> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-31.md).

# 2025.12.31

### Release date: 11-January-2026

### Summary

#### Added

* **20 Detectors:** 5 Low, 15 Informational
* **27 Variations:** 2 High, 6 Medium, 18 Low, 1 Informational

#### Removed

* **1 Detector:** 1 Informational
* **2 Variations:** 1 Low, 1 Informational

#### Modified Logic

* **1125 Detectors:** 20 High, 85 Medium, 291 Low, 729 Informational
* **69 Variations:** 4 High, 17 Medium, 28 Low, 20 Informational

### Added

* \[Informational] [Uncommon login item persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-login-item-persistency-was-registered-or-modified)
  * \[High] Uncommon login item persistency was registered or modified by a security testing tool
  * \[Low] Uncommon login item persistency was registered or modified by an invalidly signed actor process
  * \[Low] Uncommon login item persistency was registered or modified by an invalidly signed causality process
  * \[Low] Uncommon login item persistency was registered or modified while using osascript
* \[Informational] [Uncommon process communication to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[High] Uncommon process communication to a rare external host by an automated penetration testing tool
  * \[Medium] Uncommon process communication to a rare external host related to LOTTunnels
  * \[Medium] Uncommon process communication to a rare external host with a possible crypto mining tool for the first time
  * \[Low] Uncommon process communication to a rare external host involving a code sharing website
  * \[Low] Uncommon process communication to a rare external host with a possible exfiltration tool
  * \[Low] Uncommon process communication to a rare external host with a rare domain public suffix
  * \[Low] Uncommon process communication to a rare external host with an external IP in the command line
  * \[Low] Uncommon process communication to a rare external host with global anomaly detection
* \[Low] [GCP IAM deny policy creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-iam-deny-policy-creation)
  * \[Medium] Unusual GCP IAM deny policy creation
* \[Low] [GCP sensitive role granted to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-role-granted-to-group)
  * \[Medium] GCP sensitive role granted to group
* \[Low] [Mount command was executed from within a Kubernetes pod to list all the attached filesystems](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mount-command-was-executed-from-within-a-kubernetes-pod-to-list-all-the-attached-filesystems)
  * \[Medium] Unusual mount command was executed from within a Kubernetes pod to list all the attached filesystems
* \[Informational] [VPN Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-password-spray)
  * \[Medium] Successful VPN Password Spray Threat Detected with unusual characteristics
  * \[Low] VPN login password spray with unusual characteristics
* \[Informational] [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server)
  * \[Low] Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server where both the User Agent and the HTTP Server are rare
* \[Informational] [Access to Kubernetes CA certificate file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubernetes-ca-certificate-file)
  * \[Low] Access to Kubernetes CA certificate file by an unusual process
* \[Informational] [Access to kubelet credentials file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubelet-credentials-file)
  * \[Low] Access to kubelet credentials file by an unusual process
* \[Low] [An executable was written and executed by a web server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-executable-was-written-and-executed-by-a-web-server)
* \[Informational] [Local group enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration)
  * \[Low] Local group enumeration for the first time
  * \[Low] Local group enumeration using a builtin Windows binary
* \[Informational] [Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-ntlm-relay-attack-against-a-microsoft-configuration-manager-site-server)
  * \[Low] Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server using a vulnerable package
* \[Informational] [Retrieval of kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/retrieval-of-kubelet-credentials)
  * \[Low] Retrieval of kubelet credentials by an unusual process
* \[Informational] [SES Production Access Requested](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ses-production-access-requested)
  * \[Low] SES Production Access Requested by an unusual identity
* \[Low] [Suspicious activity on logging bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-activity-on-logging-bucket)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
  * \[Low] Unusual display name in the From header containing an embedded URL
  * \[Informational] Unusual display name in the From header that is identical to the email address
* \[Informational] [GCP service account impersonation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-impersonation-attempt)
* \[Informational] [Local user account creation by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-account-creation-by-a-machine-account)
* \[Informational] [Unusual user-agent for a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-agent-for-a-cloud-identity)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)

### Removed

* \[Informational] Unusual resource modification/creation
  * \[Low] Unusual resource modification/creation by newly seen user
  * \[Informational] Unusual resource modification/creation by an identity with high administrative activity

### Modified Logic

* \[High] [A Successful VPN connection from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-vpn-connection-from-tor)
* \[High] [A Successful login from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-login-from-tor)
* \[High] [A successful SSO sign-in from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-sso-sign-in-from-tor)
* \[High] [Bronze-Bit exploit](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bronze-bit-exploit)
* \[High] [Copy a process memory file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-process-memory-file)
* \[Medium -> High] [Hydra Password Brute-Force Tool Execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hydra-password-brute-force-tool-execution)
  * \[Medium -> High] Hydra Password Brute-Force Tool Execution from a Kubernetes pod - Modified Metadata
* \[High] [Memory dumping with comsvcs.dll](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/memory-dumping-with-comsvcs-dll)
* \[High] [Mimikatz command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mimikatz-command-line-arguments)
* \[High] [Netcat makes or gets connections](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/netcat-makes-or-gets-connections)
* \[High] [Possible Distributed File System Namespace Management (DFSNM) abuse](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-distributed-file-system-namespace-management-dfsnm-abuse)
* \[High] [Possible brute force or configuration change attempt on cytool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-or-configuration-change-attempt-on-cytool)
* \[High] [PowerShell used to remove mailbox export request logs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-used-to-remove-mailbox-export-request-logs)
* \[High] [Remote service command execution from an uncommon source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-service-command-execution-from-an-uncommon-source)
* \[Low] [Remote usage of an AWS service token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-aws-service-token)
  * \[High] Remote usage of an AWS EKS token - Temporarily Removed
  * \[High] Suspicious usage of AWS service token - Temporarily Removed
  * \[High] Suspicious usage of an AWS ECS token - Temporarily Removed
  * \[Low] Remote usage of an AWS ECS token - Temporarily Removed
  * \[Low] Suspicious usage of an AWS EKS token - Temporarily Removed
* \[High] [Suspicious API call from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-api-call-from-a-tor-exit-node)
* \[High] [Suspicious SaaS API call from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-saas-api-call-from-a-tor-exit-node)
* \[High] [Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dump-of-ntds-dit-using-shadow-copy-with-ntdsutil-vssadmin)
* \[High] [Suspicious objects encryption in an AWS bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-objects-encryption-in-an-aws-bucket)
* \[High] [Suspicious usage of File Server Remote VSS Protocol (FSRVP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-file-server-remote-vss-protocol-fsrvp)
* \[High] [Unicode RTL Override Character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unicode-rtl-override-character)
* \[High] [Wbadmin deleted files in quiet mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wbadmin-deleted-files-in-quiet-mode)
* \[Medium] [A Kubernetes API operation was successfully invoked by an anonymous user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-api-operation-was-successfully-invoked-by-an-anonymous-user)
* \[Medium] [A Kubernetes dashboard service account was used outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-dashboard-service-account-was-used-outside-the-cluster)
* \[Medium] [A Possible crypto miner was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-crypto-miner-was-detected-on-a-host)
* \[Medium] [A TCP stream was created directly in a shell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-tcp-stream-was-created-directly-in-a-shell)
* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
  * \[Medium] A suspicious cloud identity executed an API call from an unusual country - Added
* \[Medium] [A cloud storage object was copied to a foreign cloud account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-object-was-copied-to-a-foreign-cloud-account)
* \[Medium] [A contained executable from a mounted share initiated a suspicious outbound network connection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-executable-from-a-mounted-share-initiated-a-suspicious-outbound-network-connection)
* \[Medium] [A contained executable was executed by an unusual process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-executable-was-executed-by-an-unusual-process)
* \[Medium] [A contained process attempted to escape using the 'notify on release' feature](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-process-attempted-to-escape-using-the-notify-on-release-feature)
* \[Medium] [A machine certificate was issued with a mismatch](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-machine-certificate-was-issued-with-a-mismatch)
* \[Medium] [A mail forwarding rule was configured in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-mail-forwarding-rule-was-configured-in-google-workspace)
* \[Medium] [A new machine attempted Kerberos delegation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-new-machine-attempted-kerberos-delegation)
* \[Medium] [A process was executed with a command line obfuscated by Unicode character substitution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitution)
* \[Medium] [A suspicious executable with multiple file extensions was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-executable-with-multiple-file-extensions-was-created)
* \[Informational] [A user logged in to the AWS console for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-to-the-aws-console-for-the-first-time)
  * \[Medium] A non-user identity logged in to the AWS console for the first time - Modified Logic
* \[Informational] [AWS CloudTrail modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudtrail-modification)
  * \[Medium] AWS CloudTrail modification - Added
* \[Medium] [An internal Cloud resource performed port scan on external networks](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-internal-cloud-resource-performed-port-scan-on-external-networks)
* \[Medium] [Autorun.inf created in root C drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/autorun-inf-created-in-root-c-drive)
* \[Medium] [Azure AD PIM alert disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-alert-disabled)
* \[Low] [Azure account deletion by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-deletion-by-a-non-standard-account)
  * \[Medium] A suspicious Azure account deletion by a non-standard account - Modified Logic
* \[Medium] [Bitsadmin.exe persistence using command-line callback](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitsadmin-exe-persistence-using-command-line-callback)
* \[Medium] [Cloud snapshot of a database or storage instance was publicly shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-snapshot-of-a-database-or-storage-instance-was-publicly-shared)
* \[Medium] [Commonly abused AutoIT script connects to an external domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-autoit-script-connects-to-an-external-domain)
* \[Medium] [Discovery of misconfigured certificate templates using LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-misconfigured-certificate-templates-using-ldap)
* \[Informational] [EBS volume attachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-attachment-attempt)
  * \[Medium] EBS volume attachment attempt for volume with sensitive data - Modified Metadata
  * \[Informational] EBS volume attachment attempt using Cloud Formation or Terraform - Modified Metadata
* \[Medium] [Encoded information using Windows certificate management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/encoded-information-using-windows-certificate-management-tool)
* \[Medium] [Executable created to disk by lsass.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-created-to-disk-by-lsass-exe)
* \[Informational] [Executable moved to Windows system folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-moved-to-windows-system-folder)
  * \[Medium] Rare executable moved to Windows system folder by rare causality actor - Modified Logic
* \[Medium] [Fodhelper.exe UAC bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/fodhelper-exe-uac-bypass)
* \[Informational] [GCP logging sink modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-sink-modification)
  * \[Medium] GCP logging sink modification - Added
* \[Medium] [Indirect command execution using the Program Compatibility Assistant](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indirect-command-execution-using-the-program-compatibility-assistant)
* \[Medium] [Kerberos Traffic from Non-Standard Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-traffic-from-non-standard-process)
* \[Medium] [Kerberos User Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-user-enumeration)
* \[Informational] [Kubernetes secret enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-secret-enumeration-activity)
  * \[Medium] Kubernetes secret describe activity from a Kubernetes Pod - Added
  * \[Medium] Kubernetes secret value extraction activity from a Kubernetes pod - Added
  * \[Low] Kubernetes secret enumeration activity from a host - Added
  * \[Informational] Kubernetes secret value extraction activity - Added
* \[Medium] [Kubernetes vulnerability scanner activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-vulnerability-scanner-activity)
* \[Medium] [Kubernetes vulnerability scanning tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-vulnerability-scanning-tool-usage)
* \[Medium] [LSASS dump file written to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lsass-dump-file-written-to-disk)
* \[Medium] [Logging was impaired via external encryption key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/logging-was-impaired-via-external-encryption-key)
* \[Medium] [Machine account was added to a domain admins group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/machine-account-was-added-to-a-domain-admins-group)
* \[Medium] [Mailbox Client Access Setting (CAS) changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mailbox-client-access-setting-cas-changed)
* \[Medium] [Manipulation of netsh helper DLLs Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-netsh-helper-dlls-registry-keys)
* \[Medium] [Microsoft Office Process Spawning a Suspicious One-Liner](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-process-spawning-a-suspicious-one-liner)
* \[Medium] [NTLM Hash Harvesting](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-hash-harvesting)
* \[Medium] [New Administrative Behavior](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-administrative-behavior)
* \[Medium] [Penetration testing tool activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Medium] [Phantom DLL Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/phantom-dll-loading)
* \[Medium] [Possible Persistence via group policy Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-persistence-via-group-policy-registry-keys)
* \[Medium] [Possible RDP session hijacking using tscon.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-rdp-session-hijacking-using-tscon-exe)
* \[Medium] [Possible Search For Password Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-search-for-password-files)
* \[Medium] [Possible code downloading from a remote host by Regsvr32](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32)
* \[Medium] [Possible collection of screen captures with Windows Problem Steps Recorder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-collection-of-screen-captures-with-windows-problem-steps-recorder)
* \[Medium] [Possible compromised machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-compromised-machine-account)
* \[Medium] [Possible malicious .NET compilation started by a commonly abused process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-malicious-net-compilation-started-by-a-commonly-abused-process)
* \[Medium] [Possible new DHCP server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-new-dhcp-server)
* \[Medium] [PowerShell suspicious flags](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-suspicious-flags)
* \[Medium] [PowerShell used to export mailbox contents](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-used-to-export-mailbox-contents)
* \[Medium] [Procdump executed from an atypical directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/procdump-executed-from-an-atypical-directory)
* \[Medium] [RDP Connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connection-to-localhost)
* \[Medium] [Random-Looking Domain Names](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/random-looking-domain-names)
* \[Low -> Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
  * \[Medium] Uncommon remote scheduled task created - Modified Logic
  * \[Low] Highly rare scheduled task created - Added
  * \[Low] Uncommon local scheduled task created - Modified Logic
* \[Medium] [Remote WMI process execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-wmi-process-execution)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[Medium] Potential Brand Impersonation has been detected - Modified Logic
  * \[Medium] Potential Business Email Compromise has been detected - Modified Logic
  * \[Medium] Potential Phishing has been detected - Modified Logic
  * \[Medium] Potential Spear Phishing has been detected - Modified Logic
* \[Medium] [Rundll32.exe running with no command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-running-with-no-command-line-arguments)
* \[Medium] [Rundll32.exe spawns conhost.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-spawns-conhost-exe)
* \[Medium] [Script file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/script-file-added-to-startup-related-registry-keys)
* \[Medium] [Service ticket request with a spoofed sAMAccountName](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/service-ticket-request-with-a-spoofed-samaccountname)
* \[Medium] [Sudoedit Brute force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudoedit-brute-force-attempt)
* \[Medium] [Suspicious .NET process loads an MSBuild DLL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-net-process-loads-an-msbuild-dll)
* \[Medium] [Suspicious Encrypting File System Remote call (EFSRPC) to domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-encrypting-file-system-remote-call-efsrpc-to-domain-controller)
* \[Medium] [Suspicious HTTP parameters detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-http-parameters-detected)
* \[Medium] [Suspicious Kubernetes pod token access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-kubernetes-pod-token-access)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) net function was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-used-to-search-for-exposed-hosts)
* \[Medium] [Suspicious Process Spawned by wininit.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawned-by-wininit-exe)
* \[Medium] [Suspicious SearchProtocolHost.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-searchprotocolhost-exe-parent-process)
* \[Medium] [Suspicious authentication package registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-authentication-package-registered)
* \[Medium] [Suspicious authentication with Azure Password Hash Sync user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-authentication-with-azure-password-hash-sync-user)
* \[Medium] [Suspicious certutil command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-command-line)
* \[Medium] [Suspicious dNSHostName attribute change to DC name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dnshostname-attribute-change-to-dc-name)
* \[Medium] [Suspicious disablement of the Windows Firewall using PowerShell commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-disablement-of-the-windows-firewall-using-powershell-commands)
* \[Medium] [Suspicious heavy allocation of compute resources - possible mining activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-heavy-allocation-of-compute-resources-possible-mining-activity)
* \[Medium] [Suspicious hidden user created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-hidden-user-created)
* \[Medium] [Suspicious print processor registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-print-processor-registered)
* \[Medium] [Suspicious time provider registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-time-provider-registered)
* \[Medium -> Low] [Suspicious usage of EC2 token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-ec2-token)
  * \[High -> Medium] Suspicious usage of EC2 token - Modified Logic
  * \[Informational] Suspicious usage of EC2 token - Removed
* \[Medium] [TGT request with a spoofed sAMAccountName - Event log](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-event-log)
* \[Medium] [TGT request with a spoofed sAMAccountName - Network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-network)
* \[Medium] [The CA policy EditFlags was queried](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/the-ca-policy-editflags-was-queried)
* \[Medium] [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dll-sideloading-from-a-logical-cd-rom-iso-device)
* \[Medium] [Uncommon Service Create/Config](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-service-create-config)
* \[Medium] [Uncommon SetWindowsHookEx API invocation of a possible keylogger](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-setwindowshookex-api-invocation-of-a-possible-keylogger)
* \[Medium] [Uncommon jsp file write by a Java process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-jsp-file-write-by-a-java-process)
* \[Low] [Unsigned process creates a scheduled task via file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-creates-a-scheduled-task-via-file-access)
  * \[Medium] Unsigned process creates a scheduled task via file access on a sensitive server - Modified Metadata
* \[Medium] [Unsigned process injecting into a Windows system binary with no command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line)
* \[Informational] [Unusual cloud identity impersonation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-identity-impersonation)
  * \[Medium] Suspicious cloud identity impersonation was succeeded - Modified Logic
  * \[Informational] Suspicious cloud identity impersonation was failed - Modified Logic
* \[Medium] [Unusual process access to ld.so.preload file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-access-to-ld-so-preload-file)
* \[Medium] [Windows Installer exploitation for local privilege escalation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-installer-exploitation-for-local-privilege-escalation)
* \[Medium] [Windows LOLBIN executable connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-lolbin-executable-connected-to-a-rare-external-host)
* \[Low] [A Backup vault policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-backup-vault-policy-was-modified)
* \[Low] [A Command Line Interface (CLI) command was executed from a GCP serverless compute service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-a-gcp-serverless-compute-service)
* \[Low] [A Command Line Interface (CLI) command was executed from an AWS serverless compute service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-command-line-interface-cli-command-was-executed-from-an-aws-serverless-compute-service)
* \[Low] [A GCP service account was delegated domain-wide authority in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspace)
* \[Low] [A cloud function was created with an unusual runtime](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-function-was-created-with-an-unusual-runtime)
* \[Low] [A commonly abused process connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-cloud-resource)
* \[Low] [A commonly abused process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-external-host)
* \[Low] [A compiled HTML help file wrote a script file to the disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compiled-html-help-file-wrote-a-script-file-to-the-disk)
* \[Low] [A computer account was promoted to DC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-computer-account-was-promoted-to-dc)
* \[Low] [A disabled user attempted to log in to a VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-log-in-to-a-vpn)
* \[Low] [A domain was added to the trusted domains list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-domain-was-added-to-the-trusted-domains-list)
* \[Low] [A process queried the ADFS database decryption key via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap)
* \[Low] [A rare FTP user has been detected on an existing FTP server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-server)
* \[Low] [A rare file path was added to the AppInit\_DLLs registry value](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value)
* \[Low] [A remote service was created via RPC over SMB](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-remote-service-was-created-via-rpc-over-smb)
* \[Low] [A suspicious direct syscall was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-direct-syscall-was-executed)
* \[Low] [A suspicious process enrolled for a certificate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-process-enrolled-for-a-certificate)
* \[Low] [A user attempted to bypass Okta MFA](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-attempted-to-bypass-okta-mfa)
* \[Low] [A user connected a new USB storage device to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-multiple-hosts)
* \[Low] [A user modified the CA audit policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-the-ca-audit-policy)
* \[Low] [A user rejected an SSO request from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-rejected-an-sso-request-from-an-unusual-country)
* \[Low] [A user sent multiple TGT requests to irregular service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-sent-multiple-tgt-requests-to-irregular-service)
* \[Low] [A user uploaded malware to SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive)
* \[Low] [AWS Guard-Duty detector deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-guard-duty-detector-deletion)
* \[Low] [AWS S3 bucket was exposed to public access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-s3-bucket-was-exposed-to-public-access)
* \[Low] [AWS data asset shared public](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-data-asset-shared-public)
* \[Low] [AWS web ACL deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-web-acl-deletion)
* \[Low] [Abnormal ICMP echo (PING) to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-icmp-echo-ping-to-multiple-hosts)
* \[Low] [Abnormal RPC traffic to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rpc-traffic-to-multiple-hosts)
* \[Low] [Abnormal SMB activity to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-smb-activity-to-multiple-hosts)
* \[Low] [Abnormal communication with a rare combination of TLS and HTTP User Agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-with-a-rare-combination-of-tls-and-http-user-agent)
* \[Low] [Abnormal network communication through TOR using an uncommon port](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-through-tor-using-an-uncommon-port)
* \[Low] [Abnormal sensitive RPC traffic to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts)
* \[Low] [Account probing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/account-probing)
* \[Low] [An Azure Firewall policy deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-policy-deletion)
* \[Low] [An RDS snapshot was exported to an unknown S3 bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-s3-bucket)
* \[Low] [An S3 replication policy to an unknown bucket was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-s3-replication-policy-to-an-unknown-bucket-was-created)
* \[Low] [An uncommon executable was remotely written over SMB to an uncommon destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-executable-was-remotely-written-over-smb-to-an-uncommon-destination)
* \[Low] [An uncommon service was started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-service-was-started)
* \[Low] [An unpopular process accessed the microphone on the host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unpopular-process-accessed-the-microphone-on-the-host)
* \[Low] [Attempt to execute a command on a remote host using PsExec.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/attempt-to-execute-a-command-on-a-remote-host-using-psexec-exe)
* \[Low] [Authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-by-a-honey-user)
* \[Low] [Azure AD PIM role settings change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-role-settings-change)
* \[Low] [Azure Event Hub Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-event-hub-deletion)
* \[Low] [Azure Network Watcher Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-network-watcher-deletion)
* \[Low] [Azure domain federation settings modification attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-domain-federation-settings-modification-attempt)
* \[Low] [Billing admin role was removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/billing-admin-role-was-removed)
* \[Low] [Cached credentials discovery with cmdkey](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cached-credentials-discovery-with-cmdkey)
* \[Low] [Certutil pfx parsing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/certutil-pfx-parsing)
* \[Low] [Change of sudo caching configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/change-of-sudo-caching-configuration)
* \[Low] [ClickFix - PowerShell executed through the run application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clickfix-powershell-executed-through-the-run-application)
* \[Informational] [Cloud compute instance user data script modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-instance-user-data-script-modification)
  * \[Low] Unusual Cloud compute instance user data script modification - Modified Metadata
* \[Low] [Command running with COMSPEC in the command line argument](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-running-with-comspec-in-the-command-line-argument)
* \[Low] [Compressing data using python](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compressing-data-using-python)
* \[Low] [Conditional Access policy removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/conditional-access-policy-removed)
* \[Low] [Conhost.exe spawned a suspicious cmd process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/conhost-exe-spawned-a-suspicious-cmd-process)
* \[Low] [Contained process execution with a rare GitHub URL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/contained-process-execution-with-a-rare-github-url)
* \[Low] [Copy a user's GnuPG directory with rsync](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-user-s-gnupg-directory-with-rsync)
* \[Low] [DNS Tunneling](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dns-tunneling)
* \[Low] [Delayed Deletion of Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/delayed-deletion-of-files)
* \[Low] [Disable encryption operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/disable-encryption-operations)
* \[Low] [Discovery of accounts with pre-authentication disabled via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-accounts-with-pre-authentication-disabled-via-ldap)
* \[Low] [Download a script using the python requests module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-a-script-using-the-python-requests-module)
* \[Low] [Elevation to SYSTEM via services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/elevation-to-system-via-services)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Excessive user account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/excessive-user-account-lockouts)
* \[Low] [Exchange DKIM signing configuration disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-dkim-signing-configuration-disabled)
* \[Low] [Exchange Safe Attachment policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-safe-attachment-policy-disabled-or-removed)
* \[Low] [Exchange Safe Link policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-safe-link-policy-disabled-or-removed)
* \[Low] [Exchange anti-phish policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-anti-phish-policy-disabled-or-removed)
* \[Low] [Exchange audit log disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-audit-log-disabled)
* \[Low] [Exchange mailbox audit bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-audit-bypass)
* \[Low] [Exchange malware filter policy removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-malware-filter-policy-removed)
* \[Low] [Exchange transport forwarding rule configured](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-transport-forwarding-rule-configured)
* \[Low] [Exchange user mailbox forwarding](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-user-mailbox-forwarding)
* \[Low] [Executable or Script file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-or-script-file-written-by-a-web-server-process)
* \[Low] [Execution of an uncommon process at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary)
* \[Low] [Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage-by-windows-system-binary)
* \[Low] [Execution of dllhost.exe with an empty command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-dllhost-exe-with-an-empty-command-line)
* \[Informational] [External user created a Microsoft Teams conversation with suspicious operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations)
  * \[Informational -> Low] An external user created a chat and shortly after sent a link with a newly seen domain name - Modified Metadata
  * \[Informational -> Low] An external user created a chat then sent a link with a file for the first time via Microsoft Teams - Modified Metadata
  * \[Informational -> Low] An external user created a chat with a suspicious user or chat name and then sent a link via Microsoft Teams - Modified Metadata
  * \[Informational -> Low] An external user initiated a Microsoft Teams chat in which a link was shared and a member was removed - Modified Metadata
  * \[Informational -> Low] An external user initiated a Microsoft Teams chat in which a suspicious link was shared and a member was removed - Modified Metadata
  * \[Informational -> Low] External user created a Microsoft Teams conversation with a suspicious user or chat name and shortly after removed a user from it - Modified Metadata
* \[Low] [Extracting credentials from Unix files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/extracting-credentials-from-unix-files)
* \[Low] [FTP Connection Using an Anonymous Login or Default Credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ftp-connection-using-an-anonymous-login-or-default-credentials)
* \[Low] [Failed Connections](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-connections)
* \[Low] [Failed DNS](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-dns)
* \[Low] [First Azure AD PowerShell operation for a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-azure-ad-powershell-operation-for-a-user)
* \[Low] [GCP data asset shared public](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-data-asset-shared-public)
* \[Low] [Globally uncommon root domain from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-from-a-signed-process)
* \[Low] [Globally uncommon root-domain port combination from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-from-a-signed-process)
* \[Low] [HTTP with suspicious characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/http-with-suspicious-characteristics)
* \[Low] [Image file execution options (IFEO) registry key set](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/image-file-execution-options-ifeo-registry-key-set)
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
* \[Low] [Impossible traveler - VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-vpn)
* \[Low] [Installation of a new System-V service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/installation-of-a-new-system-v-service)
* \[Medium -> Low] [Interactive at.exe privilege escalation method](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-at-exe-privilege-escalation-method)
* \[Low] [Interactive local account enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-local-account-enumeration)
* \[Low] [Interactive login by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-by-a-service-account)
* \[Low] [Kerberos Pre-Auth Failures by Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-pre-auth-failures-by-host)
* \[Low] [Keylogging using system commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/keylogging-using-system-commands)
* \[Low] [Known service display name with uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-display-name-with-uncommon-image-path)
* \[Low] [Known service name with an uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-name-with-an-uncommon-image-path)
* \[Low] [Kubernetes pod creation from unknown container image registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-creation-from-unknown-container-image-registry)
* \[Low] [LDAP AD CS Enumeration via Attack Tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-ad-cs-enumeration-via-attack-tool)
* \[Low] [LDAP search query from an unpopular and unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-search-query-from-an-unpopular-and-unsigned-process)
* \[Low] [LOLBIN process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-process-executed-with-a-high-integrity-level)
* \[Low] [Large Upload (FTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-ftp)
* \[Low] [Large Upload (Generic)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-generic)
* \[Low] [Large Upload (HTTPS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-https)
* \[Low] [Large Upload (SMTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-smtp)
* \[Low] [Linux system firewall was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-system-firewall-was-modified)
* \[Low] [Login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/login-attempt-by-a-honey-user)
* \[Low] [Logs were not collected from a data source for an abnormally long time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/logs-were-not-collected-from-a-data-source-for-an-abnormally-long-time)
* \[Low] [MFA Disabled for Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-disabled-for-google-workspace)
* \[Low] [MFA was disabled for an Azure identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-was-disabled-for-an-azure-identity)
* \[Low] [Masquerading as a default local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/masquerading-as-a-default-local-account)
* \[Low] [Masquerading as the Linux crond process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/masquerading-as-the-linux-crond-process)
* \[Low] [Microsoft 365 storage services exfiltration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-365-storage-services-exfiltration-activity)
* \[Low] [Microsoft Office adds a value to autostart Registry key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-adds-a-value-to-autostart-registry-key)
* \[Low] [Microsoft Office injects code into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-injects-code-into-a-process)
* \[Low] [Microsoft Office process spawns a commonly abused process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-process-spawns-a-commonly-abused-process)
* \[Low] [Modification of NTLM restrictions in the Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-ntlm-restrictions-in-the-registry)
* \[Low] [MpCmdRun.exe was used to download files into the system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mpcmdrun-exe-was-used-to-download-files-into-the-system)
* \[Low] [Mshta.exe launched with suspicious arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-launched-with-suspicious-arguments)
* \[Low] [Mshta.exe spawns from a browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-spawns-from-a-browser-process)
* \[Low] [Multiple Azure AD admin role removals](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-azure-ad-admin-role-removals)
* \[Low] [Multiple Rare LOLBIN Process Executions by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-rare-lolbin-process-executions-by-user)
* \[Low] [Multiple Suspicious FTP Login Attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-suspicious-ftp-login-attempts)
* \[Low] [Multiple Weakly-Encrypted Kerberos Tickets Received](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-weakly-encrypted-kerberos-tickets-received)
* \[Low] [Multiple discovery commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands)
* \[Low] [Multiple discovery commands on a Windows host by the same process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands-on-a-windows-host-by-the-same-process)
* \[Low] [Multiple suspicious user accounts were created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-suspicious-user-accounts-were-created)
* \[Low] [Multiple uncommon SSH Servers with the same Server host key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key)
* \[Low] [Multiple user accounts failed login due to account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts)
* \[Low] [NTDS.dit file written by an uncommon executable](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntds-dit-file-written-by-an-uncommon-executable)
* \[Low] [NTLM Brute Force on a Service Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force-on-a-service-account)
* \[Low] [NTLM Brute Force on an Administrator Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force-on-an-administrator-account)
* \[Low] [New FTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-ftp-server)
* \[Low] [New Shared User Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-shared-user-account)
* \[Low] [New addition to Windows Defender exclusion list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-addition-to-windows-defender-exclusion-list)
* \[Low] [Non-browser access to a pastebin-like site](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/non-browser-access-to-a-pastebin-like-site)
* \[Low] [Office process accessed an unusual .LNK file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-accessed-an-unusual-lnk-file)
* \[Low] [Office process spawned with suspicious command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-spawned-with-suspicious-command-line-arguments)
* \[Low] [Okta FastPass reported phishing attack suspected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected)
* \[Low] [Okta Reported Attack Suspected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-reported-attack-suspected)
* \[Low] [Outlook files accessed by an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outlook-files-accessed-by-an-unsigned-process)
* \[Low] [Possible DCSync from a non domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dcsync-from-a-non-domain-controller)
* \[Low] [Possible DLL Search Order Hijacking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-search-order-hijacking)
* \[Low] [Possible Kerberoasting without SPNs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberoasting-without-spns)
* \[Low] [Possible Kerberos relay attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberos-relay-attack)
* \[Low] [Possible Pass-the-Hash](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-pass-the-hash)
* \[Low] [Possible external RDP Brute-Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-external-rdp-brute-force)
* \[Low] [Possible multistage attack in Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-multistage-attack-in-microsoft-teams)
* \[Low] [Possible network service discovery via command-line tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-service-discovery-via-command-line-tool)
* \[Low] [Possible network sniffing attempt via tcpdump or tshark](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark)
* \[Low] [Possible path traversal via HTTP request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-path-traversal-via-http-request)
* \[Low] [Possible webshell file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-webshell-file-written-by-a-web-server-process)
* \[Low] [Potential SCCM credential harvesting using WMI detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-sccm-credential-harvesting-using-wmi-detected)
* \[Low] [PowerShell Initiates a Network Connection to GitHub](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-initiates-a-network-connection-to-github)
* \[Low] [PowerShell runs suspicious base64-encoded commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-runs-suspicious-base64-encoded-commands)
* \[Low] [RDP connections enabled remotely via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connections-enabled-remotely-via-registry)
* \[Low] [Rare LDAP enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ldap-enumeration)
* \[Low] [Rare RDP session to a remote host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-rdp-session-to-a-remote-host)
* \[Low] [Rare SMB session to a remote host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-smb-session-to-a-remote-host)
* \[Low] [Rare SSH Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ssh-session)
* \[Low] [Rare Unsigned Process Spawned by Office Process Under Suspicious Directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-spawned-by-office-process-under-suspicious-directory)
* \[Low] [Rare Windows Remote Management (WinRM) HTTP Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-windows-remote-management-winrm-http-activity)
* \[Low] [Rare binary connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-binary-connected-to-a-rare-cloud-resource)
* \[Low] [Rare binary connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-binary-connected-to-a-rare-external-host)
* \[Low] [Rare communication over email ports to external email server by unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-communication-over-email-ports-to-external-email-server-by-unsigned-process)
* \[Low] [Rare file transfer over SMB protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-file-transfer-over-smb-protocol)
* \[Low] [Rare process created an SSH session to an uncommon cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-cloud-resource)
* \[Low] [Rare process created an SSH session to an uncommon external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-external-host)
* \[Low] [Rare process executed by an AppleScript](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-executed-by-an-applescript)
* \[Low] [Rare process with VNC server capabilities started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-with-vnc-server-capabilities-started)
* \[Low] [Rare security product signed executable executed in the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-security-product-signed-executable-executed-in-the-network)
* \[Low] [Rare service DLL was added to the registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-service-dll-was-added-to-the-registry)
* \[Low] [Reading bash command history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/reading-bash-command-history-file)
* \[Low] [Recurring access to rare IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-ip)
* \[Low] [Recurring access to rare domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-domain)
* \[Low] [Recurring rare domain access from an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-from-an-unsigned-process)
* \[Low] [Recurring rare domain access to dynamic DNS domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-to-dynamic-dns-domain)
* \[Low] [Remote DCOM command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-dcom-command-execution)
* \[Low] [Remote command execution via wmic.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-command-execution-via-wmic-exe)
* \[Low] [Remote service start from an uncommon source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-service-start-from-an-uncommon-source)
* \[Low] [Remote usage of an Azure Managed Identity token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-managed-identity-token)
* \[Low] [Rundll32.exe executes a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module)
* \[Low] [SMB Traffic from Non-Standard Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/smb-traffic-from-non-standard-process)
* \[Low] [SPNs cleared from a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/spns-cleared-from-a-machine-account)
* \[Low] [SSO authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-attempt-by-a-honey-user)
* \[Low] [SSO authentication by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-machine-account)
* \[Low] [SSO authentication by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-service-account)
* \[Low] [SUID/GUID permission discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suid-guid-permission-discovery)
* \[Low] [Scheduled Task hidden by registry modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scheduled-task-hidden-by-registry-modification)
* \[Low] [Screensaver process executed from Users or temporary folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/screensaver-process-executed-from-users-or-temporary-folder)
* \[Low] [Scripting engine connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scripting-engine-connected-to-a-rare-external-host)
* \[Low] [SecureBoot was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/secureboot-was-disabled)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Sensitive browser credential files accessed by a rare non browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process)
* \[Low] [Setuid and Setgid file bit manipulation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/setuid-and-setgid-file-bit-manipulation)
* \[Low] [Short-lived user account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/short-lived-user-account)
* \[Low] [Spam Bot Traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/spam-bot-traffic)
* \[Low] [Stored credentials exported using credwiz.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/stored-credentials-exported-using-credwiz-exe)
* \[Low] [Subdomain Fuzzing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/subdomain-fuzzing)
* \[Low] [Suspicious Certutil AD CS contact](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-ad-cs-contact)
* \[Low] [Suspicious DotNet log file created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dotnet-log-file-created)
* \[Low] [Suspicious ICMP packet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-icmp-packet)
* \[Low] [Suspicious ICMP traffic that resembles smurf attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-icmp-traffic-that-resembles-smurf-attack)
* \[Low] [Suspicious LDAP search query executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ldap-search-query-executed)
* \[Low] [Suspicious PowerShell Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-command-line)
* \[Low] [Suspicious PowerShell Enumeration of Running Processes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-enumeration-of-running-processes)
* \[Low] [Suspicious Print System Remote Protocol usage by a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-print-system-remote-protocol-usage-by-a-process)
* \[Low] [Suspicious Process Spawned by Adobe Reader](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawned-by-adobe-reader)
* \[Low] [Suspicious RunOnce Parent Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-runonce-parent-process)
* \[Low] [Suspicious SMB connection from domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-smb-connection-from-domain-controller)
* \[Low] [Suspicious SSH Downgrade](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ssh-downgrade)
* \[Low] [Suspicious Udev driver rule execution manipulation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-udev-driver-rule-execution-manipulation)
* \[Low] [Suspicious access of the System Management Container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-of-the-system-management-container)
* \[Low] [Suspicious container orchestration job](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-orchestration-job)
* \[Low] [Suspicious data encryption](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-data-encryption)
* \[Low] [Suspicious disablement of the Windows Firewall](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-disablement-of-the-windows-firewall)
* \[Low] [Suspicious failed HTTP request - potential Spring4Shell exploit](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit)
* \[Low] [Suspicious identity downloaded multiple objects from a bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-identity-downloaded-multiple-objects-from-a-bucket)
* \[Low] [Suspicious modification of the AdminSDHolder's ACL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-modification-of-the-adminsdholder-s-acl)
* \[Low] [Suspicious module load using direct syscall](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-module-load-using-direct-syscall)
* \[Low] [Suspicious process accessed certificate files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-accessed-certificate-files)
* \[Low] [Suspicious process modified RC script file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-modified-rc-script-file)
* \[Low] [Suspicious runonce.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-runonce-exe-parent-process)
* \[Low] [Suspicious sAMAccountName change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-samaccountname-change)
* \[Low] [Suspicious setspn.exe execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-setspn-exe-execution)
* \[Low] [Suspicious sshpass command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sshpass-command-execution)
* \[Low] [Suspicious systemd timer activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-systemd-timer-activity)
* \[Low] [Svchost.exe loads a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/svchost-exe-loads-a-rare-unsigned-module)
* \[Low] [System information discovery via psinfo.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-information-discovery-via-psinfo-exe)
* \[Low] [The Linux system firewall was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/the-linux-system-firewall-was-disabled)
* \[Low] [Uncommon ARP cache listing via arp.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe)
* \[Low] [Uncommon AT task-job creation by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-at-task-job-creation-by-user)
* \[Low] [Uncommon IP Configuration Listing via ipconfig.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ip-configuration-listing-via-ipconfig-exe)
* \[Informational] [Uncommon Launch Agent persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-agent-persistency-was-registered-or-modified)
  * \[Low] Uncommon Launch Agent persistency was registered or modified by a non validly signed process - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified by a tool with possible web access - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified by an unsigned process - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified while using a data communication tool - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified while using osascript - Modified Logic
  * \[Low] Uncommon Launch Agent persistency was registered or modified with an uncommon path containing a known vendor name - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified with an unusual persistency executable path - Modified Metadata
* \[Informational] [Uncommon Launch Daemon persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-daemon-persistency-was-registered-or-modified)
  * \[Low] Uncommon Launch Daemon persistency was registered or modified by a non validly signed process - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified by a tool with possible web access - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified by an unsigned process - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified while using a data communication tool - Modified Logic
  * \[Low] Uncommon Launch Daemon persistency was registered or modified while using osascript - Modified Logic
  * \[Low] Uncommon Launch Daemon persistency was registered or modified with an uncommon path containing a known vendor name - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified with an unusual persistency executable path - Modified Metadata
* \[Low] [Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ntwritevirtualmemoryremote-api-invocation-with-a-pe-header-buffer)
* \[Low] [Uncommon PowerShell commands used to create or alter scheduled task parameters](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-powershell-commands-used-to-create-or-alter-scheduled-task-parameters)
* \[Low] [Uncommon SSH session was established](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ssh-session-was-established)
* \[Low] [Uncommon Security Support Provider (SSP) registered via a registry key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-security-support-provider-ssp-registered-via-a-registry-key)
* \[Low] [Uncommon VNC server communication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-vnc-server-communication)
* \[Low] [Uncommon access to Microsoft Teams credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-microsoft-teams-credential-files)
* \[Low] [Uncommon attempt to clear shell history](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-to-clear-shell-history)
* \[Low] [Uncommon creation or access operation of sensitive shadow copy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-creation-or-access-operation-of-sensitive-shadow-copy)
* \[Low] [Uncommon driver loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-driver-loaded)
* \[Low] [Uncommon execution of ODBCConf](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-execution-of-odbcconf)
* \[Low] [Uncommon file access over WebDAV](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-file-access-over-webdav)
* \[Low] [Uncommon local scheduled task creation via schtasks.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe)
* \[Low] [Uncommon msiexec execution of an arbitrary file from a remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location)
* \[Low] [Uncommon remote monitoring and management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-monitoring-and-management-tool)
* \[Low] [Uncommon remote scheduled task creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-scheduled-task-creation)
* \[Low] [Uncommon remote service start via sc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-service-start-via-sc-exe)
* \[Low] [Uncommon reverse SSH tunnel to external domain/ip](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-reverse-ssh-tunnel-to-external-domain-ip)
* \[Low] [Uncommon routing table listing via route.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-routing-table-listing-via-route-exe)
* \[Low] [Uncommon sensitive registry hive dump](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-registry-hive-dump)
* \[Low] [Unprivileged process opened a registry hive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unprivileged-process-opened-a-registry-hive)
* \[Low] [Unsigned and unpopular process performed a DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-a-dll-injection)
* \[Low] [Unsigned and unpopular process performed an injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-an-injection)
* \[Low] [Unsigned process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Unusual AWS credentials creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-credentials-creation)
* \[Low] [Unusual AWS user added to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-user-added-to-group)
* \[Low] [Unusual Azure AD sync module load](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-azure-ad-sync-module-load)
* \[Low] [Unusual CIM repository file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cim-repository-file-access)
* \[Low] [Unusual CertLog Remote File Write](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-certlog-remote-file-write)
* \[Low] [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-encrypting-file-system-remote-call-efsrpc-to-domain-controller)
* \[Low] [Unusual Kubernetes API server communication from a pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Unusual Kubernetes dashboard communication from a pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-dashboard-communication-from-a-pod)
* \[Low] [Unusual Lolbins Process Spawned by InstallUtil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe)
* \[Low] [Unusual Netsh PortProxy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-netsh-portproxy-rule)
* \[Low] [Unusual Process Spawned by Nginx in Ingress-Nginx pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-spawned-by-nginx-in-ingress-nginx-pod)
* \[Low] [Unusual compressed file password protection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-compressed-file-password-protection)
* \[Low] [Unusual cross projects activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cross-projects-activity)
* \[Low] [Unusual process accessed FTP Client credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-ftp-client-credentials)
* \[Low] [Unusual process accessed a crypto wallet's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files)
* \[Low] [Unusual process accessed a messaging app's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-messaging-app-s-files)
* \[Low] [Unusual process accessed a web browser history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-web-browser-history-file)
* \[Informational] [Unusual resource modification by newly seen IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-resource-modification-by-newly-seen-iam-user)
  * \[Low] Unusual resource modification by newly seen IAM user from an uncommon IP - Modified Logic
* \[Low] [User added to the SMS Admins local group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-to-the-sms-admins-local-group)
* \[Low] [User collected remote shared files in an archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-collected-remote-shared-files-in-an-archive)
* \[Informational] [User exported multiple messages in Microsoft Teams via Graph API](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-exported-multiple-messages-in-microsoft-teams-via-graph-api)
  * \[Low] User exported multiple chats in Microsoft Teams via Graph API - Modified Logic
* \[Low] [User set insecure CA registry setting for global SANs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-set-insecure-ca-registry-setting-for-global-sans)
* \[Low] [VPN login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-attempt-by-a-honey-user)
* \[Low] [VPN login by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-by-a-service-account)
* \[Low] [Weakly-Encrypted Kerberos Ticket Requested](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-ticket-requested)
* \[Low] [Windows Event Log was cleared using wevtutil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-log-was-cleared-using-wevtutil-exe)
* \[Low] [Windows event logs were cleared with PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-logs-were-cleared-with-powershell)
* \[Low] [WmiPrvSe.exe Rare Child Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wmiprvse-exe-rare-child-command-line)
* \[Low] [Wscript/Cscript loads .NET DLLs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wscript-cscript-loads-net-dlls)
* \[Low] [Wsmprovhost.exe Rare Child Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wsmprovhost-exe-rare-child-process)
* \[Informational] [A Google Workspace Role privilege was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-role-privilege-was-deleted)
* \[Informational] [A Google Workspace identity created, assigned or modified a role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-created-assigned-or-modified-a-role)
* \[Informational] [A Google Workspace identity performed an unusual admin console activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-performed-an-unusual-admin-console-activity)
* \[Informational] [A Google Workspace identity used the security investigation tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-used-the-security-investigation-tool)
* \[Informational] [A Google Workspace service was configured as unrestricted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-service-was-configured-as-unrestricted)
* \[Informational] [A Google Workspace user was added to a group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-user-was-added-to-a-group)
* \[Informational] [A Google Workspace user was removed from a group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-user-was-removed-from-a-group)
* \[Informational] [A Kubernetes ConfigMap was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-configmap-was-created-or-deleted)
* \[Informational] [A Kubernetes Cronjob was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cronjob-was-created)
* \[Informational] [A Kubernetes DaemonSet was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-daemonset-was-created)
* \[Informational] [A Kubernetes Pod was created with a sidecar container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-pod-was-created-with-a-sidecar-container)
* \[Informational] [A Kubernetes Pod was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-pod-was-deleted)
* \[Informational] [A Kubernetes ReplicaSet was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-replicaset-was-created)
* \[Informational] [A Kubernetes StatefulSet was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-statefulset-was-created)
* \[Informational] [A Kubernetes cluster role binding was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-role-binding-was-created-or-deleted)
* \[Informational] [A Kubernetes cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-was-created-or-deleted)
* \[Informational] [A Kubernetes deployment was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-deployment-was-created)
* \[Informational] [A Kubernetes ephemeral container was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-ephemeral-container-was-created)
* \[Informational] [A Kubernetes namespace was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-namespace-was-created-or-deleted)
* \[Informational] [A Kubernetes node service account activity from external IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-node-service-account-activity-from-external-ip)
* \[Informational] [A Kubernetes role binding was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-role-binding-was-created-or-deleted)
* \[Informational] [A Kubernetes secret was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-secret-was-created-or-deleted)
* \[Informational] [A Kubernetes service account executed an unusual API call](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-account-executed-an-unusual-api-call)
* \[Informational] [A Kubernetes service account has enumerated its permissions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-account-has-enumerated-its-permissions)
* \[Informational] [A Kubernetes service account was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-account-was-created-or-deleted)
* \[Informational] [A Kubernetes service was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-was-created-or-deleted)
* \[Informational] [A LOLBIN was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-lolbin-was-copied-to-a-different-location)
* \[Informational] [A Microsoft Teams application was installed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-microsoft-teams-application-was-installed)
* \[Informational] [A Microsoft Teams bot was added to a team](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-microsoft-teams-bot-was-added-to-a-team)
* \[Informational] [A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-new-server-was-added-to-an-azure-active-directory-hybrid-health-adfs-environment)
* \[Informational] [A Service Principal was created in Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-service-principal-was-created-in-azure)
* \[Informational] [A Service Principal was removed from Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-service-principal-was-removed-from-azure)
* \[Informational] [A Torrent client was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-torrent-client-was-detected-on-a-host)
* \[Informational] [A WMI subscriber was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-wmi-subscriber-was-created)
* \[Informational] [A browser extension was installed or loaded in an uncommon way](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-browser-extension-was-installed-or-loaded-in-an-uncommon-way)
* \[Informational] [A browser was opened in private mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-browser-was-opened-in-private-mode)
* \[Informational] [A cloud identity created or modified a security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-created-or-modified-a-security-group)
* \[Informational] [A cloud identity had escalated its permissions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-had-escalated-its-permissions)
* \[Informational] [A cloud identity invoked IAM related persistence operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-invoked-iam-related-persistence-operations)
* \[Informational] [A cloud identity started a Cloud Shell session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-started-a-cloud-shell-session)
* \[Informational] [A cloud instance was stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-instance-was-stopped)
* \[Informational] [A cloud snapshot of AWS database or storage was modified or shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-snapshot-of-aws-database-or-storage-was-modified-or-shared)
* \[Informational] [A cloud storage configuration was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-configuration-was-modified)
* \[Informational] [A compressed file was exfiltrated over SSH](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compressed-file-was-exfiltrated-over-ssh)
* \[Informational] [A compute-attached identity executed API calls outside the instance's region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region)
* \[Informational] [A container registry was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-container-registry-was-created-or-deleted)
* \[Informational] [A disabled user attempted to authenticate via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-authenticate-via-sso)
* \[Informational] [A disabled user attempted to log in](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-log-in)
* \[Informational] [A new Azure email domain verification was requested](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-new-azure-email-domain-verification-was-requested)
* \[Informational] [A non-browser process accessed a website UI](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-non-browser-process-accessed-a-website-ui)
* \[Informational] [A possible risky login to Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-risky-login-to-azure)
* \[Informational] [A process connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-cloud-resource)
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
* \[Informational] [A process connected to rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-rare-external-host)
* \[Informational] [A process is masquerading as a common Microsoft product](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product)
* \[Informational] [A process modified an SSH authorized\_keys file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-modified-an-ssh-authorized-keys-file)
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process)
* \[Informational] [A rare local administrator login](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-local-administrator-login)
* \[Informational] [A service was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-service-was-disabled)
* \[Informational] [A suspicious process queried AD CS objects via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-process-queried-ad-cs-objects-via-ldap)
* \[Informational] [A third-party application was authorized to access the Google Workspace APIs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-application-was-authorized-to-access-the-google-workspace-apis)
* \[Informational] [A third-party application's access to the Google Workspace domain's resources was revoked](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revoked)
* \[Informational] [A third-party utility was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-utility-was-copied-to-a-different-location)
* \[Informational] [A user accessed Okta's admin application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-okta-s-admin-application)
* \[Informational] [A user accessed an abnormal number of files on a remote shared folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-files-on-a-remote-shared-folder)
* \[Informational] [A user accessed an abnormal number of remote shared folders](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-remote-shared-folders)
* \[Informational] [A user accessed an uncommon AppID](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-uncommon-appid)
* \[Informational] [A user accessed multiple time-consuming websites](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-time-consuming-websites)
* \[Informational] [A user accessed multiple unusual resources via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-unusual-resources-via-sso)
* \[Informational] [A user account was modified to password never expires](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-account-was-modified-to-password-never-expires)
* \[Informational] [A user added a Windows firewall rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-added-a-windows-firewall-rule)
* \[Informational] [A user authenticated with weak NTLM to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-authenticated-with-weak-ntlm-to-multiple-hosts)
* \[Informational] [A user certificate was issued with a mismatch](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-certificate-was-issued-with-a-mismatch)
* \[Informational] [A user changed the Windows system time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-changed-the-windows-system-time)
* \[Informational] [A user connected a USB storage device for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-usb-storage-device-for-the-first-time)
* \[Informational] [A user connected a new USB storage device to a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-a-host)
* \[Informational] [A user connected from a new country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-from-a-new-country)
* \[Informational] [A user connected to a VPN from a new country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-to-a-vpn-from-a-new-country)
* \[Informational] [A user created a pfx file for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-created-a-pfx-file-for-the-first-time)
* \[Informational] [A user created an abnormal password-protected archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-created-an-abnormal-password-protected-archive)
* \[Informational] [A user enabled a default local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-enabled-a-default-local-account)
* \[Informational] [A user established an SMB connection to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-established-an-smb-connection-to-multiple-hosts)
* \[Informational] [A user executed multiple LDAP enumeration queries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-executed-multiple-ldap-enumeration-queries)
* \[Informational] [A user logged in at an unusual time via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-sso)
* \[Informational] [A user logged in at an unusual time via VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-vpn)
* \[Informational] [A user logged in from an abnormal country or ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-from-an-abnormal-country-or-asn)
* \[Informational] [A user logged on to multiple workstations via Schannel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-on-to-multiple-workstations-via-schannel)
* \[Informational] [A user modified an Okta network zone](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-an-okta-network-zone)
* \[Informational] [A user modified an Okta policy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-an-okta-policy-rule)
* \[Informational] [A user observed and reported unusual activity in Okta](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-observed-and-reported-unusual-activity-in-okta)
* \[Informational] [A user performed suspiciously massive file activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-performed-suspiciously-massive-file-activity)
* \[Informational] [A user printed an unusual number of files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-printed-an-unusual-number-of-files)
* \[Informational] [A user queried AD CS objects via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-queried-ad-cs-objects-via-ldap)
* \[Informational] [A user received multiple weakly encrypted service tickets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-received-multiple-weakly-encrypted-service-tickets)
* \[Informational] [A user requested multiple service tickets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-requested-multiple-service-tickets)
* \[Informational] [A user took numerous screenshots](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-took-numerous-screenshots)
* \[Informational] [A user was added to a Windows security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-was-added-to-a-windows-security-group)
* \[Informational] [AWS Backup recovery point deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-backup-recovery-point-deletion)
* \[Informational] [AWS CloudTrail has been stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudtrail-has-been-stopped)
* \[Informational] [AWS CloudWatch log group deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudwatch-log-group-deletion)
* \[Informational] [AWS CloudWatch log stream deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudwatch-log-stream-deletion)
* \[Informational] [AWS Config Recorder stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-config-recorder-stopped)
* \[Informational] [AWS EBS discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS EBS enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-enumeration-activity)
* \[Informational] [AWS EBS snapshot deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-snapshot-deletion)
* \[Informational] [AWS EC2 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS EC2 infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-infrastructure-enumeration-activity)
* \[Informational] [AWS EC2 instance exported into S3](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-instance-exported-into-s3)
* \[Informational] [AWS Flow Logs deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-flow-logs-deletion)
* \[Informational] [AWS IAM account discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS IAM permission groups discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS IAM resource group deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-iam-resource-group-deletion)
* \[Informational] [AWS Lambda discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS Lambda infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-lambda-infrastructure-enumeration-activity)
* \[Informational] [AWS RDS cluster deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-rds-cluster-deletion)
* \[Informational] [AWS S3 Buckets enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-s3-buckets-enumeration-activity)
* \[Informational] [AWS S3 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS S3 object deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS SES account sending settings modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ses-account-sending-settings-modified)
* \[Informational] [AWS SSM parameters discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-parameters-discovery)
* \[Informational] [AWS SSM parameters retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-parameters-retrieval)
* \[Informational] [AWS SSM send command attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-send-command-attempt)
* \[Informational] [AWS STS temporary credentials were generated](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-sts-temporary-credentials-were-generated)
* \[Informational] [AWS Secrets Manager Access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS Secrets Manager discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-secrets-manager-discovery)
* \[Informational] [AWS SecurityHub findings were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-securityhub-findings-were-modified)
* \[Informational] [AWS Storage Gateway enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-storage-gateway-enumeration)
* \[Informational] [AWS Storage Gateway file share enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-storage-gateway-file-share-enumeration)
* \[Informational] [AWS Transfer Family server created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-transfer-family-server-created)
* \[Informational] [AWS config resource deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-config-resource-deletion)
* \[Informational] [AWS network ACL rule creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-network-acl-rule-creation)
* \[Informational] [AWS network ACL rule deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-network-acl-rule-deletion)
* \[Informational] [AWS root account activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-root-account-activity)
* \[Informational] [AWS user creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-user-creation)
* \[Informational] [Abnormal Allocation of compute resources in multiple regions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-allocation-of-compute-resources-in-multiple-regions)
* \[Informational] [Abnormal Communication to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-to-a-rare-domain)
* \[Informational] [Abnormal Communication to a Rare IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Abnormal File Activity in SCCMContentLib Shared Folder by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user)
* \[Informational] [Abnormal RDP connections to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts)
* \[Informational] [Abnormal Recurring Communications to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain)
* \[Informational] [Abnormal SMB scanning activity to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-smb-scanning-activity-to-multiple-hosts)
* \[Informational] [Abnormal User Login to Domain Controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-user-login-to-domain-controller)
* \[Informational] [Abnormal connections to a dormant host from a newly seen endpoint](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-connections-to-a-dormant-host-from-a-newly-seen-endpoint)
* \[Informational] [Abnormal process connection to default Meterpreter port](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-process-connection-to-default-meterpreter-port)
* \[Informational] [Access to Kubernetes configuration file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubernetes-configuration-file)
* \[Informational] [Activity in a dormant region of a cloud project](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Adding execution privileges](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/adding-execution-privileges)
* \[Informational] [Admin privileges were granted to a Google Workspace user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/admin-privileges-were-granted-to-a-google-workspace-user)
* \[Informational] [Administrator groups enumerated via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/administrator-groups-enumerated-via-ldap)
* \[Informational] [Allocation of multiple cloud compute resources](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/allocation-of-multiple-cloud-compute-resources)
* \[Informational] [An AWS EFS File-share mount was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-efs-file-share-mount-was-deleted)
* \[Informational] [An AWS EFS file-share was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-efs-file-share-was-deleted)
* \[Informational] [An AWS EKS cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-eks-cluster-was-created-or-deleted)
* \[Informational] [An AWS GuardDuty IP set was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-guardduty-ip-set-was-created)
* \[Informational] [An AWS Lambda Function was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-lambda-function-was-created)
* \[Informational] [An AWS Lambda function was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-lambda-function-was-modified)
* \[Informational] [An AWS RDS Global Cluster Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-rds-global-cluster-deletion)
* \[Informational] [An AWS RDS instance was created from a snapshot](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-rds-instance-was-created-from-a-snapshot)
* \[Informational] [An AWS Route 53 domain was transferred to another AWS account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-route-53-domain-was-transferred-to-another-aws-account)
* \[Informational] [An AWS S3 bucket configuration was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-s3-bucket-configuration-was-modified)
* \[Informational] [An AWS SAML provider was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-saml-provider-was-modified)
* \[Informational] [An AWS SES identity was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-ses-identity-was-deleted)
* \[Informational] [An AWS database service master user password was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-database-service-master-user-password-was-changed)
* \[Informational] [An Azure DNS Zone was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-dns-zone-was-modified)
* \[Informational] [An Azure Firewall rule collection group was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-rule-collection-group-was-modified-or-deleted)
* \[Informational] [An Azure Firewall was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-was-modified)
* \[Informational] [An Azure Key Vault key was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-key-vault-key-was-modified)
* \[Informational] [An Azure Key Vault was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-key-vault-was-modified)
* \[Informational] [An Azure Kubernetes Cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-cluster-was-created-or-deleted)
* \[Informational] [An Azure Kubernetes Role or Cluster-Role was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-role-or-cluster-role-was-modified)
* \[Informational] [An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-role-binding-or-cluster-role-binding-was-modified-or-deleted)
* \[Informational] [An Azure Kubernetes Service Account was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-service-account-was-modified-or-deleted)
* \[Informational] [An Azure Network Security Group was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-network-security-group-was-modified)
* \[Informational] [An Azure Point-to-Site VPN was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-point-to-site-vpn-was-modified)
* \[Informational] [An Azure Suppression Rule was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-suppression-rule-was-created)
* \[Informational] [An Azure VPN Connection was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-vpn-connection-was-modified)
* \[Informational] [An Azure application reached a throttling API rate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-application-reached-a-throttling-api-rate)
* \[Informational] [An Azure firewall rule group was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-rule-group-was-modified)
* \[Informational] [An Azure identity performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-identity-performed-multiple-actions-that-were-denied)
* \[Informational] [An Azure virtual network Device was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-virtual-network-device-was-modified)
* \[Informational] [An Azure virtual network was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-virtual-network-was-modified)
* \[Informational] [An EBS snapshot block was downloaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-ebs-snapshot-block-was-downloaded)
* \[Informational] [An Email address was added to AWS SES](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-email-address-was-added-to-aws-ses)
* \[Informational] [An IAM group was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-iam-group-was-created)
* \[Informational] [An app was added to Google Marketplace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-added-to-google-marketplace)
* \[Informational] [An app was added to the Google Workspace trusted OAuth apps list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-added-to-the-google-workspace-trusted-oauth-apps-list)
* \[Informational] [An app was removed from a blocked list in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-removed-from-a-blocked-list-in-google-workspace)
* \[Informational] [An identity accessed Azure Kubernetes Secrets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-azure-kubernetes-secrets)
* \[Informational] [An identity accessed a backup cloud storage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-a-backup-cloud-storage)
* \[Informational] [An identity accessed a cloud storage for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-a-cloud-storage-for-the-first-time)
* \[Informational] [An identity accessed cloud storage containing sensitive data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [An identity attached an administrative policy to an IAM user or role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role)
* \[Informational] [An identity created or updated password for an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user)
* \[Informational] [An identity disabled bucket logging](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-disabled-bucket-logging)
* \[Informational] [An identity initiated a download of multiple cloud objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects)
* \[Informational] [An identity performed a suspicious download of multiple cloud storage objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objects)
* \[Informational] [An identity started an AWS SSM session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-started-an-aws-ssm-session)
* \[Informational] [An identity was granted permissions to manage user access to Azure resources](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-was-granted-permissions-to-manage-user-access-to-azure-resources)
* \[Informational] [An operation was performed by an identity from a domain that was not seen in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organization)
* \[Informational] [An uncommon file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-added-to-startup-related-registry-keys)
* \[Informational] [An uncommon file was created in the startup folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-was-created-in-the-startup-folder)
* \[Informational] [An unknown account was invited to the AWS organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unknown-account-was-invited-to-the-aws-organization)
* \[Informational] [An unusual archive file creation by a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-archive-file-creation-by-a-user)
* \[Informational] [An unusual cloud identity was granted permissions to a BigQuery resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-cloud-identity-was-granted-permissions-to-a-bigquery-resource)
* \[Informational] [An unusual read activity of cloud object](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-read-activity-of-cloud-object)
* \[Informational] [AppleScript executed a shell script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-executed-a-shell-script)
* \[Informational] [AppleScript interpreter dynamic library loaded into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process)
* \[Informational] [AppleScript process executed with a rare command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-process-executed-with-a-rare-command-line)
* \[Informational] [Attempted Azure application access from unknown tenant](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/attempted-azure-application-access-from-unknown-tenant)
* \[Informational] [Aurora DB cluster stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aurora-db-cluster-stopped)
* \[Informational] [Authentication Attempt From a Dormant Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-from-a-dormant-account)
* \[Informational] [Authentication method added to an Azure account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-method-added-to-an-azure-account)
* \[Informational] [Authentication method was added to Azure account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-method-was-added-to-azure-account)
* \[Informational] [Azure AD PIM elevation request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-elevation-request)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
* \[Informational] [Azure Automation Account Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-account-creation)
* \[Informational] [Azure Automation Runbook Creation/Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-creation-modification)
* \[Informational] [Azure Automation Runbook Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-deletion)
* \[Informational] [Azure Automation Webhook creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-webhook-creation)
* \[Informational] [Azure Blob Container Access Level Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-blob-container-access-level-modification)
* \[Informational] [Azure Event Hub Authorization rule creation/modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-event-hub-authorization-rule-creation-modification)
* \[Informational] [Azure Key Vault Secrets were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-secrets-were-modified)
* \[Informational] [Azure Key Vault modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-modification)
* \[Informational] [Azure Kubernetes events were deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-kubernetes-events-were-deleted)
* \[Informational] [Azure Resource Group Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-resource-group-deletion)
* \[Informational] [Azure Service principal/Application creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-service-principal-application-creation)
* \[Informational] [Azure Storage Account key generated](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-key-generated)
* \[Informational] [Azure Temporary Access Pass (TAP) registered to an account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-temporary-access-pass-tap-registered-to-an-account)
* \[Informational] [Azure account creation by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-creation-by-a-non-standard-account)
* \[Informational] [Azure application URI modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-uri-modification)
* \[Informational] [Azure application consent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-consent)
* \[Informational] [Azure application credentials added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-credentials-added)
* \[Informational] [Azure application removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-removed)
* \[Informational] [Azure conditional access policy creation or modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-conditional-access-policy-creation-or-modification)
* \[Informational] [Azure device code authentication flow used](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-device-code-authentication-flow-used)
* \[Informational] [Azure diagnostic configuration deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-diagnostic-configuration-deletion)
* \[Informational] [Azure enumeration activity using Microsoft Graph API](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-enumeration-activity-using-microsoft-graph-api)
* \[Informational] [Azure group creation/deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-group-creation-deletion)
* \[Informational] [Azure mailbox rule creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-mailbox-rule-creation)
* \[Informational] [Azure permission delegation granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-permission-delegation-granted)
* \[Informational] [Azure service principal assigned app role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-service-principal-assigned-app-role)
* \[Informational] [Azure storage account blob anonymous access is enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-blob-anonymous-access-is-enabled)
* \[Informational] [Azure storage account cross-tenant object replication was enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-cross-tenant-object-replication-was-enabled)
* \[Informational] [Azure storage account was publicly shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-was-publicly-shared)
* \[Informational] [Azure uncommon increase in API request sizes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Azure user creation/deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-user-creation-deletion)
* \[Informational] [Azure user password reset](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-user-password-reset)
* \[Informational] [Azure virtual machine commands execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-virtual-machine-commands-execution)
* \[Informational] [BigQuery table or query results exfiltrated to a foreign project](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bigquery-table-or-query-results-exfiltrated-to-a-foreign-project)
* \[Informational] [BitLocker key retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitlocker-key-retrieval)
* \[Informational] [Browser Extension Installed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/browser-extension-installed)
* \[Informational] [Browser bookmark files accessed by a rare non-browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/browser-bookmark-files-accessed-by-a-rare-non-browser-process)
* \[Informational] [Brute-force attempt on a local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/brute-force-attempt-on-a-local-account)
* \[Informational] [Bucket's block public access setting turned off](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bucket-s-block-public-access-setting-turned-off)
* \[Informational] [Bucket's object ownership controls were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bucket-s-object-ownership-controls-were-modified)
* \[Informational] [Cloud Organizational policy was created or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-organizational-policy-was-created-or-modified)
* \[Informational] [Cloud Watch alarm deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-watch-alarm-deletion)
* \[Informational] [Cloud access key creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-access-key-creation)
* \[Informational] [Cloud compute serial console access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-serial-console-access)
* \[Informational] [Cloud compute volume creation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-volume-creation-attempt)
* \[Informational] [Cloud email infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-email-infrastructure-enumeration-activity)
* \[Informational] [Cloud email sending was enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-email-sending-was-enabled)
* \[Informational] [Cloud email service activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-email-service-activity)
* \[Informational] [Cloud identity reached a throttling API rate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-identity-reached-a-throttling-api-rate)
* \[Informational] [Cloud impersonation attempt by unusual identity type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-impersonation-attempt-by-unusual-identity-type)
* \[Informational] [Cloud infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-infrastructure-enumeration-activity)
* \[Informational] [Cloud instance creation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-instance-creation-attempt)
* \[Informational] [Cloud instance deletion attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-instance-deletion-attempt)
* \[Informational] [Cloud resource logging was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-resource-logging-was-disabled)
* \[Informational] [Cloud snapshot created or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-snapshot-created-or-modified)
* \[Informational] [Cloud storage automatic backup disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-storage-automatic-backup-disabled)
* \[Informational] [Cloud storage delete protection disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-storage-delete-protection-disabled)
* \[Informational] [Cloud storage object discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Cloud user performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied)
* \[Informational] [CloudTrail logging deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloudtrail-logging-deletion)
* \[Informational] [Command execution in a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-in-a-kubernetes-pod)
* \[Informational] [Command execution via wmiexec](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-via-wmiexec)
* \[Informational] [Common third-party software name masquerading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-third-party-software-name-masquerading)
* \[Informational] [Commonly abused AutoIT script drops an executable file to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-autoit-script-drops-an-executable-file-to-disk)
* \[Informational] [Commonly abused process launched as a system service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-process-launched-as-a-system-service)
* \[Informational] [Creation or modification of the default command executed when opening an application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/creation-or-modification-of-the-default-command-executed-when-opening-an-application)
* \[Informational] [Credentials were added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/credentials-were-added-to-azure-application)
* \[Informational] [DLP sensitive data exposed to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dlp-sensitive-data-exposed-to-external-users)
* \[Informational] [DSC (Desired State Configuration) lateral movement using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dsc-desired-state-configuration-lateral-movement-using-powershell)
* \[Informational] [Data Sharing between GCP and Google Workspace was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-sharing-between-gcp-and-google-workspace-was-disabled)
* \[Informational] [Data encryption was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-encryption-was-disabled)
* \[Informational] [Deletion of AD CS certificate database entries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/deletion-of-ad-cs-certificate-database-entries)
* \[Informational] [Deletion of multiple cloud resources](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/deletion-of-multiple-cloud-resources)
* \[Informational] [Denied API call by a Kubernetes service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/denied-api-call-by-a-kubernetes-service-account)
* \[Informational] [Device Registration Policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/device-registration-policy-modification)
* \[Informational] [Discovery of host users via WMIC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-host-users-via-wmic)
* \[Informational] [Download pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [EBS snapshots were created from an EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance)
* \[Informational] [EBS volume detachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-detachment-attempt)
  * \[Informational] EBS volume detachment attempt using Cloud Formation or Terraform - Modified Metadata
* \[Informational] [EC2 instance Amazon machine image was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ec2-instance-amazon-machine-image-was-created)
* \[Informational] [EC2 snapshot attribute has been modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email has a short body or subject and was sent from an external source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email was received from an unknown sender using a recognized domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Informational] [Exchange compliance search created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-compliance-search-created)
* \[Informational] [Exchange email-hiding inbox rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-email-hiding-inbox-rule)
* \[Informational] [Exchange email-hiding transport rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-email-hiding-transport-rule)
* \[Informational] [Exchange inbox forwarding rule configured](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-inbox-forwarding-rule-configured)
* \[Informational] [Exchange mailbox delegation permissions added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-delegation-permissions-added)
* \[Informational] [Exchange mailbox folder permission modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/exchange-mailbox-folder-permission-modification)
* \[Informational] [Execution of an uncommon process at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage)
* \[Informational] [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage)
* \[Informational] [Execution of masqueraded third-party utility](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-masqueraded-third-party-utility)
* \[Informational] [Execution of renamed lolbin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-renamed-lolbin)
* \[Informational] [External Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-login-password-spray)
* \[Informational] [External SaaS file-sharing activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-saas-file-sharing-activity)
* \[Informational] [External Sharing was turned on for Google Drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-sharing-was-turned-on-for-google-drive)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [External user added a link to a Microsoft Teams chat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-added-a-link-to-a-microsoft-teams-chat)
* \[Informational] [External user invitation to Azure tenant](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-invitation-to-azure-tenant)
* \[Informational] [External user started a Microsoft Teams conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-started-a-microsoft-teams-conversation)
* \[Informational] [Failed Login For Locked-Out Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-login-for-locked-out-account)
* \[Informational] [Failed Login For a Long Username With Special Characters](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-login-for-a-long-username-with-special-characters)
* \[Informational] [File transfer from unusual IP using known tools](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/file-transfer-from-unusual-ip-using-known-tools)
* \[Informational] [First SSO Resource Access in the Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-resource-access-in-the-organization)
* \[Informational] [First SSO access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-for-user)
* \[Informational] [First SSO access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-in-organization)
* \[Informational] [First VPN access attempt from a country in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-attempt-from-a-country-in-organization)
* \[Informational] [First VPN access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-for-user)
* \[Informational] [First VPN access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-in-organization)
* \[Informational] [First connection from a country in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-connection-from-a-country-in-organization)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Foreign account was granted permissions to S3 bucket via resource-based policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/foreign-account-was-granted-permissions-to-s3-bucket-via-resource-based-policy)
* \[Informational] [GCP Firewall Rule Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-firewall-rule-modification)
* \[Informational] [GCP Firewall Rule creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-firewall-rule-creation)
* \[Informational] [GCP IAM Role Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-iam-role-deletion)
* \[Informational] [GCP IAM Service Account Key Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-iam-service-account-key-deletion)
* \[Informational] [GCP Logging Bucket Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-bucket-deletion)
* \[Informational] [GCP Pub/Sub Subscription Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-pub-sub-subscription-deletion)
* \[Informational] [GCP Pub/Sub Topic Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-pub-sub-topic-deletion)
* \[Informational] [GCP Service Account Disable](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-disable)
* \[Informational] [GCP Service Account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-creation)
* \[Informational] [GCP Service Account deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-deletion)
* \[Informational] [GCP Service Account key creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-key-creation)
* \[Informational] [GCP Storage Bucket Configuration Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-configuration-modification)
* \[Informational] [GCP Storage Bucket Permissions Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-permissions-modification)
* \[Informational] [GCP Storage Bucket deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-deletion)
* \[Informational] [GCP VPC Firewall Rule Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-vpc-firewall-rule-deletion)
* \[Informational] [GCP Virtual Private Cloud (VPC) Network Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-cloud-vpc-network-deletion)
* \[Informational] [GCP Virtual Private Network Route Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-network-route-creation)
* \[Informational] [GCP Virtual Private Network Route Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-network-route-deletion)
* \[Informational] [GCP administrative role granted to a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-administrative-role-granted-to-a-cloud-identity)
* \[Informational] [GCP logging sink deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-sink-deletion)
* \[Informational] [GCP sensitive Cloud Run role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-cloud-run-role-granted)
* \[Informational] [GCP sensitive Deployment Manager role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-deployment-manager-role-granted)
* \[Informational] [GCP sensitive Functions role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-functions-role-granted)
* \[Informational] [GCP sensitive IAM role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-iam-role-granted)
* \[Informational] [GCP sensitive Secret Manager role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-secret-manager-role-granted)
* \[Informational] [GCP sensitive compute role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-compute-role-granted)
* \[Informational] [GCP sensitive storage role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-storage-role-granted)
* \[Informational] [GCP set IAM policy activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-set-iam-policy-activity)
* \[Informational] [Globally uncommon IP address by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256)
* \[Informational] [Globally uncommon IP address connection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-connection-from-a-signed-process)
* \[Informational] [Globally uncommon high entropy module was loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-module-was-loaded)
* \[Informational] [Globally uncommon high entropy process was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-process-was-executed)
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
* \[Informational] [Globally uncommon injection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-injection-from-a-signed-process)
* \[Informational] [Globally uncommon process execution from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-process-execution-from-a-signed-process)
* \[Informational] [Globally uncommon root-domain port combination by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-by-a-common-process-sha256)
* \[Informational] [Gmail delegation was turned on for the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gmail-delegation-was-turned-on-for-the-organization)
* \[Informational] [Gmail routing settings changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gmail-routing-settings-changed)
* \[Informational] [Google Marketplace restrictions were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-marketplace-restrictions-were-modified)
* \[Informational] [Google Workspace organizational unit was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-organizational-unit-was-modified)
* \[Informational] [Google Workspace third-party application's security settings were changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-third-party-application-s-security-settings-were-changed)
* \[Informational] [Granting Access to an Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/granting-access-to-an-account)
* \[Informational] [Hidden Attribute was added to a file using attrib.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hidden-attribute-was-added-to-a-file-using-attrib-exe)
* \[Informational] [IAM Enumeration sequence](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-enumeration-sequence)
* \[Informational] [IAM User added to an IAM group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-user-added-to-an-iam-group)
* \[Informational] [IAM inline policy was added to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-group)
* \[Informational] [IAM inline policy was added to role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-role)
* \[Informational] [IAM inline policy was added to user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-user)
* \[Informational] [IAM instance profile associations were described](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-associations-were-described)
* \[Informational] [IAM instance profile was associated with EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-associated-with-ec2-instance)
* \[Informational] [IAM instance profile was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-created)
* \[Informational] [IAM instance profile was replaced for EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-replaced-for-ec2-instance)
* \[Informational] [IAM instance profiles were listed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [IAM policy default version was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-default-version-was-changed)
* \[Informational] [IAM policy version was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-version-was-created)
* \[Informational] [IAM policy was attached to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-was-attached-to-group)
* \[Informational] [IAM policy was attached to role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-was-attached-to-role)
* \[Informational] [IAM role trust policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-trust-policy-modification)
* \[Informational] [IAM role was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-was-created)
* \[Informational] [IAM role-attached managed policies were listed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-attached-managed-policies-were-listed)
* \[Informational] [IP Rotation Pattern in SSO Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ip-rotation-pattern-in-sso-spray)
* \[Informational] [Identity assigned an Azure AD Administrator Role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/identity-assigned-an-azure-ad-administrator-role)
* \[Informational] [Increase in Job-Related Site Visits](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/increase-in-job-related-site-visits)
* \[Informational] [Indicator blocking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indicator-blocking)
* \[Informational] [Injection into rundll32.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/injection-into-rundll32-exe)
* \[Informational] [Intense SSO failures](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/intense-sso-failures)
* \[Informational] [Interactive login by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-by-a-machine-account)
* \[Informational] [Interactive login from a shared user account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-from-a-shared-user-account)
* \[Informational] [Internal Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/internal-login-password-spray)
* \[Informational] [Iptables configuration command was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iptables-configuration-command-was-executed)
* \[Informational] [Kerberos Pre-Auth Failures by User and Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-pre-auth-failures-by-user-and-host)
* \[Informational] [Key credential attribute modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/key-credential-attribute-modification)
* \[Informational] [Kubernetes Pod Created With Sensitive Volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-created-with-sensitive-volume)
* \[Informational] [Kubernetes Pod Created with host Inter Process Communications (IPC) namespace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-created-with-host-inter-process-communications-ipc-namespace)
* \[Informational] [Kubernetes Pod created with host process ID (PID) namespace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-created-with-host-process-id-pid-namespace)
* \[Informational] [Kubernetes Privileged Pod Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-privileged-pod-creation)
* \[Informational] [Kubernetes admission controller activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-admission-controller-activity)
* \[Informational] [Kubernetes cluster events deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-cluster-events-deletion)
* \[Informational] [Kubernetes enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-enumeration-activity)
* \[Informational] [Kubernetes environment enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-environment-enumeration-activity)
* \[Informational] [Kubernetes network policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-network-policy-modification)
* \[Informational] [Kubernetes nsenter container escape](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-nsenter-container-escape)
* \[Informational] [Kubernetes pod creation with host network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-pod-creation-with-host-network)
* \[Informational] [Kubernetes service account activity outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-service-account-activity-outside-the-cluster)
* \[Informational] [Kubernetes version disclosure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-version-disclosure)
* \[Informational] [LDAP traffic from non-standard process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-traffic-from-non-standard-process)
* \[Informational] [LOLBAS executable injects into another process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbas-executable-injects-into-another-process)
* \[Informational] [LOLBIN created a PSScriptPolicyTest PowerShell script file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-created-a-psscriptpolicytest-powershell-script-file)
* \[Informational] [Linux local user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-local-user-account-creation)
* \[Informational] [Linux network share discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-network-share-discovery)
* \[Informational] [Linux process execution with a rare GitHub URL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-process-execution-with-a-rare-github-url)
* \[Informational] [Local account discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-account-discovery)
* \[Informational] [Local group enumeration via RPC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration-via-rpc)
* \[Informational] [Local user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-account-creation)
* \[Informational] [Local user enumeration via SAMR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-enumeration-via-samr)
* \[Informational] [Log enumeration via cloud native logging service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/log-enumeration-via-cloud-native-logging-service)
* \[Informational] [Login by a dormant user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/login-by-a-dormant-user)
* \[Informational] [MFA device was removed/deactivated from an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-device-was-removed-deactivated-from-an-iam-user)
* \[Informational] [MSI accessed a web page running a server-side script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script)
* \[Informational] [Mailbox enumeration activity by Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mailbox-enumeration-activity-by-azure-application)
* \[Informational] [Massive file activity abnormal to process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-activity-abnormal-to-process)
* \[Informational] [Massive file compression by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-compression-by-user)
* \[Informational] [Massive file downloads from SaaS service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-downloads-from-saas-service)
* \[Informational] [Massive upload to SaaS service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-upload-to-saas-service)
* \[Informational] [Massive upload to a rare storage or mail domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain)
* \[Informational] [Member added to a Windows local security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/member-added-to-a-windows-local-security-group)
* \[Informational] [Microsoft 365 DLP policy disabled or removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-365-dlp-policy-disabled-or-removed)
* \[Informational] [Microsoft Configuration Manager device registration and policy request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-configuration-manager-device-registration-and-policy-request)
* \[Informational] [Microsoft OneDrive enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-onedrive-enumeration-activity)
* \[Informational] [Microsoft OneNote enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-onenote-enumeration-activity)
* \[Informational] [Microsoft SharePoint enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-sharepoint-enumeration-activity)
* \[Informational] [Microsoft Teams application setup policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-application-setup-policy-was-modified)
* \[Informational] [Microsoft Teams enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-enumeration-activity)
* \[Informational] [Microsoft Teams external communication policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-external-communication-policy-was-modified)
* \[Informational] [Microsoft Teams messages were exported from conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-messages-were-exported-from-conversation)
* \[Informational] [Modification of PAM](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-pam)
* \[Informational] [Modification or Deletion of an Azure Application Gateway Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-or-deletion-of-an-azure-application-gateway-detected)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Msiexec execution of an executable from an uncommon remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msiexec-execution-of-an-executable-from-an-uncommon-remote-location)
* \[Informational] [Multi region enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multi-region-enumeration-activity)
* \[Informational] [Multiple Okta MFA requests sent to a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-okta-mfa-requests-sent-to-a-user)
* \[Informational] [Multiple Rare Process Executions in Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-rare-process-executions-in-organization)
* \[Informational] [Multiple TGT requests for users without Kerberos pre-authentication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-tgt-requests-for-users-without-kerberos-pre-authentication)
* \[Informational] [Multiple cloud snapshots export](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-cloud-snapshots-export)
* \[Informational] [Multiple discovery commands on a Linux host by the same process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands-on-a-linux-host-by-the-same-process)
* \[Informational] [Multiple discovery-like commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-like-commands)
* \[Informational] [Multiple failed logins from a single IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-failed-logins-from-a-single-ip)
* \[Informational] [Multiple user accounts were deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-were-deleted)
* \[Informational] [Multiple users authenticated with weak NTLM to a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-users-authenticated-with-weak-ntlm-to-a-host)
* \[Informational] [NTLM Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force)
* \[Informational] [NTLM Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-password-spray)
* \[Informational] [NTLM Relay](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-relay)
* \[Informational] [Network sniffing detected in Cloud environment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/network-sniffing-detected-in-cloud-environment)
* \[Informational] [New Teams application published to the organization catalog](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-teams-application-published-to-the-organization-catalog)
* \[Informational] [New process created via a WMI call](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Object versioning was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/object-versioning-was-disabled)
* \[Informational] [Okta API Token Created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-api-token-created)
* \[Informational] [Okta Reported Threat Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-reported-threat-detected)
* \[Informational] [Okta User Session Impersonation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-user-session-impersonation)
* \[Informational] [Okta account reset password attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-reset-password-attempt)
* \[Informational] [Okta account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock)
* \[Informational] [Okta account unlock by admin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock-by-admin)
* \[Informational] [Okta admin privilege assignment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-admin-privilege-assignment)
* \[Informational] [Okta device assignment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-device-assignment)
* \[Informational] [OneDrive file download](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/onedrive-file-download)
* \[Informational] [OneDrive file upload](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/onedrive-file-upload)
* \[Informational] [OneDrive folder creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/onedrive-folder-creation)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Owner added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/owner-added-to-azure-application)
* \[Informational] [Owner was added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/owner-was-added-to-azure-application)
* \[Informational] [PIM privilege member removal](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/pim-privilege-member-removal)
* \[Informational] [PKINIT TGT authentication request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/pkinit-tgt-authentication-request)
* \[Informational] [Penetration testing tool activity attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/penetration-testing-tool-activity-attempt)
* \[Informational] [Penetration testing tool attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Permission Groups discovery commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/permission-groups-discovery-commands)
* \[Informational] [Ping to localhost from an uncommon, unsigned parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ping-to-localhost-from-an-uncommon-unsigned-parent-process)
* \[Informational] [Port Scan](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-scan)
* \[Informational] [Possible Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-attempt)
* \[Informational] [Possible DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-hijack-into-a-microsoft-process)
* \[Informational] [Possible DLL Side-Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Possible Email collection using Outlook RPC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-email-collection-using-outlook-rpc)
* \[Informational] [Possible GPO Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-gpo-enumeration)
* \[Informational] [Possible IPFS traffic was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ipfs-traffic-was-detected)
* \[Informational] [Possible Impossible Travel Pattern - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-impossible-travel-pattern-sso)
* \[Informational] [Possible LDAP Enumeration Tool Usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-tool-usage)
* \[Informational] [Possible LDAP Enumeration of Microsoft Configuration Manager](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-of-microsoft-configuration-manager)
* \[Informational] [Possible LDAP enumeration by unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-by-unsigned-process)
* \[Informational] [Possible Privilege Escalation using Delegated MSA account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-privilege-escalation-using-delegated-msa-account)
* \[Informational] [Possible SPN enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-spn-enumeration)
* \[Informational] [Possible TGT reuse from different hosts (pass the ticket)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-tgt-reuse-from-different-hosts-pass-the-ticket)
* \[Informational] [Possible authentication coercion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-authentication-coercion)
* \[Informational] [Possible binary padding using dd](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-binary-padding-using-dd)
* \[Informational] [Possible brute force on sudo user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-on-sudo-user)
* \[Informational] [Possible data exfiltration over a USB storage device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-data-exfiltration-over-a-usb-storage-device)
* \[Informational] [Possible data obfuscation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-data-obfuscation)
* \[Informational] [Possible internal data exfiltration over a USB storage device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-internal-data-exfiltration-over-a-usb-storage-device)
* \[Informational] [Possible use of IPFS was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-use-of-ipfs-was-detected)
* \[Informational] [Possible use of a networking driver for network sniffing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-use-of-a-networking-driver-for-network-sniffing)
* \[Informational] [Potential DCSync by an unusual user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-dcsync-by-an-unusual-user)
* \[Informational] [Potential NTLM Relay Attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-ntlm-relay-attack)
* \[Informational] [Potential Okta access limit breach](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-okta-access-limit-breach)
* \[Informational] [Potential creation of persistent cloud credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-creation-of-persistent-cloud-credentials)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [PowerShell pfx certificate extraction](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-pfx-certificate-extraction)
* \[Informational] [Privileged certificate request via certificate template](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/privileged-certificate-request-via-certificate-template)
* \[Informational] [Privileged role used by Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/privileged-role-used-by-azure-application)
* \[Informational] [PsExec was executed with a suspicious command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/psexec-was-executed-with-a-suspicious-command-line)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Python HTTP server started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/python-http-server-started)
* \[Informational] [Rare AppID usage to a rare destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-appid-usage-to-a-rare-destination)
* \[Informational] [Rare DCOM RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dcom-rpc-activity)
* \[Informational] [Rare DLP rule match by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dlp-rule-match-by-user)
* \[Informational] [Rare LOLBIN Process Execution by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-lolbin-process-execution-by-user)
* \[Informational] [Rare MS-Update Server was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-server-was-detected)
* \[Informational] [Rare MS-Update traffic over HTTP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-traffic-over-http)
* \[Informational] [Rare NTLM Access By User To Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-access-by-user-to-host)
* \[Informational] [Rare NTLM Usage by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-usage-by-user)
* \[Informational] [Rare Remote Service (SVCCTL) RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-remote-service-svcctl-rpc-activity)
* \[Informational] [Rare SMTP/S Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-smtp-s-session)
* \[Informational] [Rare Scheduled Task RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-rpc-activity)
* \[Informational] [Rare Unix process divided files by size](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unix-process-divided-files-by-size)
* \[Informational] [Rare WinRM Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-winrm-session)
* \[Informational] [Rare access to known advertising domains](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-access-to-known-advertising-domains)
* \[Informational] [Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-connection-to-external-ip-address-or-host-by-an-application-using-rmi-iiop-or-ldap-protocol)
* \[Informational] [Rare machine account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-machine-account-creation)
* \[Informational] [Rare process accessed a Keychain file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-accessed-a-keychain-file)
* \[Informational] [Rare process execution by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-execution-by-user)
* \[Informational] [Rare process execution in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-execution-in-organization)
* \[Informational] [Rare process spawned by srvany.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-spawned-by-srvany-exe)
* \[Informational] [Rare signature signed executable executed in the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-signature-signed-executable-executed-in-the-network)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Registration of Uncommon .NET Services and/or Assemblies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/registration-of-uncommon-net-services-and-or-assemblies)
* \[Informational] [Remote PsExec-like command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-psexec-like-command-execution)
* \[Informational] [Remote account enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-account-enumeration)
* \[Informational] [Remote code execution into Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-code-execution-into-kubernetes-pod)
* \[Informational] [Remote usage of AWS Lambda's role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-aws-lambda-s-role)
* \[Informational] [Remote usage of VM Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-vm-service-account-token)
* \[Informational] [Remote usage of an App engine Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-app-engine-service-account-token)
* \[Informational] [Remote usage of an Azure Service Principal token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-service-principal-token)
* \[Informational] [Removal of an Azure Owner from an Application or Service Principal](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/removal-of-an-azure-owner-from-an-application-or-service-principal)
* \[Informational] [Retrieval of cloud compute EC2 instance user data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/retrieval-of-cloud-compute-ec2-instance-user-data)
* \[Informational] [Run downloaded script using pipe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/run-downloaded-script-using-pipe)
* \[Informational] [S3 configuration deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/s3-configuration-deletion)
* \[Informational] [SCCM log files enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sccm-log-files-enumeration)
* \[Informational] [SSH authentication brute force attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ssh-authentication-brute-force-attempts)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [SSO Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-password-spray)
* \[Informational] [SSO with abnormal operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-operating-system)
* \[Informational] [SSO with abnormal user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-user-agent)
* \[Informational] [SSO with new operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-new-operating-system)
* \[Informational] [SaaS suspicious external domain user activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/saas-suspicious-external-domain-user-activity)
* \[Informational] [Scrcons.exe Rare Child Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scrcons-exe-rare-child-process)
* \[Informational] [Security tools detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/security-tools-detection-attempt)
* \[Informational] [Sensitive Exchange mail sent to external users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-exchange-mail-sent-to-external-users)
* \[Informational] [Sensitive account password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-account-password-reset-attempt)
* \[Informational] [Serial console access was enabled in AWS account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/serial-console-access-was-enabled-in-aws-account)
* \[Informational] [Service execution via sc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/service-execution-via-sc-exe)
* \[Informational] [SharePoint Site Collection admin group addition](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sharepoint-site-collection-admin-group-addition)
* \[Informational] [Short-lived Azure AD user account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/short-lived-azure-ad-user-account)
* \[Informational] [Signed process performed an unpopular DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-dll-injection)
* \[Informational] [Signed process performed an unpopular injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-injection)
* \[Informational] [Single account excessively locked out](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/single-account-excessively-locked-out)
* \[Informational] [Soft delete of cloud storage configuration was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/soft-delete-of-cloud-storage-configuration-was-disabled)
* \[Informational] [Space after filename](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/space-after-filename)
* \[Informational] [Storage enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/storage-enumeration-activity)
* \[Informational] [Successful unusual guest user invitation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/successful-unusual-guest-user-invitation)
* \[Informational] [Suspicious AMSI decode attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-amsi-decode-attempt)
* \[Informational] [Suspicious Azure AD interactive sign-in using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-azure-ad-interactive-sign-in-using-powershell)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
* \[Informational] [Suspicious DNS traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dns-traffic)
* \[Informational] [Suspicious External RDP Login](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-external-rdp-login)
* \[Informational] [Suspicious MFA request reported by user in Entra ID](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-mfa-request-reported-by-user-in-entra-id)
* \[Informational] [Suspicious NTLM authentication with machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ntlm-authentication-with-machine-account)
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
* \[Informational] [Suspicious SSO access from ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-access-from-asn)
* \[Informational] [Suspicious SSO authentication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-authentication)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [Suspicious access to cloud credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-cloud-credential-files)
* \[Informational] [Suspicious access to shadow file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-shadow-file)
* \[Informational] [Suspicious active setup registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-active-setup-registered)
* \[Informational] [Suspicious certificate template modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certificate-template-modification)
* \[Informational] [Suspicious cloud compute instance SSH keys modification attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-cloud-compute-instance-ssh-keys-modification-attempt)
* \[Informational] [Suspicious container reconnaissance activity in a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-reconnaissance-activity-in-a-kubernetes-pod)
* \[Informational] [Suspicious container runtime connection from within a Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-runtime-connection-from-within-a-kubernetes-pod)
* \[Informational] [Suspicious curl user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-curl-user-agent)
* \[Informational] [Suspicious docker image download from an unusual repository](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-docker-image-download-from-an-unusual-repository)
* \[Informational] [Suspicious domain user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-domain-user-account-creation)
* \[Informational] [Suspicious process accessed a site masquerading as Google](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-accessed-a-site-masquerading-as-google)
* \[Informational] [Suspicious process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-executed-with-a-high-integrity-level)
* \[Informational] [Suspicious process execution from tmp folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-execution-from-tmp-folder)
* \[Informational] [Suspicious process execution in a privileged container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-execution-in-a-privileged-container)
* \[Informational] [Suspicious process loads a known PowerShell module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-loads-a-known-powershell-module)
* \[Informational] [Suspicious proxy environment variable setting](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-proxy-environment-variable-setting)
* \[Informational] [Suspicious reconnaissance using LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-reconnaissance-using-ldap)
* \[Informational] [Suspicious secrets dump activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-secrets-dump-activity)
* \[Informational] [Suspicious successful RDP connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-successful-rdp-connection-to-localhost)
* \[Informational] [Suspicious theme and sentiment in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-theme-and-sentiment-in-email)
* \[Informational] [Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-microsoft-s-active-directory-powershell-module-remote-discovery-cmdlet)
* \[Informational] [System profiling WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-profiling-wmi-query-execution)
* \[Informational] [System shutdown or reboot](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-shutdown-or-reboot)
* \[Informational] [Tampering with Internet Explorer Protected Mode configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-internet-explorer-protected-mode-configuration)
* \[Informational] [Tampering with the Windows User Account Controls (UAC) configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-the-windows-user-account-controls-uac-configuration)
* \[Informational] [Uncommon DotNet module load relationship](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dotnet-module-load-relationship)
* \[Informational] [Uncommon GetClipboardData API function invocation of a possible information stealer](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-getclipboarddata-api-function-invocation-of-a-possible-information-stealer)
* \[Informational] [Uncommon Linux remote shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-remote-shell-command-execution)
* \[Informational] [Uncommon Linux shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-shell-command-execution)
* \[Informational] [Uncommon Managed Object Format (MOF) compiler usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-managed-object-format-mof-compiler-usage)
* \[Informational] [Uncommon RDP connection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-rdp-connection)
* \[Informational] [Uncommon SQL like command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sql-like-command-line)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Uncommon WPAD queries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-wpad-queries)
* \[Informational] [Uncommon access to cloud platforms' sensitive files by a scripting engine](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine)
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
* \[Informational] [Uncommon browser extension loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-browser-extension-loaded)
* \[Informational] [Uncommon cloud CLI tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-cloud-cli-tool-usage)
* \[Informational] [Uncommon communication to an instant messaging server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-communication-to-an-instant-messaging-server)
* \[Informational] [Uncommon kernel module load](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-kernel-module-load)
* \[Informational] [Uncommon macOS shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-macos-shell-command-execution)
* \[Informational] [Uncommon net group command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-group-command-execution)
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
* \[Informational] [Uncommon net localgroup execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-execution)
* \[Informational] [Uncommon network tunnel creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-network-tunnel-creation)
* \[Informational] [Uncommon recurring rare external host access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-recurring-rare-external-host-access)
* \[Informational] [Uncommon sensitive filesystem registry hive access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-filesystem-registry-hive-access)
* \[Informational] [Uncommon service stop operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-service-stop-operation)
* \[Informational] [Uncommon user management via net.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-user-management-via-net-exe)
* \[Informational] [Unique client computer model was detected via MS-Update protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol)
* \[Informational] [Unpopular URL(s) detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unpopular rsync process execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-rsync-process-execution)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unsigned DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-hijack-into-a-microsoft-process)
* \[Informational] [Unusual ADConnect database file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-adconnect-database-file-access)
* \[Informational] [Unusual AWS CLI/SDK activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-cli-sdk-activity)
* \[Informational] [Unusual AWS systems manager activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-systems-manager-activity)
* \[Informational] [Unusual Conditional Access operation for an identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-conditional-access-operation-for-an-identity)
* \[Informational] [Unusual DB process spawning a shell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-db-process-spawning-a-shell)
* \[Informational] [Unusual IAM enumeration activity by a non-user Identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-iam-enumeration-activity-by-a-non-user-identity)
* \[Informational] [Unusual Identity and Access Management (IAM) activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-identity-and-access-management-iam-activity)
* \[Informational] [Unusual Kubernetes secret access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-secret-access)
* \[Informational] [Unusual Kubernetes service account file read](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-service-account-file-read)
* \[Informational] [Unusual SSH Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ssh-activity)
* \[Informational] [Unusual SSH activity that resembles SSH proxy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ssh-activity-that-resembles-ssh-proxy)
* \[Informational] [Unusual access to Microsoft 365 storage services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-microsoft-365-storage-services)
* \[Informational] [Unusual access to the AD Sync credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-the-ad-sync-credential-files)
* \[Informational] [Unusual access to the Windows Internal Database on an ADFS server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-the-windows-internal-database-on-an-adfs-server)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual certificate management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-certificate-management-activity)
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
* \[Informational] [Unusual exec into a Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-exec-into-a-kubernetes-pod)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual key management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-key-management-activity)
* \[Informational] [Unusual process accessed a macOS notes DB file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-macos-notes-db-file)
* \[Informational] [Unusual process accessed the PowerShell history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-the-powershell-history-file)
* \[Informational] [Unusual process accessed web browser cookies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-cookies)
* \[Informational] [Unusual process accessed web browser credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-credentials)
* \[Informational] [Unusual resource access by Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-resource-access-by-azure-application)
* \[Informational] [Unusual secret management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-secret-management-activity)
* \[Informational] [Unusual use of a 'SysInternals' tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-use-of-a-sysinternals-tool)
* \[Informational] [Unusual user account enablement](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-account-enablement)
* \[Informational] [Unusual user account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-account-unlock)
* \[Informational] [Unusual weak authentication by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-weak-authentication-by-user)
* \[Informational] [Unverified domain added to Azure AD](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unverified-domain-added-to-azure-ad)
* \[Informational] [Upload pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [User accessed SaaS resource via anonymous link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-accessed-saas-resource-via-anonymous-link)
* \[Informational] [User accessed multiple O365 AIP sensitive files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-accessed-multiple-o365-aip-sensitive-files)
* \[Informational] [User account delegation change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-account-delegation-change)
* \[Informational] [User added SID History to an account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-sid-history-to-an-account)
* \[Informational] [User added a new device to Okta Verify instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-a-new-device-to-okta-verify-instance)
* \[Informational] [User added to a group and removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-to-a-group-and-removed)
* \[Informational] [User and Group Enumeration via SAMR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-and-group-enumeration-via-samr)
* \[Informational] [User attempted to connect from a suspicious country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country)
* \[Informational] [User discovery via WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-discovery-via-wmi-query-execution)
* \[Informational] [User installed an application in Microsoft Teams via Graph API](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-installed-an-application-in-microsoft-teams-via-graph-api)
* \[Informational] [User moved Exchange sent messages to deleted items](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-moved-exchange-sent-messages-to-deleted-items)
* \[Informational] [User sent messages in Microsoft Teams to multiple conversations via Graph API](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-sent-messages-in-microsoft-teams-to-multiple-conversations-via-graph-api)
* \[Informational] [User signed in to an application via Power Automate for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-signed-in-to-an-application-via-power-automate-for-the-first-time)
* \[Informational] [VM Detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vm-detection-attempt)
* \[Informational] [VM Detection attempt on Linux](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vm-detection-attempt-on-linux)
* \[Informational] [VPN access with an abnormal operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-access-with-an-abnormal-operating-system)
* \[Informational] [VPN login Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-brute-force-attempt)
* \[Informational] [VPN login by a dormant user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-by-a-dormant-user)
* \[Informational] [VPN login with a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-with-a-machine-account)
* \[Informational] [Vulnerable certificate template loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vulnerable-certificate-template-loaded)
* \[Informational] [Weakly-Encrypted Kerberos TGT Response](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-tgt-response)
* \[Informational] [Web server CGO executed an uncommon process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/web-server-cgo-executed-an-uncommon-process)
* \[Informational] [WebDAV drive mounted from net.exe over HTTPS](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/webdav-drive-mounted-from-net-exe-over-https)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)
  * \[Informational] Email contains an attachment flagged by X-Forefront-Antispam-Report as malware due to its file type - Modified Logic
  * \[Informational] Email flagged by X-Forefront-Antispam-Report as a highly confident phishing attempt - Modified Logic
  * \[Informational] Email flagged by X-Forefront-Antispam-Report as impersonating internal communication - Modified Logic
  * \[Informational] Email identified by X-Forefront-Antispam-Report as a phishing attempt - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report flagged this email as spam - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has categorized this email as containing malware (AMP) - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has categorized this email as containing malware (MALW) - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged an internal email as spam - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as a bulk email - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as attempting to forge the sender's identity - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as impersonating a specific user within the organization - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as impersonating a well-known brand - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as impersonating the organization's domain - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has flagged this email as using advanced impersonation techniques - Modified Logic
  * \[Informational] X-Forefront-Antispam-Report has strongly flagged this email as spam - Modified Logic


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2025-12-31.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
