| [Kubernetes Pod Created with host Inter Process Communications (IPC) namespace](/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-host-inter-process-communications-ipc-namespace.md)                                                 |
| [Kubernetes Pod created with host process ID (PID) namespace](/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-host-process-id-pid-namespace.md)                                                                                     |
| [Kubernetes Pod Created With Sensitive Volume](/analytics-alerts/alerts-by-name/kubernetes-pod-created-with-sensitive-volume.md)                                                                                                                 |
| [Kubernetes pod creation from unknown container image registry](/analytics-alerts/alerts-by-name/kubernetes-pod-creation-from-unknown-container-image-registry.md)                                                                               |
| [Kubernetes pod creation with host network](/analytics-alerts/alerts-by-name/kubernetes-pod-creation-with-host-network.md)                                                                                                                       |
| [Kubernetes Privileged Pod Creation](/analytics-alerts/alerts-by-name/kubernetes-privileged-pod-creation.md)                                                                                                                                     |
| [Kubernetes secret enumeration activity](/analytics-alerts/alerts-by-name/kubernetes-secret-enumeration-activity.md)                                                                                                                             |
| [Kubernetes secrets enumeration for the first time](/analytics-alerts/alerts-by-name/kubernetes-secrets-enumeration-for-the-first-time.md)                                                                                                       |
| [Kubernetes service account activity outside the cluster](/analytics-alerts/alerts-by-name/kubernetes-service-account-activity-outside-the-cluster.md)                                                                                           |
| [Kubernetes version disclosure](/analytics-alerts/alerts-by-name/kubernetes-version-disclosure.md)                                                                                                                                               |
| [Kubernetes vulnerability scanner activity](/analytics-alerts/alerts-by-name/kubernetes-vulnerability-scanner-activity.md)                                                                                                                       |
| [Kubernetes vulnerability scanning tool usage](/analytics-alerts/alerts-by-name/kubernetes-vulnerability-scanning-tool-usage.md)                                                                                                                 |
| [Large Upload (FTP)](/analytics-alerts/alerts-by-name/large-upload-ftp.md)                                                                                                                                                                       |
| [Large Upload (Generic)](/analytics-alerts/alerts-by-name/large-upload-generic.md)                                                                                                                                                               |
| [Large Upload (HTTPS)](/analytics-alerts/alerts-by-name/large-upload-https.md)                                                                                                                                                                   |
| [Large Upload (SMTP)](/analytics-alerts/alerts-by-name/large-upload-smtp.md)                                                                                                                                                                     |
| [Large volume of files potentially containing credentials accessed in Google Drive](/analytics-alerts/alerts-by-name/large-volume-of-files-potentially-containing-credentials-accessed-in-google-drive.md)                                       |
| [LDAP AD CS Enumeration via Attack Tool](/analytics-alerts/alerts-by-name/ldap-ad-cs-enumeration-via-attack-tool.md)                                                                                                                             |
| [LDAP search query from an unpopular and unsigned process](/analytics-alerts/alerts-by-name/ldap-search-query-from-an-unpopular-and-unsigned-process.md)                                                                                         |
| [LDAP traffic from non-standard process](/analytics-alerts/alerts-by-name/ldap-traffic-from-non-standard-process.md)                                                                                                                             |
| [Linux local user account creation](/analytics-alerts/alerts-by-name/linux-local-user-account-creation.md)                                                                                                                                       |
| [Linux network share discovery](/analytics-alerts/alerts-by-name/linux-network-share-discovery.md)                                                                                                                                               |
| [Linux process execution with a rare GitHub URL](/analytics-alerts/alerts-by-name/linux-process-execution-with-a-rare-github-url.md)                                                                                                             |
| [Linux system firewall was modified](/analytics-alerts/alerts-by-name/linux-system-firewall-was-modified.md)                                                                                                                                     |
| [Local account discovery](/analytics-alerts/alerts-by-name/local-account-discovery.md)                                                                                                                                                           |
| [Local group enumeration](/analytics-alerts/alerts-by-name/local-group-enumeration.md)                                                                                                                                                           |
| [Local group enumeration via RPC](/analytics-alerts/alerts-by-name/local-group-enumeration-via-rpc.md)                                                                                                                                           |
| [Local user account creation](/analytics-alerts/alerts-by-name/local-user-account-creation.md)                                                                                                                                                   |
| [Local user account creation by a machine account](/analytics-alerts/alerts-by-name/local-user-account-creation-by-a-machine-account.md)                                                                                                         |
| [Local user enumeration via SAMR](/analytics-alerts/alerts-by-name/local-user-enumeration-via-samr.md)                                                                                                                                           |
| [Log enumeration via cloud native logging service](/analytics-alerts/alerts-by-name/log-enumeration-via-cloud-native-logging-service.md)                                                                                                         |
| [Logging was impaired via external encryption key](/analytics-alerts/alerts-by-name/logging-was-impaired-via-external-encryption-key.md)                                                                                                         |
| [Login attempt by a honey user](/analytics-alerts/alerts-by-name/login-attempt-by-a-honey-user.md)                                                                                                                                               |
| [Login by a dormant user](/analytics-alerts/alerts-by-name/login-by-a-dormant-user.md)                                                                                                                                                           |
| [Logs were not collected from a data source for an abnormally long time](/analytics-alerts/alerts-by-name/logs-were-not-collected-from-a-data-source-for-an-abnormally-long-time.md)                                                             |
| [LOLBAS executable injects into another process](/analytics-alerts/alerts-by-name/lolbas-executable-injects-into-another-process.md)                                                                                                             |
| [LOLBIN created a PSScriptPolicyTest PowerShell script file](/analytics-alerts/alerts-by-name/lolbin-created-a-psscriptpolicytest-powershell-script-file.md)                                                                                     |
| [LOLBIN process executed with a high integrity level](/analytics-alerts/alerts-by-name/lolbin-process-executed-with-a-high-integrity-level.md)                                                                                                   |
| [LSASS dump file written to disk](/analytics-alerts/alerts-by-name/lsass-dump-file-written-to-disk.md)                                                                                                                                           |
| [Machine Account NTLM Relay](/analytics-alerts/alerts-by-name/machine-account-ntlm-relay.md)                                                                                                                                                     |
| [Machine account was added to a domain admins group](/analytics-alerts/alerts-by-name/machine-account-was-added-to-a-domain-admins-group.md)                                                                                                     |
| [Mailbox Client Access Setting (CAS) changed](/analytics-alerts/alerts-by-name/mailbox-client-access-setting-cas-changed.md)                                                                                                                     |
| [Mailbox enumeration activity by Azure application](/analytics-alerts/alerts-by-name/mailbox-enumeration-activity-by-azure-application.md)                                                                                                       |
| [Manipulation of netsh helper DLLs Registry keys](/analytics-alerts/alerts-by-name/manipulation-of-netsh-helper-dlls-registry-keys.md)                                                                                                           |
| [Masquerading as a default local account](/analytics-alerts/alerts-by-name/masquerading-as-a-default-local-account.md)                                                                                                                           |
| [Masquerading as the Linux crond process](/analytics-alerts/alerts-by-name/masquerading-as-the-linux-crond-process.md)                                                                                                                           |
| [Massive file activity abnormal to process](/analytics-alerts/alerts-by-name/massive-file-activity-abnormal-to-process.md)                                                                                                                       |
| [Massive file compression by user](/analytics-alerts/alerts-by-name/massive-file-compression-by-user.md)                                                                                                                                         |
| [Massive file downloads from SaaS service](/analytics-alerts/alerts-by-name/massive-file-downloads-from-saas-service.md)                                                                                                                         |
| [Massive files deletion in Box](/analytics-alerts/alerts-by-name/massive-files-deletion-in-box.md)                                                                                                                                               |
| [Massive files deletion in Dropbox](/analytics-alerts/alerts-by-name/massive-files-deletion-in-dropbox.md)                                                                                                                                       |
| [Massive files deletion in Google Drive](/analytics-alerts/alerts-by-name/massive-files-deletion-in-google-drive.md)                                                                                                                             |
| [Massive files deletion in Microsoft SharePoint or OneDrive](/analytics-alerts/alerts-by-name/massive-files-deletion-in-microsoft-sharepoint-or-onedrive.md)                                                                                     |
| [Massive upload to a rare storage or mail domain](/analytics-alerts/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain.md)                                                                                                           |
| [Massive upload to SaaS service](/analytics-alerts/alerts-by-name/massive-upload-to-saas-service.md)                                                                                                                                             |
| [Member added to a Windows local security group](/analytics-alerts/alerts-by-name/member-added-to-a-windows-local-security-group.md)                                                                                                             |
| [Memory dumping with comsvcs.dll](/analytics-alerts/alerts-by-name/memory-dumping-with-comsvcs-dll.md)                                                                                                                                           |
| [MFA device was removed/deactivated from an IAM user](/analytics-alerts/alerts-by-name/mfa-device-was-removed-deactivated-from-an-iam-user.md)                                                                                                   |
| [MFA Disabled for Google Workspace](/analytics-alerts/alerts-by-name/mfa-disabled-for-google-workspace.md)                                                                                                                                       |
| [MFA was disabled for a Google Workspace user](/analytics-alerts/alerts-by-name/mfa-was-disabled-for-a-google-workspace-user.md)                                                                                                                 |
| [MFA was disabled for an Azure identity](/analytics-alerts/alerts-by-name/mfa-was-disabled-for-an-azure-identity.md)                                                                                                                             |
| [Microsoft 365 DLP policy disabled or removed](/analytics-alerts/alerts-by-name/microsoft-365-dlp-policy-disabled-or-removed.md)                                                                                                                 |
| [Microsoft 365 storage services exfiltration activity](/analytics-alerts/alerts-by-name/microsoft-365-storage-services-exfiltration-activity.md)                                                                                                 |
| [Microsoft Configuration Manager device registration and policy request](/analytics-alerts/alerts-by-name/microsoft-configuration-manager-device-registration-and-policy-request.md)                                                             |
| [Microsoft Office adds a value to autostart Registry key](/analytics-alerts/alerts-by-name/microsoft-office-adds-a-value-to-autostart-registry-key.md)                                                                                           |
| [Microsoft Office injects code into a process](/analytics-alerts/alerts-by-name/microsoft-office-injects-code-into-a-process.md)                                                                                                                 |
| [Microsoft Office Process Spawning a Suspicious One-Liner](/analytics-alerts/alerts-by-name/microsoft-office-process-spawning-a-suspicious-one-liner.md)                                                                                         |
| [Microsoft Office process spawns a commonly abused process](/analytics-alerts/alerts-by-name/microsoft-office-process-spawns-a-commonly-abused-process.md)                                                                                       |
| [Microsoft Office process spawns conhost.exe](/analytics-alerts/alerts-by-name/microsoft-office-process-spawns-conhost-exe.md)                                                                                                                   |
| [Microsoft OneDrive enumeration activity](/analytics-alerts/alerts-by-name/microsoft-onedrive-enumeration-activity.md)                                                                                                                           |
| [Microsoft OneNote enumeration activity](/analytics-alerts/alerts-by-name/microsoft-onenote-enumeration-activity.md)                                                                                                                             |
| [Microsoft SharePoint enumeration activity](/analytics-alerts/alerts-by-name/microsoft-sharepoint-enumeration-activity.md)                                                                                                                       |
| [Microsoft Teams application setup policy was modified](/analytics-alerts/alerts-by-name/microsoft-teams-application-setup-policy-was-modified.md)                                                                                               |
| [Microsoft Teams enumeration activity](/analytics-alerts/alerts-by-name/microsoft-teams-enumeration-activity.md)                                                                                                                                 |
| [Microsoft Teams external communication policy was modified](/analytics-alerts/alerts-by-name/microsoft-teams-external-communication-policy-was-modified.md)                                                                                     |
| [Microsoft Teams messages were exported from conversation](/analytics-alerts/alerts-by-name/microsoft-teams-messages-were-exported-from-conversation.md)                                                                                         |
| [Mimikatz command-line arguments](/analytics-alerts/alerts-by-name/mimikatz-command-line-arguments.md)                                                                                                                                           |
| [ML artifacts destruction](/analytics-alerts/alerts-by-name/ml-artifacts-destruction.md)                                                                                                                                                         |
| [Modification of NTLM restrictions in the Registry](/analytics-alerts/alerts-by-name/modification-of-ntlm-restrictions-in-the-registry.md)                                                                                                       |
| [Modification of PAM](/analytics-alerts/alerts-by-name/modification-of-pam.md)                                                                                                                                                                   |
| [Modification of the AD FS IdentityServer configuration file](/analytics-alerts/alerts-by-name/modification-of-the-ad-fs-identityserver-configuration-file.md)                                                                                   |
| [Modification or Deletion of an Azure Application Gateway Detected](/analytics-alerts/alerts-by-name/modification-or-deletion-of-an-azure-application-gateway-detected.md)                                                                       |
| [Moniker link detected in URL(s)](/analytics-alerts/alerts-by-name/moniker-link-detected-in-url-s.md)                                                                                                                                            |
| [Mount command was executed from within a Kubernetes pod to list all the attached filesystems](/analytics-alerts/alerts-by-name/mount-command-was-executed-from-within-a-kubernetes-pod-to-list-all-the-attached-filesystems.md)                 |
| [MpCmdRun.exe was used to download files into the system](/analytics-alerts/alerts-by-name/mpcmdrun-exe-was-used-to-download-files-into-the-system.md)                                                                                           |
| [Mshta.exe launched with suspicious arguments](/analytics-alerts/alerts-by-name/mshta-exe-launched-with-suspicious-arguments.md)                                                                                                                 |
| [Mshta.exe spawns from a browser process](/analytics-alerts/alerts-by-name/mshta-exe-spawns-from-a-browser-process.md)                                                                                                                           |
| [MSI accessed a web page running a server-side script](/analytics-alerts/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script.md)                                                                                                 |
| [Msiexec execution of an executable from an uncommon remote location](/analytics-alerts/alerts-by-name/msiexec-execution-of-an-executable-from-an-uncommon-remote-location.md)                                                                   |
| [Multi region enumeration activity](/analytics-alerts/alerts-by-name/multi-region-enumeration-activity.md)                                                                                                                                       |
| [Multiple alerts associated with a single RDP connection](/analytics-alerts/alerts-by-name/multiple-alerts-associated-with-a-single-rdp-connection.md)                                                                                           |
| [Multiple alerts of different MITRE tactics were seen](/analytics-alerts/alerts-by-name/multiple-alerts-of-different-mitre-tactics-were-seen.md)                                                                                                 |
| [Multiple Azure AD admin role removals](/analytics-alerts/alerts-by-name/multiple-azure-ad-admin-role-removals.md)                                                                                                                               |
| [Multiple cloud snapshots export](/analytics-alerts/alerts-by-name/multiple-cloud-snapshots-export.md)                                                                                                                                           |
| [Multiple discovery commands](/analytics-alerts/alerts-by-name/multiple-discovery-commands.md)                                                                                                                                                   |
| [Multiple discovery commands on a Linux host by the same process](/analytics-alerts/alerts-by-name/multiple-discovery-commands-on-a-linux-host-by-the-same-process.md)                                                                           |
| [Multiple discovery commands on a Windows host by the same process](/analytics-alerts/alerts-by-name/multiple-discovery-commands-on-a-windows-host-by-the-same-process.md)                                                                       |
| [Multiple discovery-like commands](/analytics-alerts/alerts-by-name/multiple-discovery-like-commands.md)                                                                                                                                         |
| [Multiple failed AWS assume role attempts](/analytics-alerts/alerts-by-name/multiple-failed-aws-assume-role-attempts.md)                                                                                                                         |
| [Multiple failed logins from a single IP](/analytics-alerts/alerts-by-name/multiple-failed-logins-from-a-single-ip.md)                                                                                                                           |
| [Multiple network-related alerts of different MITRE tactics on the same host](/analytics-alerts/alerts-by-name/multiple-network-related-alerts-of-different-mitre-tactics-on-the-same-host.md)                                                   |
| [Multiple network-related alerts produced by different detectors on the same host](/analytics-alerts/alerts-by-name/multiple-network-related-alerts-produced-by-different-detectors-on-the-same-host.md)                                         |
| [Multiple Okta MFA requests sent to a user](/analytics-alerts/alerts-by-name/multiple-okta-mfa-requests-sent-to-a-user.md)                                                                                                                       |
| [Multiple Rare LOLBIN Process Executions by User](/analytics-alerts/alerts-by-name/multiple-rare-lolbin-process-executions-by-user.md)                                                                                                           |
| [Multiple Rare Process Executions in Organization](/analytics-alerts/alerts-by-name/multiple-rare-process-executions-in-organization.md)                                                                                                         |
| [Multiple risk indicators for a cloud identity](/analytics-alerts/alerts-by-name/multiple-risk-indicators-for-a-cloud-identity.md)                                                                                                               |
| [Multiple Suspicious FTP Login Attempts](/analytics-alerts/alerts-by-name/multiple-suspicious-ftp-login-attempts.md)                                                                                                                             |
| [Multiple suspicious user accounts were created](/analytics-alerts/alerts-by-name/multiple-suspicious-user-accounts-were-created.md)                                                                                                             |
| [Multiple TGT requests for users without Kerberos pre-authentication](/analytics-alerts/alerts-by-name/multiple-tgt-requests-for-users-without-kerberos-pre-authentication.md)                                                                   |
| [Multiple uncommon SSH Servers with the same Server host key](/analytics-alerts/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key.md)                                                                                   |
| [Multiple user accounts failed login due to account lockouts](/analytics-alerts/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts.md)                                                                                   |
| [Multiple user accounts were deleted](/analytics-alerts/alerts-by-name/multiple-user-accounts-were-deleted.md)                                                                                                                                   |
| [Multiple users authenticated with weak NTLM to a host](/analytics-alerts/alerts-by-name/multiple-users-authenticated-with-weak-ntlm-to-a-host.md)                                                                                               |
| [Multiple Weakly-Encrypted Kerberos Tickets Received](/analytics-alerts/alerts-by-name/multiple-weakly-encrypted-kerberos-tickets-received.md)                                                                                                   |
| [Near-empty email from an external sender](/analytics-alerts/alerts-by-name/near-empty-email-from-an-external-sender.md)                                                                                                                         |
| [Netcat makes or gets connections](/analytics-alerts/alerts-by-name/netcat-makes-or-gets-connections.md)                                                                                                                                         |
| [Network sniffing detected in Cloud environment](/analytics-alerts/alerts-by-name/network-sniffing-detected-in-cloud-environment.md)                                                                                                             |
| [New addition to Windows Defender exclusion list](/analytics-alerts/alerts-by-name/new-addition-to-windows-defender-exclusion-list.md)                                                                                                           |
| [New Administrative Behavior](/analytics-alerts/alerts-by-name/new-administrative-behavior.md)                                                                                                                                                   |
| [New cloud identity created with administrative policy](/analytics-alerts/alerts-by-name/new-cloud-identity-created-with-administrative-policy.md)                                                                                               |
| [New FTP Server](/analytics-alerts/alerts-by-name/new-ftp-server.md)                                                                                                                                                                             |
| [New Shared User Account](/analytics-alerts/alerts-by-name/new-shared-user-account.md)                                                                                                                                                           |
| [New Teams application published to the organization catalog](/analytics-alerts/alerts-by-name/new-teams-application-published-to-the-organization-catalog.md)                                                                                   |
| [Non-browser access to a pastebin-like site](/analytics-alerts/alerts-by-name/non-browser-access-to-a-pastebin-like-site.md)                                                                                                                     |
| [NTDS.dit file written by an uncommon executable](/analytics-alerts/alerts-by-name/ntds-dit-file-written-by-an-uncommon-executable.md)                                                                                                           |
| [NTLM Brute Force](/analytics-alerts/alerts-by-name/ntlm-brute-force.md)                                                                                                                                                                         |
| [NTLM Brute Force on a Service Account](/analytics-alerts/alerts-by-name/ntlm-brute-force-on-a-service-account.md)                                                                                                                               |
| [NTLM Brute Force on an Administrator Account](/analytics-alerts/alerts-by-name/ntlm-brute-force-on-an-administrator-account.md)                                                                                                                 |
| [NTLM Hash Harvesting](/analytics-alerts/alerts-by-name/ntlm-hash-harvesting.md)                                                                                                                                                                 |
| [NTLM Password Spray](/analytics-alerts/alerts-by-name/ntlm-password-spray.md)                                                                                                                                                                   |
| [NTLM Relay](/analytics-alerts/alerts-by-name/ntlm-relay.md)                                                                                                                                                                                     |
| [Numerous emails sent by a single sender to multiple internal recipients](/analytics-alerts/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients.md)                                                           |
| [Object versioning was disabled](/analytics-alerts/alerts-by-name/object-versioning-was-disabled.md)                                                                                                                                             |
| [Office process accessed an unusual .LNK file](/analytics-alerts/alerts-by-name/office-process-accessed-an-unusual-lnk-file.md)                                                                                                                  |
| [Office process spawned with suspicious command-line arguments](/analytics-alerts/alerts-by-name/office-process-spawned-with-suspicious-command-line-arguments.md)                                                                               |
| [Okta account reset password attempt](/analytics-alerts/alerts-by-name/okta-account-reset-password-attempt.md)                                                                                                                                   |
| [Okta account unlock](/analytics-alerts/alerts-by-name/okta-account-unlock.md)                                                                                                                                                                   |
| [Okta account unlock by admin](/analytics-alerts/alerts-by-name/okta-account-unlock-by-admin.md)                                                                                                                                                 |
| [Okta admin privilege assignment](/analytics-alerts/alerts-by-name/okta-admin-privilege-assignment.md)                                                                                                                                           |
| [Okta API Token Created](/analytics-alerts/alerts-by-name/okta-api-token-created.md)                                                                                                                                                             |
| [Okta device assignment](/analytics-alerts/alerts-by-name/okta-device-assignment.md)                                                                                                                                                             |
| [Okta FastPass reported phishing attack suspected](/analytics-alerts/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected.md)                                                                                                         |
| [Okta Reported Attack Suspected](/analytics-alerts/alerts-by-name/okta-reported-attack-suspected.md)                                                                                                                                             |
| [Okta Reported Threat Detected](/analytics-alerts/alerts-by-name/okta-reported-threat-detected.md)                                                                                                                                               |
| [Okta User Session Impersonation](/analytics-alerts/alerts-by-name/okta-user-session-impersonation.md)                                                                                                                                           |
| [OneDrive file download](/analytics-alerts/alerts-by-name/onedrive-file-download.md)                                                                                                                                                             |
| [OneDrive file upload](/analytics-alerts/alerts-by-name/onedrive-file-upload.md)                                                                                                                                                                 |
| [OneDrive folder creation](/analytics-alerts/alerts-by-name/onedrive-folder-creation.md)                                                                                                                                                         |
| [Outbound email contains file-sharing service link sent to external recipient](/analytics-alerts/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient.md)                                                 |
| [Outbound email includes an external BCC recipient observed for the first time](/analytics-alerts/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time.md)                                               |
| [Outbound email to an address hosted by a public email service provider](/analytics-alerts/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider.md)                                                             |
| [Outlook files accessed by an unsigned process](/analytics-alerts/alerts-by-name/outlook-files-accessed-by-an-unsigned-process.md)                                                                                                               |
| [Owner added to Azure application](/analytics-alerts/alerts-by-name/owner-added-to-azure-application.md)                                                                                                                                         |
| [Owner was added to Azure application](/analytics-alerts/alerts-by-name/owner-was-added-to-azure-application.md)                                                                                                                                 |
| [Parsing Rule Error](/analytics-alerts/alerts-by-name/parsing-rule-error.md)                                                                                                                                                                     |
| [Penetration testing tool activity attempt](/analytics-alerts/alerts-by-name/penetration-testing-tool-activity-attempt.md)                                                                                                                       |
| [Permission Groups discovery commands](/analytics-alerts/alerts-by-name/permission-groups-discovery-commands.md)                                                                                                                                 |
| [Phantom DLL Loading](/analytics-alerts/alerts-by-name/phantom-dll-loading.md)                                                                                                                                                                   |
| [PIM privilege member removal](/analytics-alerts/alerts-by-name/pim-privilege-member-removal.md)                                                                                                                                                 |
| [Ping to localhost from an uncommon, unsigned parent process](/analytics-alerts/alerts-by-name/ping-to-localhost-from-an-uncommon-unsigned-parent-process.md)                                                                                    |
| [PKINIT TGT authentication request](/analytics-alerts/alerts-by-name/pkinit-tgt-authentication-request.md)                                                                                                                                       |
| [Port Scan](/analytics-alerts/alerts-by-name/port-scan.md)                                                                                                                                                                                       |
| [Port Sweep](/analytics-alerts/alerts-by-name/port-sweep.md)                                                                                                                                                                                     |
| [Possible AS-REP Roasting Attack](/analytics-alerts/alerts-by-name/possible-as-rep-roasting-attack.md)                                                                                                                                           |
| [Possible authentication coercion](/analytics-alerts/alerts-by-name/possible-authentication-coercion.md)                                                                                                                                         |
| [Possible binary padding using dd](/analytics-alerts/alerts-by-name/possible-binary-padding-using-dd.md)                                                                                                                                         |
| [Possible brute force on sudo user](/analytics-alerts/alerts-by-name/possible-brute-force-on-sudo-user.md)                                                                                                                                       |
| [Possible brute force or configuration change attempt on cytool](/analytics-alerts/alerts-by-name/possible-brute-force-or-configuration-change-attempt-on-cytool.md)                                                                             |
| [Possible Brute-Force attempt](/analytics-alerts/alerts-by-name/possible-brute-force-attempt.md)                                                                                                                                                 |
| [Possible code downloading from a remote host by Regsvr32](/analytics-alerts/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32.md)                                                                                         |
| [Possible collection of screen captures with Windows Problem Steps Recorder](/analytics-alerts/alerts-by-name/possible-collection-of-screen-captures-with-windows-problem-steps-recorder.md)                                                     |
| [Possible compromised machine account](/analytics-alerts/alerts-by-name/possible-compromised-machine-account.md)                                                                                                                                 |
| [Possible ConsentFix - OAuth Token Theft Detected](/analytics-alerts/alerts-by-name/possible-consentfix-oauth-token-theft-detected.md)                                                                                                           |
| [Possible data exfiltration over a USB storage device](/analytics-alerts/alerts-by-name/possible-data-exfiltration-over-a-usb-storage-device.md)                                                                                                 |
| [Possible data obfuscation](/analytics-alerts/alerts-by-name/possible-data-obfuscation.md)                                                                                                                                                       |
| [Possible DCSync from a non domain controller](/analytics-alerts/alerts-by-name/possible-dcsync-from-a-non-domain-controller.md)                                                                                                                 |
| [Possible Distributed File System Namespace Management (DFSNM) abuse](/analytics-alerts/alerts-by-name/possible-distributed-file-system-namespace-management-dfsnm-abuse.md)                                                                     |
| [Possible DLL Hijack into a Microsoft process](/analytics-alerts/alerts-by-name/possible-dll-hijack-into-a-microsoft-process.md)                                                                                                                 |
| [Possible DLL Search Order Hijacking](/analytics-alerts/alerts-by-name/possible-dll-search-order-hijacking.md)                                                                                                                                   |
| [Possible Email collection using Outlook RPC](/analytics-alerts/alerts-by-name/possible-email-collection-using-outlook-rpc.md)                                                                                                                   |
| [Possible external RDP Brute-Force](/analytics-alerts/alerts-by-name/possible-external-rdp-brute-force.md)                                                                                                                                       |
| [Possible GPO Enumeration](/analytics-alerts/alerts-by-name/possible-gpo-enumeration.md)                                                                                                                                                         |
| [Possible Impossible Travel Pattern - SSO](/analytics-alerts/alerts-by-name/possible-impossible-travel-pattern-sso.md)                                                                                                                           |
| [Possible Insider Threat Activity](/analytics-alerts/alerts-by-name/possible-insider-threat-activity.md)                                                                                                                                         |
| [Possible internal data exfiltration over a USB storage device](/analytics-alerts/alerts-by-name/possible-internal-data-exfiltration-over-a-usb-storage-device.md)                                                                               |
| [Possible IPFS traffic was detected](/analytics-alerts/alerts-by-name/possible-ipfs-traffic-was-detected.md)                                                                                                                                     |
| [Possible Kerberoasting attack](/analytics-alerts/alerts-by-name/possible-kerberoasting-attack.md)                                                                                                                                               |
| [Possible Kerberoasting without SPNs](/analytics-alerts/alerts-by-name/possible-kerberoasting-without-spns.md)                                                                                                                                   |
| [Possible Kerberos relay attack](/analytics-alerts/alerts-by-name/possible-kerberos-relay-attack.md)                                                                                                                                             |
| [Possible Kerberos User Enumeration](/analytics-alerts/alerts-by-name/possible-kerberos-user-enumeration.md)                                                                                                                                     |
| [Possible LDAP enumeration by unsigned process](/analytics-alerts/alerts-by-name/possible-ldap-enumeration-by-unsigned-process.md)                                                                                                               |
| [Possible LDAP Enumeration of Microsoft Configuration Manager](/analytics-alerts/alerts-by-name/possible-ldap-enumeration-of-microsoft-configuration-manager.md)                                                                                 |
| [Possible LDAP Enumeration Tool Usage](/analytics-alerts/alerts-by-name/possible-ldap-enumeration-tool-usage.md)                                                                                                                                 |
| [Possible malicious .NET compilation started by a commonly abused process](/analytics-alerts/alerts-by-name/possible-malicious-net-compilation-started-by-a-commonly-abused-process.md)                                                          |
| [Possible multistage attack in Microsoft Teams](/analytics-alerts/alerts-by-name/possible-multistage-attack-in-microsoft-teams.md)                                                                                                               |
| [Possible network service discovery via command-line tool](/analytics-alerts/alerts-by-name/possible-network-service-discovery-via-command-line-tool.md)                                                                                         |
| [Possible network sniffing attempt via tcpdump or tshark](/analytics-alerts/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark.md)                                                                                           |
| [Possible new DHCP server](/analytics-alerts/alerts-by-name/possible-new-dhcp-server.md)                                                                                                                                                         |
| [Possible Pass-the-Hash](/analytics-alerts/alerts-by-name/possible-pass-the-hash.md)                                                                                                                                                             |
| [Possible path traversal via HTTP request](/analytics-alerts/alerts-by-name/possible-path-traversal-via-http-request.md)                                                                                                                         |
| [Possible Persistence via group policy Registry keys](/analytics-alerts/alerts-by-name/possible-persistence-via-group-policy-registry-keys.md)                                                                                                   |
| [Possible phishing attack via Microsoft Teams](/analytics-alerts/alerts-by-name/possible-phishing-attack-via-microsoft-teams.md)                                                                                                                 |
| [Possible Privilege Escalation using Delegated MSA account](/analytics-alerts/alerts-by-name/possible-privilege-escalation-using-delegated-msa-account.md)                                                                                       |
| [Possible RDP session hijacking using tscon.exe](/analytics-alerts/alerts-by-name/possible-rdp-session-hijacking-using-tscon-exe.md)                                                                                                             |
| [Possible Search For Password Files](/analytics-alerts/alerts-by-name/possible-search-for-password-files.md)                                                                                                                                     |
| [Possible SPN enumeration](/analytics-alerts/alerts-by-name/possible-spn-enumeration.md)                                                                                                                                                         |
| [Possible TGT reuse from different hosts (pass the ticket)](/analytics-alerts/alerts-by-name/possible-tgt-reuse-from-different-hosts-pass-the-ticket.md)                                                                                         |
| [Possible use of a networking driver for network sniffing](/analytics-alerts/alerts-by-name/possible-use-of-a-networking-driver-for-network-sniffing.md)                                                                                         |
| [Possible use of IPFS was detected](/analytics-alerts/alerts-by-name/possible-use-of-ipfs-was-detected.md)                                                                                                                                       |
| [Possible webshell file written by a web server process](/analytics-alerts/alerts-by-name/possible-webshell-file-written-by-a-web-server-process.md)                                                                                             |
| [Potential creation of persistent cloud credentials](/analytics-alerts/alerts-by-name/potential-creation-of-persistent-cloud-credentials.md)                                                                                                     |
| [Potential DCSync by an unusual user](/analytics-alerts/alerts-by-name/potential-dcsync-by-an-unusual-user.md)                                                                                                                                   |
| [Potential denial of wallet abusing AI services](/analytics-alerts/alerts-by-name/potential-denial-of-wallet-abusing-ai-services.md)                                                                                                             |
| [Potential extraction of NAA Account Credentials in Microsoft Configuration Manager](/analytics-alerts/alerts-by-name/potential-extraction-of-naa-account-credentials-in-microsoft-configuration-manager.md)                                     |
| [Potential kubelet impersonation attempt](/analytics-alerts/alerts-by-name/potential-kubelet-impersonation-attempt.md)                                                                                                                           |
| [Potential NTLM Relay Attack](/analytics-alerts/alerts-by-name/potential-ntlm-relay-attack.md)                                                                                                                                                   |
| [Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server](/analytics-alerts/alerts-by-name/potential-ntlm-relay-attack-against-a-microsoft-configuration-manager-site-server.md)                                       |
| [Potential Okta access limit breach](/analytics-alerts/alerts-by-name/potential-okta-access-limit-breach.md)                                                                                                                                     |
| [Potential Phishing has been detected](/analytics-alerts/alerts-by-name/potential-phishing-has-been-detected.md)                                                                                                                                 |
| [Potential SCCM credential harvesting using WMI detected](/analytics-alerts/alerts-by-name/potential-sccm-credential-harvesting-using-wmi-detected.md)                                                                                           |
| [Potential spoofing of internal domain spotted](/analytics-alerts/alerts-by-name/potential-spoofing-of-internal-domain-spotted.md)                                                                                                               |
| [PowerShell Initiates a Network Connection to GitHub](/analytics-alerts/alerts-by-name/powershell-initiates-a-network-connection-to-github.md)                                                                                                   |
| [PowerShell pfx certificate extraction](/analytics-alerts/alerts-by-name/powershell-pfx-certificate-extraction.md)                                                                                                                               |
| [PowerShell runs suspicious base64-encoded commands](/analytics-alerts/alerts-by-name/powershell-runs-suspicious-base64-encoded-commands.md)                                                                                                     |
| [PowerShell suspicious flags](/analytics-alerts/alerts-by-name/powershell-suspicious-flags.md)                                                                                                                                                   |
| [PowerShell used to export mailbox contents](/analytics-alerts/alerts-by-name/powershell-used-to-export-mailbox-contents.md)                                                                                                                     |
| [PowerShell used to remove mailbox export request logs](/analytics-alerts/alerts-by-name/powershell-used-to-remove-mailbox-export-request-logs.md)                                                                                               |
| [Privileged certificate request via certificate template](/analytics-alerts/alerts-by-name/privileged-certificate-request-via-certificate-template.md)                                                                                           |
| [Privileged role used by Azure application](/analytics-alerts/alerts-by-name/privileged-role-used-by-azure-application.md)                                                                                                                       |
| [Procdump executed from an atypical directory](/analytics-alerts/alerts-by-name/procdump-executed-from-an-atypical-directory.md)                                                                                                                 |
| [PsExec was executed with a suspicious command line](/analytics-alerts/alerts-by-name/psexec-was-executed-with-a-suspicious-command-line.md)                                                                                                     |
| [Punycode characters detected in URL(s)](/analytics-alerts/alerts-by-name/punycode-characters-detected-in-url-s.md)                                                                                                                              |
| [Python HTTP server started](/analytics-alerts/alerts-by-name/python-http-server-started.md)                                                                                                                                                     |
| [Quarantined email released to recipients](/analytics-alerts/alerts-by-name/quarantined-email-released-to-recipients.md)                                                                                                                         |
| [Random-Looking Domain Names](/analytics-alerts/alerts-by-name/random-looking-domain-names.md)                                                                                                                                                   |
| [Rare access to known advertising domains](/analytics-alerts/alerts-by-name/rare-access-to-known-advertising-domains.md)                                                                                                                         |
| [Rare AppID usage to a rare destination](/analytics-alerts/alerts-by-name/rare-appid-usage-to-a-rare-destination.md)                                                                                                                             |
| [Rare binary connected to a rare cloud resource](/analytics-alerts/alerts-by-name/rare-binary-connected-to-a-rare-cloud-resource.md)                                                                                                             |
| [Rare binary connected to a rare external host](/analytics-alerts/alerts-by-name/rare-binary-connected-to-a-rare-external-host.md)                                                                                                               |
| [Rare communication over email ports to external email server by unsigned process](/analytics-alerts/alerts-by-name/rare-communication-over-email-ports-to-external-email-server-by-unsigned-process.md)                                         |
| [Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol](/analytics-alerts/alerts-by-name/rare-connection-to-external-ip-address-or-host-by-an-application-using-rmi-iiop-or-ldap-protocol.md)         |
| [Rare DCOM RPC activity](/analytics-alerts/alerts-by-name/rare-dcom-rpc-activity.md)                                                                                                                                                             |
| [Rare DLP rule match by user](/analytics-alerts/alerts-by-name/rare-dlp-rule-match-by-user.md)                                                                                                                                                   |
| [Rare file transfer over SMB protocol](/analytics-alerts/alerts-by-name/rare-file-transfer-over-smb-protocol.md)                                                                                                                                 |
| [Rare LDAP enumeration](/analytics-alerts/alerts-by-name/rare-ldap-enumeration.md)                                                                                                                                                               |
| [Rare LOLBIN Process Execution by User](/analytics-alerts/alerts-by-name/rare-lolbin-process-execution-by-user.md)                                                                                                                               |
| [Rare machine account creation](/analytics-alerts/alerts-by-name/rare-machine-account-creation.md)                                                                                                                                               |
| [Rare MS-Update Server was detected](/analytics-alerts/alerts-by-name/rare-ms-update-server-was-detected.md)                                                                                                                                     |
| [Rare MS-Update traffic over HTTP](/analytics-alerts/alerts-by-name/rare-ms-update-traffic-over-http.md)                                                                                                                                         |
| [Rare NTLM Access By User To Host](/analytics-alerts/alerts-by-name/rare-ntlm-access-by-user-to-host.md)                                                                                                                                         |
| [Rare NTLM Usage by User](/analytics-alerts/alerts-by-name/rare-ntlm-usage-by-user.md)                                                                                                                                                           |
| [Rare process accessed a Keychain file](/analytics-alerts/alerts-by-name/rare-process-accessed-a-keychain-file.md)                                                                                                                               |
| [Rare process created an SSH session to an uncommon cloud resource](/analytics-alerts/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-cloud-resource.md)                                                                       |
| [Rare process created an SSH session to an uncommon external host](/analytics-alerts/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-external-host.md)                                                                         |
| [Rare process executed by an AppleScript](/analytics-alerts/alerts-by-name/rare-process-executed-by-an-applescript.md)                                                                                                                           |
| [Rare process execution by user](/analytics-alerts/alerts-by-name/rare-process-execution-by-user.md)                                                                                                                                             |
| [Rare process execution in organization](/analytics-alerts/alerts-by-name/rare-process-execution-in-organization.md)                                                                                                                             |
| [Rare process spawned by srvany.exe](/analytics-alerts/alerts-by-name/rare-process-spawned-by-srvany-exe.md)                                                                                                                                     |
| [Rare process with VNC server capabilities started](/analytics-alerts/alerts-by-name/rare-process-with-vnc-server-capabilities-started.md)                                                                                                       |
| [Rare RDP session to a remote host](/analytics-alerts/alerts-by-name/rare-rdp-session-to-a-remote-host.md)                                                                                                                                       |
| [Rare Remote Service (SVCCTL) RPC activity](/analytics-alerts/alerts-by-name/rare-remote-service-svcctl-rpc-activity.md)                                                                                                                         |
| [Rare scheduled task created](/analytics-alerts/alerts-by-name/rare-scheduled-task-created.md)                                                                                                                                                   |
| [Rare Scheduled Task RPC activity](/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity.md)                                                                                                                                         |
| [Rare Scheduled Task RPC activity from a rarely seen host](/analytics-alerts/alerts-by-name/rare-scheduled-task-rpc-activity-from-a-rarely-seen-host.md)                                                                                         |
| [Rare security product signed executable executed in the network](/analytics-alerts/alerts-by-name/rare-security-product-signed-executable-executed-in-the-network.md)                                                                           |
| [Rare service DLL was added to the registry](/analytics-alerts/alerts-by-name/rare-service-dll-was-added-to-the-registry.md)                                                                                                                     |
| [Rare signature signed executable executed in the network](/analytics-alerts/alerts-by-name/rare-signature-signed-executable-executed-in-the-network.md)                                                                                         |
| [Rare SMB session to a remote host](/analytics-alerts/alerts-by-name/rare-smb-session-to-a-remote-host.md)                                                                                                                                       |
| [Rare SMTP/S Session](/analytics-alerts/alerts-by-name/rare-smtp-s-session.md)                                                                                                                                                                   |
| [Rare SSH Session](/analytics-alerts/alerts-by-name/rare-ssh-session.md)                                                                                                                                                                         |
| [Rare Unix process divided files by size](/analytics-alerts/alerts-by-name/rare-unix-process-divided-files-by-size.md)                                                                                                                           |
| [Rare unsigned process execution by scheduled task](/analytics-alerts/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task.md)                                                                                                       |
| [Rare Unsigned Process Spawned by Office Process Under Suspicious Directory](/analytics-alerts/alerts-by-name/rare-unsigned-process-spawned-by-office-process-under-suspicious-directory.md)                                                     |
| [Rare Windows Remote Management (WinRM) HTTP Activity](/analytics-alerts/alerts-by-name/rare-windows-remote-management-winrm-http-activity.md)                                                                                                   |
| [Rare WinRM Session](/analytics-alerts/alerts-by-name/rare-winrm-session.md)                                                                                                                                                                     |
| [Rarely seen sender address in the organization](/analytics-alerts/alerts-by-name/rarely-seen-sender-address-in-the-organization.md)                                                                                                             |
| [Rarely seen sender domain in the organization](/analytics-alerts/alerts-by-name/rarely-seen-sender-domain-in-the-organization.md)                                                                                                               |
| [RDP Connection to localhost](/analytics-alerts/alerts-by-name/rdp-connection-to-localhost.md)                                                                                                                                                   |
| [RDP connections enabled remotely via Registry](/analytics-alerts/alerts-by-name/rdp-connections-enabled-remotely-via-registry.md)                                                                                                               |
| [RDP from an unmanaged endpoint in a typically managed subnet](/analytics-alerts/alerts-by-name/rdp-from-an-unmanaged-endpoint-in-a-typically-managed-subnet.md)                                                                                 |
| [Reading bash command history file](/analytics-alerts/alerts-by-name/reading-bash-command-history-file.md)                                                                                                                                       |
| [Recurring access to rare domain](/analytics-alerts/alerts-by-name/recurring-access-to-rare-domain.md)                                                                                                                                           |
| [Recurring access to rare IP](/analytics-alerts/alerts-by-name/recurring-access-to-rare-ip.md)                                                                                                                                                   |
| [Recurring rare domain access from an unsigned process](/analytics-alerts/alerts-by-name/recurring-rare-domain-access-from-an-unsigned-process.md)                                                                                               |
| [Recurring rare domain access to dynamic DNS domain](/analytics-alerts/alerts-by-name/recurring-rare-domain-access-to-dynamic-dns-domain.md)                                                                                                     |
| [Registration of Uncommon .NET Services and/or Assemblies](/analytics-alerts/alerts-by-name/registration-of-uncommon-net-services-and-or-assemblies.md)                                                                                          |
| [Remote account enumeration](/analytics-alerts/alerts-by-name/remote-account-enumeration.md)                                                                                                                                                     |
| [Remote code execution into Kubernetes Pod](/analytics-alerts/alerts-by-name/remote-code-execution-into-kubernetes-pod.md)                                                                                                                       |
| [Remote command execution via wmic.exe](/analytics-alerts/alerts-by-name/remote-command-execution-via-wmic-exe.md)                                                                                                                               |
| [Remote DCOM command execution](/analytics-alerts/alerts-by-name/remote-dcom-command-execution.md)                                                                                                                                               |
| [Remote PsExec-like command execution](/analytics-alerts/alerts-by-name/remote-psexec-like-command-execution.md)                                                                                                                                 |
| [Remote service command execution from an uncommon source](/analytics-alerts/alerts-by-name/remote-service-command-execution-from-an-uncommon-source.md)                                                                                         |
| [Remote service start from an uncommon source](/analytics-alerts/alerts-by-name/remote-service-start-from-an-uncommon-source.md)                                                                                                                 |
| [Remote usage of an App engine Service Account token](/analytics-alerts/alerts-by-name/remote-usage-of-an-app-engine-service-account-token.md)                                                                                                   |
| [Remote usage of an AWS service token](/analytics-alerts/alerts-by-name/remote-usage-of-an-aws-service-token.md)                                                                                                                                 |
| [Remote usage of an Azure Managed Identity token](/analytics-alerts/alerts-by-name/remote-usage-of-an-azure-managed-identity-token.md)                                                                                                           |
| [Remote usage of an Azure Service Principal token](/analytics-alerts/alerts-by-name/remote-usage-of-an-azure-service-principal-token.md)                                                                                                         |
| [Remote usage of AWS Lambda's role](/analytics-alerts/alerts-by-name/remote-usage-of-aws-lambda-s-role.md)                                                                                                                                       |
| [Remote usage of VM Service Account token](/analytics-alerts/alerts-by-name/remote-usage-of-vm-service-account-token.md)                                                                                                                         |
| [Remote WMI process execution](/analytics-alerts/alerts-by-name/remote-wmi-process-execution.md)                                                                                                                                                 |
| [Removal of an Azure Owner from an Application or Service Principal](/analytics-alerts/alerts-by-name/removal-of-an-azure-owner-from-an-application-or-service-principal.md)                                                                     |
| [Retrieval of cloud compute EC2 instance user data](/analytics-alerts/alerts-by-name/retrieval-of-cloud-compute-ec2-instance-user-data.md)                                                                                                       |
| [Retrieval of kubelet credentials](/analytics-alerts/alerts-by-name/retrieval-of-kubelet-credentials.md)                                                                                                                                         |
| [Run downloaded script using pipe](/analytics-alerts/alerts-by-name/run-downloaded-script-using-pipe.md)                                                                                                                                         |
| [Rundll32.exe executes a rare unsigned module](/analytics-alerts/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module.md)                                                                                                                 |
| [Rundll32.exe running with no command-line arguments](/analytics-alerts/alerts-by-name/rundll32-exe-running-with-no-command-line-arguments.md)                                                                                                   |
| [Rundll32.exe spawns conhost.exe](/analytics-alerts/alerts-by-name/rundll32-exe-spawns-conhost-exe.md)                                                                                                                                           |
| [S3 configuration deletion](/analytics-alerts/alerts-by-name/s3-configuration-deletion.md)                                                                                                                                                       |
| [SAAS - Email was reported by the user or administrator as a phishing attempt](/analytics-alerts/alerts-by-name/saas-email-was-reported-by-the-user-or-administrator-as-a-phishing-attempt.md)                                                   |
| [SaaS suspicious external domain user activity](/analytics-alerts/alerts-by-name/saas-suspicious-external-domain-user-activity.md)                                                                                                               |
| [SCCM log files enumeration](/analytics-alerts/alerts-by-name/sccm-log-files-enumeration.md)                                                                                                                                                     |
| [Scheduled Task hidden by registry modification](/analytics-alerts/alerts-by-name/scheduled-task-hidden-by-registry-modification.md)                                                                                                             |
| [Scrcons.exe Rare Child Process](/analytics-alerts/alerts-by-name/scrcons-exe-rare-child-process.md)                                                                                                                                             |
| [Screensaver process executed from Users or temporary folder](/analytics-alerts/alerts-by-name/screensaver-process-executed-from-users-or-temporary-folder.md)                                                                                   |
| [Script file added to startup-related Registry keys](/analytics-alerts/alerts-by-name/script-file-added-to-startup-related-registry-keys.md)                                                                                                     |
| [Scripting engine connected to a rare external host](/analytics-alerts/alerts-by-name/scripting-engine-connected-to-a-rare-external-host.md)                                                                                                     |
| [SecureBoot was disabled](/analytics-alerts/alerts-by-name/secureboot-was-disabled.md)                                                                                                                                                           |
| [Security object deletion in Google Workspace Admin Console](/analytics-alerts/alerts-by-name/security-object-deletion-in-google-workspace-admin-console.md)                                                                                     |
| [Security tools detection attempt](/analytics-alerts/alerts-by-name/security-tools-detection-attempt.md)                                                                                                                                         |
| [Sending unusual file(s) to an external address](/analytics-alerts/alerts-by-name/sending-unusual-file-s-to-an-external-address.md)                                                                                                              |
| [Sensitive account password reset attempt](/analytics-alerts/alerts-by-name/sensitive-account-password-reset-attempt.md)                                                                                                                         |
| [Sensitive browser credential files accessed by a rare non browser process](/analytics-alerts/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process.md)                                                       |
| [Sensitive Exchange mail sent to external users](/analytics-alerts/alerts-by-name/sensitive-exchange-mail-sent-to-external-users.md)                                                                                                             |
| [Serial console access was enabled in AWS account](/analytics-alerts/alerts-by-name/serial-console-access-was-enabled-in-aws-account.md)                                                                                                         |
| [Service execution via sc.exe](/analytics-alerts/alerts-by-name/service-execution-via-sc-exe.md)                                                                                                                                                 |
| [Service ticket request with a spoofed sAMAccountName](/analytics-alerts/alerts-by-name/service-ticket-request-with-a-spoofed-samaccountname.md)                                                                                                 |
| [SES Production Access Requested](/analytics-alerts/alerts-by-name/ses-production-access-requested.md)                                                                                                                                           |
| [Setting Windows Auto Logon by uncommon process](/analytics-alerts/alerts-by-name/setting-windows-auto-logon-by-uncommon-process.md)                                                                                                             |
| [Setuid and Setgid file bit manipulation](/analytics-alerts/alerts-by-name/setuid-and-setgid-file-bit-manipulation.md)                                                                                                                           |
| [SharePoint Site Collection admin group addition](/analytics-alerts/alerts-by-name/sharepoint-site-collection-admin-group-addition.md)                                                                                                           |
| [Short-lived Azure AD user account](/analytics-alerts/alerts-by-name/short-lived-azure-ad-user-account.md)                                                                                                                                       |
| [Short-lived user account](/analytics-alerts/alerts-by-name/short-lived-user-account.md)                                                                                                                                                         |
| [Signed process creates a scheduled task via file access](/analytics-alerts/alerts-by-name/signed-process-creates-a-scheduled-task-via-file-access.md)                                                                                           |
| [Signed process performed an unpopular DLL injection](/analytics-alerts/alerts-by-name/signed-process-performed-an-unpopular-dll-injection.md)                                                                                                   |
| [Signed process performed an unpopular injection](/analytics-alerts/alerts-by-name/signed-process-performed-an-unpopular-injection.md)                                                                                                           |
| [Single account excessively locked out](/analytics-alerts/alerts-by-name/single-account-excessively-locked-out.md)                                                                                                                               |
| [SMB Traffic from Non-Standard Process](/analytics-alerts/alerts-by-name/smb-traffic-from-non-standard-process.md)                                                                                                                               |
| [Soft delete of cloud storage configuration was disabled](/analytics-alerts/alerts-by-name/soft-delete-of-cloud-storage-configuration-was-disabled.md)                                                                                           |
| [Space after filename](/analytics-alerts/alerts-by-name/space-after-filename.md)                                                                                                                                                                 |
| [Spam Bot Traffic](/analytics-alerts/alerts-by-name/spam-bot-traffic.md)                                                                                                                                                                         |
| [SPNs cleared from a machine account](/analytics-alerts/alerts-by-name/spns-cleared-from-a-machine-account.md)                                                                                                                                   |
| [SSH authentication brute force attempts](/analytics-alerts/alerts-by-name/ssh-authentication-brute-force-attempts.md)                                                                                                                           |
| [SSO authentication attempt by a honey user](/analytics-alerts/alerts-by-name/sso-authentication-attempt-by-a-honey-user.md)                                                                                                                     |
| [SSO authentication by a machine account](/analytics-alerts/alerts-by-name/sso-authentication-by-a-machine-account.md)                                                                                                                           |
| [SSO authentication by a service account](/analytics-alerts/alerts-by-name/sso-authentication-by-a-service-account.md)                                                                                                                           |
| [SSO Brute Force](/analytics-alerts/alerts-by-name/sso-brute-force.md)                                                                                                                                                                           |
| [SSO Password Spray](/analytics-alerts/alerts-by-name/sso-password-spray.md)                                                                                                                                                                     |
| [SSO with abnormal operating system](/analytics-alerts/alerts-by-name/sso-with-abnormal-operating-system.md)                                                                                                                                     |
| [SSO with abnormal user agent](/analytics-alerts/alerts-by-name/sso-with-abnormal-user-agent.md)                                                                                                                                                 |
| [SSO with new operating system](/analytics-alerts/alerts-by-name/sso-with-new-operating-system.md)                                                                                                                                               |
| [Storage enumeration activity](/analytics-alerts/alerts-by-name/storage-enumeration-activity.md)                                                                                                                                                 |
| [Stored credentials exported using credwiz.exe](/analytics-alerts/alerts-by-name/stored-credentials-exported-using-credwiz-exe.md)                                                                                                               |
| [Subdomain Fuzzing](/analytics-alerts/alerts-by-name/subdomain-fuzzing.md)                                                                                                                                                                       |
| [Successful unusual guest user invitation](/analytics-alerts/alerts-by-name/successful-unusual-guest-user-invitation.md)                                                                                                                         |
| [Sudden spike in outbound email volume](/analytics-alerts/alerts-by-name/sudden-spike-in-outbound-email-volume.md)                                                                                                                               |
| [Sudoedit Brute force attempt](/analytics-alerts/alerts-by-name/sudoedit-brute-force-attempt.md)                                                                                                                                                 |
| [SUID/GUID permission discovery](/analytics-alerts/alerts-by-name/suid-guid-permission-discovery.md)                                                                                                                                             |
| [Suspicious .NET process loads an MSBuild DLL](/analytics-alerts/alerts-by-name/suspicious-net-process-loads-an-msbuild-dll.md)                                                                                                                  |
| [Suspicious access of the System Management Container](/analytics-alerts/alerts-by-name/suspicious-access-of-the-system-management-container.md)                                                                                                 |
| [Suspicious access to cloud credential files](/analytics-alerts/alerts-by-name/suspicious-access-to-cloud-credential-files.md)                                                                                                                   |
| [Suspicious access to Kubernetes API with kubelet credentials](/analytics-alerts/alerts-by-name/suspicious-access-to-kubernetes-api-with-kubelet-credentials.md)                                                                                 |
| [Suspicious access to shadow file](/analytics-alerts/alerts-by-name/suspicious-access-to-shadow-file.md)                                                                                                                                         |
| [Suspicious account attribute modification that matches that of another account](/analytics-alerts/alerts-by-name/suspicious-account-attribute-modification-that-matches-that-of-another-account.md)                                             |
| [Suspicious active setup registered](/analytics-alerts/alerts-by-name/suspicious-active-setup-registered.md)                                                                                                                                     |
| [Suspicious activity indicating a potential abuse of a cloud-native email service](/analytics-alerts/alerts-by-name/suspicious-activity-indicating-a-potential-abuse-of-a-cloud-native-email-service.md)                                         |
| [Suspicious activity on logging bucket](/analytics-alerts/alerts-by-name/suspicious-activity-on-logging-bucket.md)                                                                                                                               |
| [Suspicious AI Dataset Download](/analytics-alerts/alerts-by-name/suspicious-ai-dataset-download.md)                                                                                                                                             |
| [Suspicious AI Dataset Label Modification](/analytics-alerts/alerts-by-name/suspicious-ai-dataset-label-modification.md)                                                                                                                         |
| [Suspicious AI model usage from a Tor exit node](/analytics-alerts/alerts-by-name/suspicious-ai-model-usage-from-a-tor-exit-node.md)                                                                                                             |
| [Suspicious AMSI decode attempt](/analytics-alerts/alerts-by-name/suspicious-amsi-decode-attempt.md)                                                                                                                                             |
| [Suspicious API call from a Tor exit node](/analytics-alerts/alerts-by-name/suspicious-api-call-from-a-tor-exit-node.md)                                                                                                                         |
| [Suspicious authentication package registered](/analytics-alerts/alerts-by-name/suspicious-authentication-package-registered.md)                                                                                                                 |
| [Suspicious authentication with Azure Password Hash Sync user](/analytics-alerts/alerts-by-name/suspicious-authentication-with-azure-password-hash-sync-user.md)                                                                                 |
| [Suspicious AWS SSM parameters retrieval activity](/analytics-alerts/alerts-by-name/suspicious-aws-ssm-parameters-retrieval-activity.md)                                                                                                         |
| [Suspicious Azure AD interactive sign-in using PowerShell](/analytics-alerts/alerts-by-name/suspicious-azure-ad-interactive-sign-in-using-powershell.md)                                                                                         |
| [Suspicious Azure enumeration activity](/analytics-alerts/alerts-by-name/suspicious-azure-enumeration-activity.md)                                                                                                                               |
| [Suspicious brand affiliation detected](/analytics-alerts/alerts-by-name/suspicious-brand-affiliation-detected.md)                                                                                                                               |
| [Suspicious certificate template modification](/analytics-alerts/alerts-by-name/suspicious-certificate-template-modification.md)                                                                                                                 |
| [Suspicious Certutil AD CS contact](/analytics-alerts/alerts-by-name/suspicious-certutil-ad-cs-contact.md)                                                                                                                                       |
| [Suspicious certutil command line](/analytics-alerts/alerts-by-name/suspicious-certutil-command-line.md)                                                                                                                                         |
| [Suspicious cloud compute instance SSH keys modification attempt](/analytics-alerts/alerts-by-name/suspicious-cloud-compute-instance-ssh-keys-modification-attempt.md)                                                                           |
| [Suspicious cloud user data modification attempt followed by VM restart](/analytics-alerts/alerts-by-name/suspicious-cloud-user-data-modification-attempt-followed-by-vm-restart.md)                                                             |
| [Suspicious container orchestration job](/analytics-alerts/alerts-by-name/suspicious-container-orchestration-job.md)                                                                                                                             |
| [Suspicious container reconnaissance activity in a Kubernetes pod](/analytics-alerts/alerts-by-name/suspicious-container-reconnaissance-activity-in-a-kubernetes-pod.md)                                                                         |
| [Suspicious container runtime connection from within a Kubernetes Pod](/analytics-alerts/alerts-by-name/suspicious-container-runtime-connection-from-within-a-kubernetes-pod.md)                                                                 |
| [Suspicious curl user agent](/analytics-alerts/alerts-by-name/suspicious-curl-user-agent.md)                                                                                                                                                     |
| [Suspicious data encryption](/analytics-alerts/alerts-by-name/suspicious-data-encryption.md)                                                                                                                                                     |
| [Suspicious disablement of the Windows Firewall](/analytics-alerts/alerts-by-name/suspicious-disablement-of-the-windows-firewall.md)                                                                                                             |
| [Suspicious disablement of the Windows Firewall using PowerShell commands](/analytics-alerts/alerts-by-name/suspicious-disablement-of-the-windows-firewall-using-powershell-commands.md)                                                         |
| [Suspicious DKIM Result](/analytics-alerts/alerts-by-name/suspicious-dkim-result.md)                                                                                                                                                             |
| [Suspicious DMARC result](/analytics-alerts/alerts-by-name/suspicious-dmarc-result.md)                                                                                                                                                           |
| [Suspicious DNS traffic](/analytics-alerts/alerts-by-name/suspicious-dns-traffic.md)                                                                                                                                                             |
| [Suspicious dNSHostName attribute change to DC name](/analytics-alerts/alerts-by-name/suspicious-dnshostname-attribute-change-to-dc-name.md)                                                                                                     |
| [Suspicious docker image download from an unusual repository](/analytics-alerts/alerts-by-name/suspicious-docker-image-download-from-an-unusual-repository.md)                                                                                   |
| [Suspicious domain user account creation](/analytics-alerts/alerts-by-name/suspicious-domain-user-account-creation.md)                                                                                                                           |
| [Suspicious DotNet log file created](/analytics-alerts/alerts-by-name/suspicious-dotnet-log-file-created.md)                                                                                                                                     |
| [Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin](/analytics-alerts/alerts-by-name/suspicious-dump-of-ntds-dit-using-shadow-copy-with-ntdsutil-vssadmin.md)                                                                 |
| [Suspicious EBS snapshots deletion](/analytics-alerts/alerts-by-name/suspicious-ebs-snapshots-deletion.md)                                                                                                                                       |
| [Suspicious Encrypting File System Remote call (EFSRPC) to domain controller](/analytics-alerts/alerts-by-name/suspicious-encrypting-file-system-remote-call-efsrpc-to-domain-controller.md)                                                     |
| [Suspicious External RDP Login](/analytics-alerts/alerts-by-name/suspicious-external-rdp-login.md)                                                                                                                                               |
| [Suspicious failed HTTP request - potential Spring4Shell exploit](/analytics-alerts/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit.md)                                                                             |
| [Suspicious heavy allocation of compute resources - possible mining activity](/analytics-alerts/alerts-by-name/suspicious-heavy-allocation-of-compute-resources-possible-mining-activity.md)                                                     |
| [Suspicious hidden user created](/analytics-alerts/alerts-by-name/suspicious-hidden-user-created.md)                                                                                                                                             |
| [Suspicious HTTP parameters detected](/analytics-alerts/alerts-by-name/suspicious-http-parameters-detected.md)                                                                                                                                   |
| [Suspicious ICMP packet](/analytics-alerts/alerts-by-name/suspicious-icmp-packet.md)                                                                                                                                                             |
| [Suspicious ICMP traffic that resembles smurf attack](/analytics-alerts/alerts-by-name/suspicious-icmp-traffic-that-resembles-smurf-attack.md)                                                                                                   |
| [Suspicious identity downloaded multiple objects from a bucket](/analytics-alerts/alerts-by-name/suspicious-identity-downloaded-multiple-objects-from-a-bucket.md)                                                                               |
| [Suspicious Kerberos Pre-Auth Failures by Host](/analytics-alerts/alerts-by-name/suspicious-kerberos-pre-auth-failures-by-host.md)                                                                                                               |
| [Suspicious Kubernetes pod token access](/analytics-alerts/alerts-by-name/suspicious-kubernetes-pod-token-access.md)                                                                                                                             |
| [Suspicious LDAP queries followed by shared folder access](/analytics-alerts/alerts-by-name/suspicious-ldap-queries-followed-by-shared-folder-access.md)                                                                                         |
| [Suspicious LDAP search query executed](/analytics-alerts/alerts-by-name/suspicious-ldap-search-query-executed.md)                                                                                                                               |
| [Suspicious MFA request reported by user in Entra ID](/analytics-alerts/alerts-by-name/suspicious-mfa-request-reported-by-user-in-entra-id.md)                                                                                                   |
| [Suspicious ML Model Download](/analytics-alerts/alerts-by-name/suspicious-ml-model-download.md)                                                                                                                                                 |
| [Suspicious modification of the AdminSDHolder's ACL](/analytics-alerts/alerts-by-name/suspicious-modification-of-the-adminsdholder-s-acl.md)                                                                                                     |
| [Suspicious module load using direct syscall](/analytics-alerts/alerts-by-name/suspicious-module-load-using-direct-syscall.md)                                                                                                                   |
| [Suspicious Network Connection Originating from AWS SSM Agent](/analytics-alerts/alerts-by-name/suspicious-network-connection-originating-from-aws-ssm-agent.md)                                                                                 |
| [Suspicious NTLM authentication with machine account](/analytics-alerts/alerts-by-name/suspicious-ntlm-authentication-with-machine-account.md)                                                                                                   |
| [Suspicious objects encryption in an AWS bucket](/analytics-alerts/alerts-by-name/suspicious-objects-encryption-in-an-aws-bucket.md)                                                                                                             |
| [Suspicious PowerShell Command Line](/analytics-alerts/alerts-by-name/suspicious-powershell-command-line.md)                                                                                                                                     |
| [Suspicious PowerShell Enumeration of Running Processes](/analytics-alerts/alerts-by-name/suspicious-powershell-enumeration-of-running-processes.md)                                                                                             |
| [Suspicious PowerSploit's recon module (PowerView) net function was executed](/analytics-alerts/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed.md)                                                     |
| [Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts](/analytics-alerts/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-used-to-search-for-exposed-hosts.md)                                       |
| [Suspicious print processor registered](/analytics-alerts/alerts-by-name/suspicious-print-processor-registered.md)                                                                                                                               |
| [Suspicious Print System Remote Protocol usage by a process](/analytics-alerts/alerts-by-name/suspicious-print-system-remote-protocol-usage-by-a-process.md)                                                                                     |
| [Suspicious process accessed a site masquerading as Google](/analytics-alerts/alerts-by-name/suspicious-process-accessed-a-site-masquerading-as-google.md)                                                                                       |
| [Suspicious process accessed certificate files](/analytics-alerts/alerts-by-name/suspicious-process-accessed-certificate-files.md)                                                                                                               |
| [Suspicious process executed with a high integrity level](/analytics-alerts/alerts-by-name/suspicious-process-executed-with-a-high-integrity-level.md)                                                                                           |
| [Suspicious process execution from tmp folder](/analytics-alerts/alerts-by-name/suspicious-process-execution-from-tmp-folder.md)                                                                                                                 |
| [Suspicious process execution in a privileged container](/analytics-alerts/alerts-by-name/suspicious-process-execution-in-a-privileged-container.md)                                                                                             |
| [Suspicious process loads a known PowerShell module](/analytics-alerts/alerts-by-name/suspicious-process-loads-a-known-powershell-module.md)                                                                                                     |
| [Suspicious process modified RC script file](/analytics-alerts/alerts-by-name/suspicious-process-modified-rc-script-file.md)                                                                                                                     |
| [Suspicious Process Spawned by Adobe Reader](/analytics-alerts/alerts-by-name/suspicious-process-spawned-by-adobe-reader.md)                                                                                                                     |
| [Suspicious Process Spawned by wininit.exe](/analytics-alerts/alerts-by-name/suspicious-process-spawned-by-wininit-exe.md)                                                                                                                       |
| [Suspicious proxy environment variable setting](/analytics-alerts/alerts-by-name/suspicious-proxy-environment-variable-setting.md)                                                                                                               |
| [Suspicious reconnaissance using LDAP](/analytics-alerts/alerts-by-name/suspicious-reconnaissance-using-ldap.md)                                                                                                                                 |
| [Suspicious RunOnce Parent Process](/analytics-alerts/alerts-by-name/suspicious-runonce-parent-process.md)                                                                                                                                       |
| [Suspicious runonce.exe parent process](/analytics-alerts/alerts-by-name/suspicious-runonce-exe-parent-process.md)                                                                                                                               |
| [Suspicious SaaS API call from a Tor exit node](/analytics-alerts/alerts-by-name/suspicious-saas-api-call-from-a-tor-exit-node.md)                                                                                                               |
| [Suspicious sAMAccountName change](/analytics-alerts/alerts-by-name/suspicious-samaccountname-change.md)                                                                                                                                         |
| [Suspicious SearchProtocolHost.exe parent process](/analytics-alerts/alerts-by-name/suspicious-searchprotocolhost-exe-parent-process.md)                                                                                                         |
| [Suspicious secrets dump activity](/analytics-alerts/alerts-by-name/suspicious-secrets-dump-activity.md)                                                                                                                                         |
| [Suspicious sender exhibiting automated sending patterns](/analytics-alerts/alerts-by-name/suspicious-sender-exhibiting-automated-sending-patterns.md)                                                                                           |
| [Suspicious sending domain with sender address randomization](/analytics-alerts/alerts-by-name/suspicious-sending-domain-with-sender-address-randomization.md)                                                                                   |
| [Suspicious setspn.exe execution](/analytics-alerts/alerts-by-name/suspicious-setspn-exe-execution.md)                                                                                                                                           |
| [Suspicious SMB connection from domain controller](/analytics-alerts/alerts-by-name/suspicious-smb-connection-from-domain-controller.md)                                                                                                         |
| [Suspicious SPF Result](/analytics-alerts/alerts-by-name/suspicious-spf-result.md)                                                                                                                                                               |
| [Suspicious SSH Downgrade](/analytics-alerts/alerts-by-name/suspicious-ssh-downgrade.md)                                                                                                                                                         |
| [Suspicious sshpass command execution](/analytics-alerts/alerts-by-name/suspicious-sshpass-command-execution.md)                                                                                                                                 |
| [Suspicious SSO access from ASN](/analytics-alerts/alerts-by-name/suspicious-sso-access-from-asn.md)                                                                                                                                             |
| [Suspicious SSO authentication](/analytics-alerts/alerts-by-name/suspicious-sso-authentication.md)                                                                                                                                               |
| [Suspicious successful RDP connection to localhost](/analytics-alerts/alerts-by-name/suspicious-successful-rdp-connection-to-localhost.md)                                                                                                       |
| [Suspicious systemd timer activity](/analytics-alerts/alerts-by-name/suspicious-systemd-timer-activity.md)                                                                                                                                       |
| [Suspicious theme and sentiment in email](/analytics-alerts/alerts-by-name/suspicious-theme-and-sentiment-in-email.md)                                                                                                                           |
| [Suspicious time provider registered](/analytics-alerts/alerts-by-name/suspicious-time-provider-registered.md)                                                                                                                                   |
| [Suspicious Udev driver rule execution manipulation](/analytics-alerts/alerts-by-name/suspicious-udev-driver-rule-execution-manipulation.md)                                                                                                     |
| [Suspicious Unicode character detected in email](/analytics-alerts/alerts-by-name/suspicious-unicode-character-detected-in-email.md)                                                                                                             |
| [Suspicious usage of EC2 token](/analytics-alerts/alerts-by-name/suspicious-usage-of-ec2-token.md)                                                                                                                                               |
| [Suspicious usage of File Server Remote VSS Protocol (FSRVP)](/analytics-alerts/alerts-by-name/suspicious-usage-of-file-server-remote-vss-protocol-fsrvp.md)                                                                                     |
| [Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet](/analytics-alerts/alerts-by-name/suspicious-usage-of-microsoft-s-active-directory-powershell-module-remote-discovery-cmdlet.md)                     |
| [Svchost.exe loads a rare unsigned module](/analytics-alerts/alerts-by-name/svchost-exe-loads-a-rare-unsigned-module.md)                                                                                                                         |
| [System information discovery via psinfo.exe](/analytics-alerts/alerts-by-name/system-information-discovery-via-psinfo-exe.md)                                                                                                                   |
| [System profiling WMI query execution](/analytics-alerts/alerts-by-name/system-profiling-wmi-query-execution.md)                                                                                                                                 |
| [System shutdown or reboot](/analytics-alerts/alerts-by-name/system-shutdown-or-reboot.md)                                                                                                                                                       |
| [Tampering with Internet Explorer Protected Mode configuration](/analytics-alerts/alerts-by-name/tampering-with-internet-explorer-protected-mode-configuration.md)                                                                               |
| [Tampering with the Windows User Account Controls (UAC) configuration](/analytics-alerts/alerts-by-name/tampering-with-the-windows-user-account-controls-uac-configuration.md)                                                                   |
| [TGT request with a spoofed sAMAccountName - Event log](/analytics-alerts/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-event-log.md)                                                                                                 |
| [TGT request with a spoofed sAMAccountName - Network](/analytics-alerts/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-network.md)                                                                                                     |
| [The CA policy EditFlags was queried](/analytics-alerts/alerts-by-name/the-ca-policy-editflags-was-queried.md)                                                                                                                                   |
| [The Linux system firewall was disabled](/analytics-alerts/alerts-by-name/the-linux-system-firewall-was-disabled.md)                                                                                                                             |
| [Training simulation email detected](/analytics-alerts/alerts-by-name/training-simulation-email-detected.md)                                                                                                                                     |
| [Uncommon access to /etc/passwd](/analytics-alerts/alerts-by-name/uncommon-access-to-etc-passwd.md)                                                                                                                                              |
| [Uncommon access to cloud platforms' sensitive files by a scripting engine](/analytics-alerts/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine.md)                                                        |
| [Uncommon access to Microsoft Teams cookies files](/analytics-alerts/alerts-by-name/uncommon-access-to-microsoft-teams-cookies-files.md)                                                                                                         |
| [Uncommon access to Microsoft Teams credential files](/analytics-alerts/alerts-by-name/uncommon-access-to-microsoft-teams-credential-files.md)                                                                                                   |
| Uncommon AppleScript containing a potential defense-evasion command was executed via the command line                                                                                                                                            |
| [Uncommon AppleScript containing a potential obfuscation technique was executed](/analytics-alerts/alerts-by-name/uncommon-applescript-containing-a-potential-obfuscation-technique-was-executed.md)                                             |
| [Uncommon AppleScript containing a potential persistence command was executed via the command line](/analytics-alerts/alerts-by-name/uncommon-applescript-containing-a-potential-persistence-command-was-executed-via-the-command-line.md)       |
| Uncommon AppleScript containing a potential system information discovery command was executed via the command line                                                                                                                               |
| [Uncommon AppleScript designed to access credential files was executed via the command line](/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-credential-files-was-executed-via-the-command-line.md)                     |
| [Uncommon AppleScript designed to access cryptocurrency wallet data was executed via the command line](/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-cryptocurrency-wallet-data-was-executed-via-the-command-line.md) |
| [Uncommon AppleScript designed to access sensitive application data was executed via the command line](/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-access-sensitive-application-data-was-executed-via-the-command-line.md) |
| [Uncommon AppleScript designed to capture screen or clipboard data was executed via the command line](/analytics-alerts/alerts-by-name/uncommon-applescript-designed-to-capture-screen-or-clipboard-data-was-executed-via-the-command-line.md)   |
| [Uncommon AppleScript potentially utilizes credential-grabbing techniques to steal user passwords](/analytics-alerts/alerts-by-name/uncommon-applescript-potentially-utilizes-credential-grabbing-techniques-to-steal-user-passwords.md)         |
| [Uncommon AppleScript was executed via the command line to contact an external server](/analytics-alerts/alerts-by-name/uncommon-applescript-was-executed-via-the-command-line-to-contact-an-external-server.md)                                 |
| [Uncommon ARP cache listing via arp.exe](/analytics-alerts/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe.md)                                                                                                                             |
| [Uncommon AT task-job creation by user](/analytics-alerts/alerts-by-name/uncommon-at-task-job-creation-by-user.md)                                                                                                                               |
| [Uncommon attempt at discovering a sensitive file](/analytics-alerts/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file.md)                                                                                                         |
| [Uncommon attempt at grabbing credentials from a sensitive file](/analytics-alerts/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file.md)                                                                             |
| [Uncommon attempt to clear shell history](/analytics-alerts/alerts-by-name/uncommon-attempt-to-clear-shell-history.md)                                                                                                                           |
| [Uncommon Azure Cosmos DB master key read by identity](/analytics-alerts/alerts-by-name/uncommon-azure-cosmos-db-master-key-read-by-identity.md)                                                                                                 |
| [Uncommon browser extension loaded](/analytics-alerts/alerts-by-name/uncommon-browser-extension-loaded.md)                                                                                                                                       |
| [Uncommon cloud CLI tool usage](/analytics-alerts/alerts-by-name/uncommon-cloud-cli-tool-usage.md)                                                                                                                                               |
| [Uncommon communication to an instant messaging server](/analytics-alerts/alerts-by-name/uncommon-communication-to-an-instant-messaging-server.md)                                                                                               |
| [Uncommon creation or access operation of sensitive shadow copy](/analytics-alerts/alerts-by-name/uncommon-creation-or-access-operation-of-sensitive-shadow-copy.md)                                                                             |
| [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](/analytics-alerts/alerts-by-name/uncommon-dll-sideloading-from-a-logical-cd-rom-iso-device.md)                                                                                     |
| [Uncommon DotNet module load relationship](/analytics-alerts/alerts-by-name/uncommon-dotnet-module-load-relationship.md)                                                                                                                         |
| [Uncommon driver loaded](/analytics-alerts/alerts-by-name/uncommon-driver-loaded.md)                                                                                                                                                             |
| [Uncommon execution of ODBCConf](/analytics-alerts/alerts-by-name/uncommon-execution-of-odbcconf.md)                                                                                                                                             |
| [Uncommon file access over WebDAV](/analytics-alerts/alerts-by-name/uncommon-file-access-over-webdav.md)                                                                                                                                         |
| [Uncommon GetClipboardData API function invocation of a possible information stealer](/analytics-alerts/alerts-by-name/uncommon-getclipboarddata-api-function-invocation-of-a-possible-information-stealer.md)                                   |
| [Uncommon increase in Azure Microsoft Graph API request sizes](/analytics-alerts/alerts-by-name/uncommon-increase-in-azure-microsoft-graph-api-request-sizes.md)                                                                                 |
| [Uncommon IP Configuration Listing via ipconfig.exe](/analytics-alerts/alerts-by-name/uncommon-ip-configuration-listing-via-ipconfig-exe.md)                                                                                                     |
| [Uncommon jsp file write by a Java process](/analytics-alerts/alerts-by-name/uncommon-jsp-file-write-by-a-java-process.md)                                                                                                                       |
| [Uncommon kernel module load](/analytics-alerts/alerts-by-name/uncommon-kernel-module-load.md)                                                                                                                                                   |
| [Uncommon Launch Agent persistency was registered or modified](/analytics-alerts/alerts-by-name/uncommon-launch-agent-persistency-was-registered-or-modified.md)                                                                                 |
| [Uncommon Launch Daemon persistency was registered or modified](/analytics-alerts/alerts-by-name/uncommon-launch-daemon-persistency-was-registered-or-modified.md)                                                                               |
| [Uncommon Linux process communication to a rare external host](/analytics-alerts/alerts-by-name/uncommon-linux-process-communication-to-a-rare-external-host.md)                                                                                 |
| [Uncommon Linux remote shell command execution](/analytics-alerts/alerts-by-name/uncommon-linux-remote-shell-command-execution.md)                                                                                                               |
| [Uncommon Linux shell command execution](/analytics-alerts/alerts-by-name/uncommon-linux-shell-command-execution.md)                                                                                                                             |
| [Uncommon local scheduled task creation via schtasks.exe](/analytics-alerts/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe.md)                                                                                           |
| [Uncommon login item persistency was registered or modified](/analytics-alerts/alerts-by-name/uncommon-login-item-persistency-was-registered-or-modified.md)                                                                                     |
| [Uncommon macOS process communication to a rare external host](/analytics-alerts/alerts-by-name/uncommon-macos-process-communication-to-a-rare-external-host.md)                                                                                 |
| [Uncommon macOS shell command execution](/analytics-alerts/alerts-by-name/uncommon-macos-shell-command-execution.md)                                                                                                                             |
| [Uncommon Managed Object Format (MOF) compiler usage](/analytics-alerts/alerts-by-name/uncommon-managed-object-format-mof-compiler-usage.md)                                                                                                     |
| [Uncommon msiexec execution of an arbitrary file from a remote location](/analytics-alerts/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location.md)                                                             |
| [Uncommon net group command execution](/analytics-alerts/alerts-by-name/uncommon-net-group-command-execution.md)                                                                                                                                 |
| [Uncommon net localgroup command execution](/analytics-alerts/alerts-by-name/uncommon-net-localgroup-command-execution.md)                                                                                                                       |
| [Uncommon network tunnel creation](/analytics-alerts/alerts-by-name/uncommon-network-tunnel-creation.md)                                                                                                                                         |
| [Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer](/analytics-alerts/alerts-by-name/uncommon-ntwritevirtualmemoryremote-api-invocation-with-a-pe-header-buffer.md)                                                     |
| [Uncommon PowerShell commands used to create or alter scheduled task parameters](/analytics-alerts/alerts-by-name/uncommon-powershell-commands-used-to-create-or-alter-scheduled-task-parameters.md)                                             |
| [Uncommon RDP connection](/analytics-alerts/alerts-by-name/uncommon-rdp-connection.md)                                                                                                                                                           |
| [Uncommon recurring rare external host access](/analytics-alerts/alerts-by-name/uncommon-recurring-rare-external-host-access.md)                                                                                                                 |
| [Uncommon remote monitoring and management tool](/analytics-alerts/alerts-by-name/uncommon-remote-monitoring-and-management-tool.md)                                                                                                             |
| [Uncommon remote scheduled task creation](/analytics-alerts/alerts-by-name/uncommon-remote-scheduled-task-creation.md)                                                                                                                           |
| [Uncommon remote service start via sc.exe](/analytics-alerts/alerts-by-name/uncommon-remote-service-start-via-sc-exe.md)                                                                                                                         |
| [Uncommon reverse SSH tunnel to external domain/ip](/analytics-alerts/alerts-by-name/uncommon-reverse-ssh-tunnel-to-external-domain-ip.md)                                                                                                       |
| [Uncommon routing table listing via route.exe](/analytics-alerts/alerts-by-name/uncommon-routing-table-listing-via-route-exe.md)                                                                                                                 |
| [Uncommon Security Support Provider (SSP) registered via a registry key](/analytics-alerts/alerts-by-name/uncommon-security-support-provider-ssp-registered-via-a-registry-key.md)                                                               |
| [Uncommon sensitive filesystem registry hive access](/analytics-alerts/alerts-by-name/uncommon-sensitive-filesystem-registry-hive-access.md)                                                                                                     |
| [Uncommon sensitive registry hive dump](/analytics-alerts/alerts-by-name/uncommon-sensitive-registry-hive-dump.md)                                                                                                                               |
| [Uncommon Service Create/Config](/analytics-alerts/alerts-by-name/uncommon-service-create-config.md)                                                                                                                                             |
| [Uncommon service stop operation](/analytics-alerts/alerts-by-name/uncommon-service-stop-operation.md)                                                                                                                                           |
| [Uncommon SetWindowsHookEx API invocation of a possible keylogger](/analytics-alerts/alerts-by-name/uncommon-setwindowshookex-api-invocation-of-a-possible-keylogger.md)                                                                         |
| [Uncommon signed process execution by scheduled task](/analytics-alerts/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task.md)                                                                                                   |
| [Uncommon SQL like command line](/analytics-alerts/alerts-by-name/uncommon-sql-like-command-line.md)                                                                                                                                             |
| [Uncommon SSH session was established](/analytics-alerts/alerts-by-name/uncommon-ssh-session-was-established.md)                                                                                                                                 |
| [Uncommon URL domain(s) in your organization detected in email](/analytics-alerts/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email.md)                                                                                |
| [Uncommon user management via net.exe](/analytics-alerts/alerts-by-name/uncommon-user-management-via-net-exe.md)                                                                                                                                 |
| [Uncommon VNC server communication](/analytics-alerts/alerts-by-name/uncommon-vnc-server-communication.md)                                                                                                                                       |
| [Uncommon WPAD queries](/analytics-alerts/alerts-by-name/uncommon-wpad-queries.md)                                                                                                                                                               |
| [Unicode RTL Override Character](/analytics-alerts/alerts-by-name/unicode-rtl-override-character.md)                                                                                                                                             |
| [Unique client computer model was detected via MS-Update protocol](/analytics-alerts/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol.md)                                                                         |
| [Unknown DLL was added to the AD FS Global Assembly Cache path](/analytics-alerts/alerts-by-name/unknown-dll-was-added-to-the-ad-fs-global-assembly-cache-path.md)                                                                               |
| [Unpopular rsync process execution](/analytics-alerts/alerts-by-name/unpopular-rsync-process-execution.md)                                                                                                                                       |
| [Unprivileged process opened a registry hive](/analytics-alerts/alerts-by-name/unprivileged-process-opened-a-registry-hive.md)                                                                                                                   |
| [Unrecognized internal address (AAD mismatch)](/analytics-alerts/alerts-by-name/unrecognized-internal-address-aad-mismatch.md)                                                                                                                   |
| [Unsigned and unpopular process performed a DLL injection](/analytics-alerts/alerts-by-name/unsigned-and-unpopular-process-performed-a-dll-injection.md)                                                                                         |
| [Unsigned and unpopular process performed an injection](/analytics-alerts/alerts-by-name/unsigned-and-unpopular-process-performed-an-injection.md)                                                                                               |
| [Unsigned DLL Hijack into a Microsoft process](/analytics-alerts/alerts-by-name/unsigned-dll-hijack-into-a-microsoft-process.md)                                                                                                                 |
| [Unsigned DLL Side-Loading](/analytics-alerts/alerts-by-name/unsigned-dll-side-loading.md)                                                                                                                                                       |
| [Unsigned process creates a scheduled task via file access](/analytics-alerts/alerts-by-name/unsigned-process-creates-a-scheduled-task-via-file-access.md)                                                                                       |
| [Unsigned process injecting into a Windows system binary with no command line](/analytics-alerts/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line.md)                                                 |
| [Untrusted process contacted LLM API](/analytics-alerts/alerts-by-name/untrusted-process-contacted-llm-api.md)                                                                                                                                   |
| [Unusual access to Microsoft 365 storage services](/analytics-alerts/alerts-by-name/unusual-access-to-microsoft-365-storage-services.md)                                                                                                         |
| [Unusual access to the AD Sync credential files](/analytics-alerts/alerts-by-name/unusual-access-to-the-ad-sync-credential-files.md)                                                                                                             |
| [Unusual access to the Windows Internal Database on an ADFS server](/analytics-alerts/alerts-by-name/unusual-access-to-the-windows-internal-database-on-an-adfs-server.md)                                                                       |
| [Unusual ADConnect database file access](/analytics-alerts/alerts-by-name/unusual-adconnect-database-file-access.md)                                                                                                                             |
| [Unusual ADFS Remote Synchronization network connections from non-ADFS server](/analytics-alerts/alerts-by-name/unusual-adfs-remote-synchronization-network-connections-from-non-adfs-server.md)                                                 |
| [Unusual AI dataset modification](/analytics-alerts/alerts-by-name/unusual-ai-dataset-modification.md)                                                                                                                                           |
| [Unusual AI Knowledge Base Modification](/analytics-alerts/alerts-by-name/unusual-ai-knowledge-base-modification.md)                                                                                                                             |
| [Unusual AI model invocation](/analytics-alerts/alerts-by-name/unusual-ai-model-invocation.md)                                                                                                                                                   |
| [Unusual AI RAG Knowledge Base Modification](/analytics-alerts/alerts-by-name/unusual-ai-rag-knowledge-base-modification.md)                                                                                                                     |
| [Unusual attachment volume in outbound emails](/analytics-alerts/alerts-by-name/unusual-attachment-volume-in-outbound-emails.md)                                                                                                                 |
| [Unusual AWS Bedrock model access request](/analytics-alerts/alerts-by-name/unusual-aws-bedrock-model-access-request.md)                                                                                                                         |
| [Unusual AWS CLI/SDK activity](/analytics-alerts/alerts-by-name/unusual-aws-cli-sdk-activity.md)                                                                                                                                                 |
| [Unusual AWS credentials creation](/analytics-alerts/alerts-by-name/unusual-aws-credentials-creation.md)                                                                                                                                         |
| [Unusual AWS S3 objects deletion](/analytics-alerts/alerts-by-name/unusual-aws-s3-objects-deletion.md)                                                                                                                                           |
| [Unusual AWS SageMaker notebook access](/analytics-alerts/alerts-by-name/unusual-aws-sagemaker-notebook-access.md)                                                                                                                               |
| [Unusual AWS systems manager activity](/analytics-alerts/alerts-by-name/unusual-aws-systems-manager-activity.md)                                                                                                                                 |
| [Unusual AWS user added to group](/analytics-alerts/alerts-by-name/unusual-aws-user-added-to-group.md)                                                                                                                                           |
| [Unusual Azure AD sync module load](/analytics-alerts/alerts-by-name/unusual-azure-ad-sync-module-load.md)                                                                                                                                       |
| [Unusual certificate management activity](/analytics-alerts/alerts-by-name/unusual-certificate-management-activity.md)                                                                                                                           |
| [Unusual CertLog Remote File Write](/analytics-alerts/alerts-by-name/unusual-certlog-remote-file-write.md)                                                                                                                                       |
| [Unusual CIM repository file access](/analytics-alerts/alerts-by-name/unusual-cim-repository-file-access.md)                                                                                                                                     |
| [Unusual cloud identity impersonation](/analytics-alerts/alerts-by-name/unusual-cloud-identity-impersonation.md)                                                                                                                                 |
| [Unusual cloud Instance Metadata Service (IMDS) access](/analytics-alerts/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access.md)                                                                                                 |
| [Unusual compressed file password protection](/analytics-alerts/alerts-by-name/unusual-compressed-file-password-protection.md)                                                                                                                   |
| [Unusual Conditional Access operation for an identity](/analytics-alerts/alerts-by-name/unusual-conditional-access-operation-for-an-identity.md)                                                                                                 |
| [Unusual cross projects activity](/analytics-alerts/alerts-by-name/unusual-cross-projects-activity.md)                                                                                                                                           |
| [Unusual DB process spawning a shell](/analytics-alerts/alerts-by-name/unusual-db-process-spawning-a-shell.md)                                                                                                                                   |
| [Unusual display name in From header](/analytics-alerts/alerts-by-name/unusual-display-name-in-from-header.md)                                                                                                                                   |
| [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](/analytics-alerts/alerts-by-name/unusual-encrypting-file-system-remote-call-efsrpc-to-domain-controller.md)                                                           |
| [Unusual exec into a Kubernetes Pod](/analytics-alerts/alerts-by-name/unusual-exec-into-a-kubernetes-pod.md)                                                                                                                                     |
| [Unusual file-sharing links for mailbox owner](/analytics-alerts/alerts-by-name/unusual-file-sharing-links-for-mailbox-owner.md)                                                                                                                 |
| [Unusual hostname for the sending mail server in the email headers](/analytics-alerts/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers.md)                                                                       |
| [Unusual IAM enumeration activity by a non-user Identity](/analytics-alerts/alerts-by-name/unusual-iam-enumeration-activity-by-a-non-user-identity.md)                                                                                           |
| [Unusual Identity and Access Management (IAM) activity](/analytics-alerts/alerts-by-name/unusual-identity-and-access-management-iam-activity.md)                                                                                                 |
| [Unusual internal access to network device management interface](/analytics-alerts/alerts-by-name/unusual-internal-access-to-network-device-management-interface.md)                                                                             |
| [Unusual key management activity](/analytics-alerts/alerts-by-name/unusual-key-management-activity.md)                                                                                                                                           |
| [Unusual Kubernetes dashboard communication from a pod](/analytics-alerts/alerts-by-name/unusual-kubernetes-dashboard-communication-from-a-pod.md)                                                                                               |
| [Unusual Kubernetes secret access](/analytics-alerts/alerts-by-name/unusual-kubernetes-secret-access.md)                                                                                                                                         |
| [Unusual Kubernetes service account file read](/analytics-alerts/alerts-by-name/unusual-kubernetes-service-account-file-read.md)                                                                                                                 |
| [Unusual Lolbins Process Spawned by InstallUtil.exe](/analytics-alerts/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe.md)                                                                                                     |
| [Unusual multi-region AWS Resource Explorer searches](/analytics-alerts/alerts-by-name/unusual-multi-region-aws-resource-explorer-searches.md)                                                                                                   |
| [Unusual Netsh PortProxy rule](/analytics-alerts/alerts-by-name/unusual-netsh-portproxy-rule.md)                                                                                                                                                 |
| [Unusual process access to ld.so.preload file](/analytics-alerts/alerts-by-name/unusual-process-access-to-ld-so-preload-file.md)                                                                                                                 |
| [Unusual process accessed a crypto wallet's files](/analytics-alerts/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files.md)                                                                                                         |
| [Unusual process accessed a macOS notes DB file](/analytics-alerts/alerts-by-name/unusual-process-accessed-a-macos-notes-db-file.md)                                                                                                             |
| [Unusual process accessed a messaging app's files](/analytics-alerts/alerts-by-name/unusual-process-accessed-a-messaging-app-s-files.md)                                                                                                         |
| [Unusual process accessed a web browser history file](/analytics-alerts/alerts-by-name/unusual-process-accessed-a-web-browser-history-file.md)                                                                                                   |
| [Unusual process accessed FTP Client credentials](/analytics-alerts/alerts-by-name/unusual-process-accessed-ftp-client-credentials.md)                                                                                                           |
| [Unusual process accessed the PowerShell history file](/analytics-alerts/alerts-by-name/unusual-process-accessed-the-powershell-history-file.md)                                                                                                 |
| [Unusual process accessed web browser cookies](/analytics-alerts/alerts-by-name/unusual-process-accessed-web-browser-cookies.md)                                                                                                                 |
| [Unusual process accessed web browser credentials](/analytics-alerts/alerts-by-name/unusual-process-accessed-web-browser-credentials.md)                                                                                                         |
| [Unusual process executed by AWS Systems Manager](/analytics-alerts/alerts-by-name/unusual-process-executed-by-aws-systems-manager.md)                                                                                                           |
| [Unusual Process Spawned by Nginx in Ingress-Nginx pod](/analytics-alerts/alerts-by-name/unusual-process-spawned-by-nginx-in-ingress-nginx-pod.md)                                                                                               |
| [Unusual resource access by Azure application](/analytics-alerts/alerts-by-name/unusual-resource-access-by-azure-application.md)                                                                                                                 |
| [Unusual resource modification by newly seen IAM user](/analytics-alerts/alerts-by-name/unusual-resource-modification-by-newly-seen-iam-user.md)                                                                                                 |
| [Unusual secret management activity](/analytics-alerts/alerts-by-name/unusual-secret-management-activity.md)                                                                                                                                     |
| [Unusual sender IP subnet](/analytics-alerts/alerts-by-name/unusual-sender-ip-subnet.md)                                                                                                                                                         |
| [Unusual SSH Activity](/analytics-alerts/alerts-by-name/unusual-ssh-activity.md)                                                                                                                                                                 |
| [Unusual SSH activity that resembles SSH proxy](/analytics-alerts/alerts-by-name/unusual-ssh-activity-that-resembles-ssh-proxy.md)                                                                                                               |
| [Unusual URL(s) sent by a brand were observed in the email](/analytics-alerts/alerts-by-name/unusual-url-s-sent-by-a-brand-were-observed-in-the-email.md)                                                                                        |
| [Unusual use of a 'SysInternals' tool](/analytics-alerts/alerts-by-name/unusual-use-of-a-sysinternals-tool.md)                                                                                                                                   |
| [Unusual user account enablement](/analytics-alerts/alerts-by-name/unusual-user-account-enablement.md)                                                                                                                                           |
| [Unusual user account unlock](/analytics-alerts/alerts-by-name/unusual-user-account-unlock.md)                                                                                                                                                   |
| [Unusual user-agent for a cloud identity](/analytics-alerts/alerts-by-name/unusual-user-agent-for-a-cloud-identity.md)                                                                                                                           |
| [Unusual weak authentication by user](/analytics-alerts/alerts-by-name/unusual-weak-authentication-by-user.md)                                                                                                                                   |
| [Unverified domain added to Azure AD](/analytics-alerts/alerts-by-name/unverified-domain-added-to-azure-ad.md)                                                                                                                                   |
| [Upload pattern that resembles Peer to Peer traffic](/analytics-alerts/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic.md)                                                                                                     |
| [Usage of homograph characters detected in an email](/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email.md)                                                                                                     |
| [Usage of homograph characters detected in an email attachment(s) name](/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name.md)                                                                |
| [Usage of homograph characters detected in an email's from header](/analytics-alerts/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header.md)                                                                         |
| [User accessed multiple O365 AIP sensitive files](/analytics-alerts/alerts-by-name/user-accessed-multiple-o365-aip-sensitive-files.md)                                                                                                           |
| [User accessed SaaS resource via anonymous link](/analytics-alerts/alerts-by-name/user-accessed-saas-resource-via-anonymous-link.md)                                                                                                             |
| [User account delegation change](/analytics-alerts/alerts-by-name/user-account-delegation-change.md)                                                                                                                                             |
| [User added a new device to Okta Verify instance](/analytics-alerts/alerts-by-name/user-added-a-new-device-to-okta-verify-instance.md)                                                                                                           |
| [User added SID History to an account](/analytics-alerts/alerts-by-name/user-added-sid-history-to-an-account.md)                                                                                                                                 |
| [User added to a group and removed](/analytics-alerts/alerts-by-name/user-added-to-a-group-and-removed.md)                                                                                                                                       |
| [User added to the SMS Admins local group](/analytics-alerts/alerts-by-name/user-added-to-the-sms-admins-local-group.md)                                                                                                                         |
| [User and Group Enumeration via SAMR](/analytics-alerts/alerts-by-name/user-and-group-enumeration-via-samr.md)                                                                                                                                   |
| [User attempted to connect from a suspicious country](/analytics-alerts/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country.md)                                                                                                   |
| [User collected remote shared files in an archive](/analytics-alerts/alerts-by-name/user-collected-remote-shared-files-in-an-archive.md)                                                                                                         |
| [User discovery via WMI query execution](/analytics-alerts/alerts-by-name/user-discovery-via-wmi-query-execution.md)                                                                                                                             |
| [User exported multiple messages in Microsoft Teams via Graph API](/analytics-alerts/alerts-by-name/user-exported-multiple-messages-in-microsoft-teams-via-graph-api.md)                                                                         |
| [User installed an application in Microsoft Teams via Graph API](/analytics-alerts/alerts-by-name/user-installed-an-application-in-microsoft-teams-via-graph-api.md)                                                                             |
| [User moved Exchange sent messages to deleted items](/analytics-alerts/alerts-by-name/user-moved-exchange-sent-messages-to-deleted-items.md)                                                                                                     |
| [User sent messages in Microsoft Teams to multiple conversations via Graph API](/analytics-alerts/alerts-by-name/user-sent-messages-in-microsoft-teams-to-multiple-conversations-via-graph-api.md)                                               |
| [User set insecure CA registry setting for global SANs](/analytics-alerts/alerts-by-name/user-set-insecure-ca-registry-setting-for-global-sans.md)                                                                                               |
| [User signed in to an application via Power Automate for the first time](/analytics-alerts/alerts-by-name/user-signed-in-to-an-application-via-power-automate-for-the-first-time.md)                                                             |
| [VM Detection attempt](/analytics-alerts/alerts-by-name/vm-detection-attempt.md)                                                                                                                                                                 |
| [VM Detection attempt on Linux](/analytics-alerts/alerts-by-name/vm-detection-attempt-on-linux.md)                                                                                                                                               |
| [VPN access with an abnormal operating system](/analytics-alerts/alerts-by-name/vpn-access-with-an-abnormal-operating-system.md)                                                                                                                 |
| [VPN login attempt by a honey user](/analytics-alerts/alerts-by-name/vpn-login-attempt-by-a-honey-user.md)                                                                                                                                       |
| [VPN login Brute-Force attempt](/analytics-alerts/alerts-by-name/vpn-login-brute-force-attempt.md)                                                                                                                                               |
| [VPN login by a dormant user](/analytics-alerts/alerts-by-name/vpn-login-by-a-dormant-user.md)                                                                                                                                                   |
| [VPN login by a service account](/analytics-alerts/alerts-by-name/vpn-login-by-a-service-account.md)                                                                                                                                             |
| [VPN Login Password Spray](/analytics-alerts/alerts-by-name/vpn-login-password-spray.md)                                                                                                                                                         |
| [VPN login with a machine account](/analytics-alerts/alerts-by-name/vpn-login-with-a-machine-account.md)                                                                                                                                         |
| [Vulnerable certificate template loaded](/analytics-alerts/alerts-by-name/vulnerable-certificate-template-loaded.md)                                                                                                                             |
| [Wbadmin deleted files in quiet mode](/analytics-alerts/alerts-by-name/wbadmin-deleted-files-in-quiet-mode.md)                                                                                                                                   |
| [Weakly-Encrypted Kerberos TGT Response](/analytics-alerts/alerts-by-name/weakly-encrypted-kerberos-tgt-response.md)                                                                                                                             |
| [Weakly-Encrypted Kerberos Ticket Requested](/analytics-alerts/alerts-by-name/weakly-encrypted-kerberos-ticket-requested.md)                                                                                                                     |
| [Web server CGO executed a process following a potential Webshell dropped](/analytics-alerts/alerts-by-name/web-server-cgo-executed-a-process-following-a-potential-webshell-dropped.md)                                                         |
| [Web server CGO executed an uncommon process](/analytics-alerts/alerts-by-name/web-server-cgo-executed-an-uncommon-process.md)                                                                                                                   |
| [WebDAV drive mounted from net.exe over HTTPS](/analytics-alerts/alerts-by-name/webdav-drive-mounted-from-net-exe-over-https.md)                                                                                                                 |
| [Well-known brand in sender headers with header inconsistencies](/analytics-alerts/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies.md)                                                                             |
| [Windows CGO, actor and action processes with anomalous characteristics](/analytics-alerts/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics.md)                                                              |
| [Windows CGO, actor process and action module with anomalous characteristics](/analytics-alerts/alerts-by-name/windows-cgo-actor-process-and-action-module-with-anomalous-characteristics.md)                                                    |
| [Windows Event Log was cleared using wevtutil.exe](/analytics-alerts/alerts-by-name/windows-event-log-was-cleared-using-wevtutil-exe.md)                                                                                                         |
| [Windows event logs were cleared with PowerShell](/analytics-alerts/alerts-by-name/windows-event-logs-were-cleared-with-powershell.md)                                                                                                           |
| [Windows Installer exploitation for local privilege escalation](/analytics-alerts/alerts-by-name/windows-installer-exploitation-for-local-privilege-escalation.md)                                                                               |
| [Windows LOLBIN executable connected to a rare external host](/analytics-alerts/alerts-by-name/windows-lolbin-executable-connected-to-a-rare-external-host.md)                                                                                   |
| [WmiPrvSe.exe Rare Child Command Line](/analytics-alerts/alerts-by-name/wmiprvse-exe-rare-child-command-line.md)                                                                                                                                 |
| [Wscript/Cscript loads .NET DLLs](/analytics-alerts/alerts-by-name/wscript-cscript-loads-net-dlls.md)                                                                                                                                            |
| [Wsmprovhost.exe Rare Child Process](/analytics-alerts/alerts-by-name/wsmprovhost-exe-rare-child-process.md)                                                                                                                                     |
| [X-Forefront-Antispam-Report has flagged this email as a potential threat](/analytics-alerts/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat.md)                                                         |


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/analytics-alerts/alerts-by-name.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
