> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-04.md).

# 2026.02.04

### Release date: 17-February-2026

### Summary

#### Added

* **2 Detectors:** 1 Medium, 1 Informational
* **2 Variations:** 1 Medium, 1 Low

#### Modified Logic

* **76 Detectors:** 1 High, 1 Medium, 13 Low, 61 Informational
* **30 Variations:** 5 High, 6 Medium, 15 Low, 4 Informational

#### Modified Metadata

* **358 Detectors:** 4 High, 35 Medium, 77 Low, 242 Informational
* **73 Variations:** 5 High, 20 Medium, 40 Low, 8 Informational

### Added

* \[Medium] [Command execution via AWS SSM](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-via-aws-ssm)
* \[Informational] [Unusual AWS S3 objects deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-s3-objects-deletion)
  * \[Medium] An identity permanently deleted multiple S3 objects from a project
  * \[Low] A non administrative identity deleted multiple S3 objects from a project

### Modified Logic

* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
  * \[High] A cloud identity executed an API call from an unusual country using a compromised AWS access key - Added
  * \[Medium] A Kubernetes identity executed an API call from a country that was not seen in the organization - Modified Metadata
  * \[Low] A Kubernetes API call was executed from an unusual country - Modified Metadata
* \[Informational] [A process is masquerading as a common Microsoft product](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product)
  * \[High] An unsigned actor executed masqueraded process which was downloaded from unexpected source - Modified Metadata
* \[Informational] [Activity in a dormant region of a cloud project](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[High] Activity in a dormant region of a cloud project by a compromised AWS access key - Added
* \[High] [Collection error](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/collection-error)
* \[Informational] [Multiple failed logins from a single IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-failed-logins-from-a-single-ip)
  * \[High] Multiple failed logins from a single IP by a compromised AWS access key - Added
* \[Low] [Possible DCSync from a non domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dcsync-from-a-non-domain-controller)
  * \[High] DCSync from a non domain controller from a non-standard process - Modified Metadata
* \[Medium] [Parsing Rule Error](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/parsing-rule-error)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
  * \[Medium] SSO Brute Force Threat Detected - Modified Metadata
  * \[Medium] SSO Brute Force on a Honey User Account - Modified Metadata
  * \[Low] SSO Brute Force Activity Observed - Modified Metadata
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
  * \[Medium] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows shell process - Added
  * \[Medium] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows web service - Added
  * \[Low] Unusual cloud Instance Metadata Service (IMDS) access from an unusual known Windows scripting process - Added
* \[Informational] [Unusual user-agent for a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-agent-for-a-cloud-identity)
  * \[Medium] Unusual user-agent for a cloud identity by a compromised AWS access key - Added
* \[Low] [A user uploaded malware to SharePoint or OneDrive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-uploaded-malware-to-sharepoint-or-onedrive)
* \[Low] [Azure domain federation settings modification attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-domain-federation-settings-modification-attempt)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] [Logs were not collected from a data source for an abnormally long time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/logs-were-not-collected-from-a-data-source-for-an-abnormally-long-time)
  * \[Low] Logs were not collected from a Microsoft Windows XDR Collector (XDRC) for an abnormally long time - Modified Logic
  * \[Low] Logs were not collected from a Windows Event Collector (WEC) for an abnormally long time - Modified Logic
* \[Low] [Rare process executed by an AppleScript](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-executed-by-an-applescript)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Informational] [Uncommon Launch Agent persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-agent-persistency-was-registered-or-modified)
  * \[Low] Uncommon Launch Agent persistency was registered or modified while using a data communication tool - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified while using osascript - Modified Metadata
* \[Informational] [Uncommon Launch Daemon persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-daemon-persistency-was-registered-or-modified)
  * \[Low] Uncommon Launch Daemon persistency was registered or modified while using osascript - Modified Logic
* \[Informational] [Uncommon login item persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-login-item-persistency-was-registered-or-modified)
  * \[Low] Uncommon login item persistency was registered or modified while using osascript - Modified Logic
* \[Informational] [Uncommon macOS shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-macos-shell-command-execution)
  * \[Low] Uncommon macOS shell command execution trying to gather information about the system - Removed
  * \[Low] Uncommon macOS shell command execution trying to gather information about the system - Added
* \[Low] [Unusual process accessed a crypto wallet's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files)
* \[Low] [Unusual process accessed a messaging app's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-messaging-app-s-files)
* \[Low] [Unusual process accessed a web browser history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-web-browser-history-file)
* \[Informational] [Unusual process accessed web browser cookies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-cookies)
  * \[Low] Unusual unsigned process accessed web browser cookies - Modified Metadata
* \[Informational] [User exported multiple messages in Microsoft Teams via Graph API](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-exported-multiple-messages-in-microsoft-teams-via-graph-api)
  * \[Low] User exported multiple chats in Microsoft Teams via Graph API - Modified Metadata
  * \[Low] User exported multiple messages in Microsoft Teams via Graph API by a privileged user for the first time - Modified Metadata
  * \[Low] User exported multiple messages in Microsoft Teams via Graph API from a first seen ASN - Modified Metadata
* \[Informational] [AppleScript executed a shell script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-executed-a-shell-script)
* \[Informational] [AppleScript interpreter dynamic library loaded into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
  * \[Informational] External email display name impersonation of internal personnel, using a public provider - Modified Logic
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Microsoft Teams messages were exported from conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-teams-messages-were-exported-from-conversation)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Sudden spike in outbound email volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudden-spike-in-outbound-email-volume)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
  * \[Informational] DKIM results lacking sender correlation - Modified Logic
  * \[Informational] Known domain DKIM deviation - Modified Logic
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
  * \[Informational] DMARC deviation from historically compliant domain - Modified Metadata
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
* \[Informational] [Unpopular URL(s) detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unrecognized sender domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual process accessed a macOS notes DB file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-macos-notes-db-file)
* \[Informational] [Unusual process accessed web browser credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-credentials)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)

### Modified Metadata

* \[High] [A Successful login from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-login-from-tor)
* \[Informational] [A compute-attached identity executed API calls outside the instance's region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region)
  * \[High] A compute-attached identity executed API calls outside the instance's region from an unusual geolocation and ASN - Modified Metadata
  * \[Medium] A compute-attached identity executed API calls outside the instance's region from an unusual geolocation - Modified Metadata
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
  * \[High] LOLBIN spawned by an Office executable connected to a rare external host - Modified Metadata
  * \[Informational] A curl process connected to a rare external host - Modified Metadata
* \[High] [Copy a process memory file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-process-memory-file)
* \[High] [Memory dumping with comsvcs.dll](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/memory-dumping-with-comsvcs-dll)
* \[Informational] [Remote usage of AWS Lambda's role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-aws-lambda-s-role)
  * \[High] Remote command line usage of AWS Lambda's role - Modified Metadata
  * \[High] Suspicious usage of AWS Lambda's role - Modified Metadata
  * \[Medium] Suspicious usage of AWS Lambda's role - Modified Metadata
  * \[Low] Suspicious usage of AWS Lambda's role - Modified Metadata
* \[High] [Suspicious objects encryption in an AWS bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-objects-encryption-in-an-aws-bucket)
* \[Low] [Unsigned and unpopular process performed a DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-a-dll-injection)
  * \[High] Unsigned and unpopular process performed a DLL injection to a commonly abused process - Modified Metadata
  * \[Medium] Unsigned and unpopular process performed a DLL injection to a security vendor signed process - Modified Metadata
  * \[Medium] Unsigned and unpopular process performed a DLL injection to a sensitive process - Modified Metadata
* \[Medium] [A Possible crypto miner was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-crypto-miner-was-detected-on-a-host)
* \[Medium] [A cloud identity performed multiple unusual activities](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-performed-multiple-unusual-activities)
* \[Medium] [A contained executable was executed by an unusual process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-executable-was-executed-by-an-unusual-process)
  * \[Medium] 69ab3fbe-7b14-4439-bd23-8b7c5e40a76a - Modified Metadata
* \[Medium] [A machine certificate was issued with a mismatch](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-machine-certificate-was-issued-with-a-mismatch)
* \[Informational] [A non-browser process accessed a website UI](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-non-browser-process-accessed-a-website-ui)
  * \[Medium] Uncommon data download from a known text share website through a Non-browser process - Modified Metadata
* \[Medium] [A process was executed with a command line obfuscated by Unicode character substitution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitution)
* \[Informational] [An uncommon file was created in the startup folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-was-created-in-the-startup-folder)
  * \[Medium] An executable file with a non-default extension was added to the startup folder - Modified Metadata
  * \[Low] An executable or script was added to the startup folder - Modified Metadata
* \[Medium] [Bitsadmin.exe persistence using command-line callback](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitsadmin-exe-persistence-using-command-line-callback)
* \[Informational] [EBS snapshots were created from an EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-snapshots-were-created-from-an-ec2-instance)
  * \[Medium] EBS snapshots were created from an EC2 instance attached one or more volumes with sensitive data - Modified Metadata
  * \[Low] An unusual creation of EBS snapshots from an EC2 instances - Modified Metadata
* \[Informational] [Executable moved to Windows system folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-moved-to-windows-system-folder)
  * \[Medium] Rare executable moved to Windows system folder by rare causality actor - Modified Metadata
  * \[Low] Executable moved to Windows system folder by rare and unsigned actor - Modified Metadata
  * \[Low] Rare executable moved to Windows system folder by rare actor - Modified Metadata
* \[Medium] [Fodhelper.exe UAC bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/fodhelper-exe-uac-bypass)
* \[Informational] [Globally uncommon injection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-injection-from-a-signed-process)
  * \[Medium] Globally uncommon suspicious injection from a signed process - Modified Metadata
* \[Medium] [Gost tunneling execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Image file execution options (IFEO) registry key set](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/image-file-execution-options-ifeo-registry-key-set)
  * \[Medium] Image file execution options (IFEO) registry key set to activate Windows licenses illegally - Modified Metadata
* \[Medium] [Indirect command execution using the Program Compatibility Assistant](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indirect-command-execution-using-the-program-compatibility-assistant)
* \[Medium] [Logging was impaired via external encryption key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/logging-was-impaired-via-external-encryption-key)
* \[Low] [MFA was disabled for an Azure identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-was-disabled-for-an-azure-identity)
  * \[Medium] Suspicious MFA was disabled for an Azure identity - Modified Metadata
  * \[Informational] MFA was disabled for an Azure identity regularly by the user - Modified Metadata
* \[Medium] [Mailbox Client Access Setting (CAS) changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mailbox-client-access-setting-cas-changed)
* \[Medium] [Manipulation of netsh helper DLLs Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-netsh-helper-dlls-registry-keys)
* \[Informational] [Multiple cloud snapshots export](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-cloud-snapshots-export)
  * \[Medium] c04afdbe-fcb3-43f1-825c-556f25bca9cd - Modified Metadata
* \[Informational] [Penetration testing tool activity attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/penetration-testing-tool-activity-attempt)
  * \[Medium] 3f88509f-bc75-40df-bca4-db19cf11b6cd - Modified Metadata
* \[Medium] [Possible Kerberoasting attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberoasting-attack)
* \[Medium] [Possible Persistence via group policy Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-persistence-via-group-policy-registry-keys)
* \[Medium] [Possible Search For Password Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-search-for-password-files)
* \[Medium] [Possible code downloading from a remote host by Regsvr32](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32)
* \[Medium] [Possible collection of screen captures with Windows Problem Steps Recorder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-collection-of-screen-captures-with-windows-problem-steps-recorder)
* \[Medium] [Possible malicious .NET compilation started by a commonly abused process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-malicious-net-compilation-started-by-a-commonly-abused-process)
* \[Medium] [PowerShell dumps users and roles from Exchange server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Medium] [PowerShell used to export mailbox contents](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-used-to-export-mailbox-contents)
* \[Medium] [Procdump executed from an atypical directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/procdump-executed-from-an-atypical-directory)
* \[Medium] [Process changes the Windows logon text](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Medium] [RDP Connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connection-to-localhost)
* \[Informational] [Rare process accessed a Keychain file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-accessed-a-keychain-file)
  * \[Medium] Rare process accessed a Keychain file while installing a new certificate - Modified Metadata
  * \[Low] Rare process accessed a Keychain file initiated by a causality actor with a rare path - Modified Metadata
  * \[Low] Rare process accessed a Keychain file initiated by an unsigned causality actor - Modified Metadata
  * \[Low] Rare unsigned process accessed a Keychain file - Modified Metadata
* \[Medium] [Rundll32.exe spawns conhost.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-spawns-conhost-exe)
* \[Medium] [Script file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/script-file-added-to-startup-related-registry-keys)
* \[Low] [Stored credentials exported using credwiz.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/stored-credentials-exported-using-credwiz-exe)
  * \[Medium] Stored credentials exported using credwiz.exe using keymgr.dll's KRShowKeyMgr function - Modified Metadata
  * \[Low] Stored credentials exported using credwiz.exe over RDP - Modified Metadata
  * \[Low] Stored credentials exported using credwiz.exe with a built-in Windows tool - Modified Metadata
* \[Medium] [Suspicious .NET process loads an MSBuild DLL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-net-process-loads-an-msbuild-dll)
* \[Medium] [Suspicious Process Spawned by wininit.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawned-by-wininit-exe)
* \[Medium] [Suspicious SearchProtocolHost.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-searchprotocolhost-exe-parent-process)
* \[Medium] [Suspicious certutil command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-command-line)
* \[Medium] [Suspicious disablement of the Windows Firewall using PowerShell commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-disablement-of-the-windows-firewall-using-powershell-commands)
* \[Medium] [Suspicious heavy allocation of compute resources - possible mining activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-heavy-allocation-of-compute-resources-possible-mining-activity)
* \[Medium] [Suspicious time provider registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-time-provider-registered)
* \[Low] [Suspicious usage of EC2 token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-ec2-token)
  * \[Medium] Suspicious usage of EC2 token - Modified Metadata
* \[Medium] [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dll-sideloading-from-a-logical-cd-rom-iso-device)
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
  * \[Medium] Uncommon net localgroup administrators command execution by a web server process or CGO - Modified Metadata
  * \[Low] Uncommon remote net localgroup execution - Modified Metadata
* \[Low] [Uncommon remote monitoring and management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-monitoring-and-management-tool)
  * \[Medium] Uncommon remote monitoring and management tool downloaded from an uncommon source and executed - Modified Metadata
* \[Medium] [Unsigned process injecting into a Windows system binary with no command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line)
* \[Medium] [Unusual process access to ld.so.preload file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-access-to-ld-so-preload-file)
* \[Low] [Weakly-Encrypted Kerberos Ticket Requested](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-ticket-requested)
  * \[Medium] Weakly-Encrypted Kerberos Ticket Requested on a sensitive server - Modified Metadata
* \[Low] [A GCP service account was delegated domain-wide authority in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspace)
* \[Informational] [A Google Workspace identity created, assigned or modified a role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-created-assigned-or-modified-a-role)
  * \[Low] A non-administrative Google Workspace identity created, assigned or modified a role from an unusual ASN - Modified Metadata
* \[Informational] [A Google Workspace service was configured as unrestricted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-service-was-configured-as-unrestricted)
  * \[Low] A Google Workspace service was configured as unrestricted by a suspicious identity - Modified Metadata
* \[Informational] [A cloud identity created or modified a security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-created-or-modified-a-security-group)
  * \[Low] A cloud identity opened a security group to an unknown IP - Modified Metadata
* \[Low] [A compiled HTML help file wrote a script file to the disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compiled-html-help-file-wrote-a-script-file-to-the-disk)
* \[Low] [A domain was added to the trusted domains list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-domain-was-added-to-the-trusted-domains-list)
  * \[Low] A domain was added to the trusted domains list from an unusual ASN - Modified Metadata
* \[Low] [A rare file path was added to the AppInit\_DLLs registry value](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value)
* \[Low] [A remote service was created via RPC over SMB](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-remote-service-was-created-via-rpc-over-smb)
* \[Low] [A suspicious direct syscall was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-direct-syscall-was-executed)
* \[Low] [AWS Guard-Duty detector deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-guard-duty-detector-deletion)
* \[Low] [AWS web ACL deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-web-acl-deletion)
* \[Informational] [Abnormal process connection to default Meterpreter port](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-process-connection-to-default-meterpreter-port)
  * \[Low] Abnormal process connection to default Meterpreter port on an internet-facing server - Modified Metadata
* \[Informational] [An AWS database service master user password was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-database-service-master-user-password-was-changed)
  * \[Low] An AWS Database Service master user password was changed by a non-DevOps identity - Modified Metadata
  * \[Low] An AWS Database Service master user password was changed from an unusual country - Modified Metadata
* \[Low] [An Azure Firewall policy deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-policy-deletion)
* \[Informational] [An Azure application reached a throttling API rate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-application-reached-a-throttling-api-rate)
  * \[Low] An Azure application reached an unusual throttling API rate - Modified Metadata
  * \[Informational] An Azure application reached an unusual throttling API rate - Modified Metadata
* \[Informational] [An app was removed from a blocked list in Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-removed-from-a-blocked-list-in-google-workspace)
  * \[Low] An app was removed from a blocked list in Google Workspace by a suspicious identity - Modified Metadata
* \[Low] [An uncommon service was started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-service-was-started)
* \[Informational] [Authentication Attempt From a Dormant Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-from-a-dormant-account)
  * \[Low] Authentication Attempt From a Dormant Account to a sensitive server - Modified Metadata
* \[Low] [Azure Network Watcher Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-network-watcher-deletion)
* \[Low] [Change of sudo caching configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/change-of-sudo-caching-configuration)
* \[Informational] [Common third-party software name masquerading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-third-party-software-name-masquerading)
  * \[Low] Common third-party software name masquerading which was downloaded from an unexpected source - Modified Metadata
* \[Low] [Copy a user's GnuPG directory with rsync](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-user-s-gnupg-directory-with-rsync)
* \[Informational] [Data Sharing between GCP and Google Workspace was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-sharing-between-gcp-and-google-workspace-was-disabled)
  * \[Low] Data Sharing between GCP and Google Workspace was disabled by a suspicious identity - Modified Metadata
* \[Low] [Delayed Deletion of Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/delayed-deletion-of-files)
* \[Low] [Disable encryption operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/disable-encryption-operations)
* \[Low] [Download a script using the python requests module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-a-script-using-the-python-requests-module)
* \[Low] [Dumping Registry hives with passwords](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Low] [Executable or Script file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-or-script-file-written-by-a-web-server-process)
  * \[Low] A driver was written by a web server process - Modified Metadata
* \[Informational] [External Sharing was turned on for Google Drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-sharing-was-turned-on-for-google-drive)
  * \[Low] External Sharing was turned on for Google Drive by a non Google Workspace administrative user from an unusual ASN - Modified Metadata
* \[Low] [GCP data asset shared public](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-data-asset-shared-public)
* \[Informational] [Globally uncommon high entropy process was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-process-was-executed)
  * \[Low] Globally uncommon high entropy process was downloaded from an uncommon source and executed - Modified Metadata
* \[Low] [Globally uncommon root domain from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-from-a-signed-process)
* \[Low] [Globally uncommon root-domain port combination from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-from-a-signed-process)
* \[Informational] [Gmail routing settings changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gmail-routing-settings-changed)
  * \[Low] Gmail routing settings changed by a non-administrative Google Workspace identity - Modified Metadata
* \[Low] [Installation of a new System-V service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/installation-of-a-new-system-v-service)
* \[Low] [Interactive at.exe privilege escalation method](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-at-exe-privilege-escalation-method)
* \[Low] [Interactive local account enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-local-account-enumeration)
* \[Low] [Keylogging using system commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/keylogging-using-system-commands)
* \[Low] [Known service display name with uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-display-name-with-uncommon-image-path)
* \[Low] [Known service name with an uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-name-with-an-uncommon-image-path)
* \[Low] [Large Upload (FTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-ftp)
* \[Low] [MFA Disabled for Google Workspace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-disabled-for-google-workspace)
  * \[Low] MFA Disabled for Google Workspace from an unusual caller IP ASN - Modified Metadata
* \[Low] [Microsoft Office adds a value to autostart Registry key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-adds-a-value-to-autostart-registry-key)
* \[Low] [Microsoft Office injects code into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-injects-code-into-a-process)
* \[Low] [Modification of NTLM restrictions in the Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-ntlm-restrictions-in-the-registry)
* \[Low] [MpCmdRun.exe was used to download files into the system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mpcmdrun-exe-was-used-to-download-files-into-the-system)
* \[Low] [Mshta.exe launched with suspicious arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-launched-with-suspicious-arguments)
* \[Low] [Multiple Azure AD admin role removals](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-azure-ad-admin-role-removals)
* \[Low] [Multiple uncommon SSH Servers with the same Server host key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key)
* \[Low] [NTDS.dit file written by an uncommon executable](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntds-dit-file-written-by-an-uncommon-executable)
* \[Low] [New addition to Windows Defender exclusion list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-addition-to-windows-defender-exclusion-list)
* \[Low] [Office process spawned with suspicious command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-spawned-with-suspicious-command-line-arguments)
  * \[Low] PowerPoint process accesses a suspicious PPAM file - Modified Metadata
* \[Low] [Possible Kerberoasting without SPNs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberoasting-without-spns)
* \[Low] [Possible external RDP Brute-Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-external-rdp-brute-force)
* \[Low] [Possible network sniffing attempt via tcpdump or tshark](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark)
* \[Informational] [Potential DCSync by an unusual user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-dcsync-by-an-unusual-user)
  * \[Low] Possible DCSync by an unusual user - Modified Metadata
* \[Informational] [Privileged role used by Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/privileged-role-used-by-azure-application)
  * \[Low] First-time privileged role is used by Azure application - Modified Metadata
* \[Low] [RDP connections enabled remotely via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connections-enabled-remotely-via-registry)
* \[Low] [Rare RDP session to a remote host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-rdp-session-to-a-remote-host)
* \[Low] [Rare process created an SSH session to an uncommon cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-cloud-resource)
* \[Low] [Rare service DLL was added to the registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-service-dll-was-added-to-the-registry)
* \[Informational] [Rare signature signed executable executed in the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-signature-signed-executable-executed-in-the-network)
  * \[Low] Rare signature signed executable downloaded from an uncommon source and executed in the network - Modified Metadata
* \[Low] [Recurring access to rare IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-ip)
* \[Low] [Remote usage of an AWS service token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-aws-service-token)
* \[Informational] [Removal of an Azure Owner from an Application or Service Principal](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/removal-of-an-azure-owner-from-an-application-or-service-principal)
  * \[Low] Removal of an Azure AD privileged user from an Application or Service Principal - Modified Metadata
* \[Low] [Rundll32.exe executes a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module)
* \[Low] [Screensaver process executed from Users or temporary folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/screensaver-process-executed-from-users-or-temporary-folder)
* \[Low] [SecureBoot was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/secureboot-was-disabled)
* \[Low] [Suspicious EBS snapshots deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ebs-snapshots-deletion)
* \[Low] [Suspicious SMB connection from domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-smb-connection-from-domain-controller)
* \[Low] [Suspicious SSH Downgrade](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ssh-downgrade)
* \[Low] [Suspicious account attribute modification that matches that of another account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-account-attribute-modification-that-matches-that-of-another-account)
* \[Low] [Suspicious activity indicating a potential abuse of a cloud-native email service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-activity-indicating-a-potential-abuse-of-a-cloud-native-email-service)
* \[Informational] [Suspicious docker image download from an unusual repository](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-docker-image-download-from-an-unusual-repository)
  * \[Low] Suspicious docker image download from an unrecognized registry - Modified Metadata
  * \[Low] Suspicious docker image download from an unrecognized repository - Modified Metadata
* \[Low] [Suspicious failed HTTP request - potential Spring4Shell exploit](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit)
* \[Low] [Suspicious runonce.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-runonce-exe-parent-process)
* \[Low] [Suspicious sshpass command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sshpass-command-execution)
* \[Low] [Svchost.exe loads a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/svchost-exe-loads-a-rare-unsigned-module)
* \[Low] [System information discovery via psinfo.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-information-discovery-via-psinfo-exe)
* \[Low] [Uncommon VNC server communication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-vnc-server-communication)
  * \[Low] Uncommon VNC server communication from an unmanaged previously unseen external host - Modified Metadata
  * \[Informational] Partially uncommon VNC server communication - Modified Metadata
* \[Informational] [Uncommon communication to an instant messaging server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-communication-to-an-instant-messaging-server)
  * \[Low] Uncommon communication to an instant messaging server by an uncommon scripting engine execution - Modified Metadata
* \[Low] [Uncommon msiexec execution of an arbitrary file from a remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location)
* \[Informational] [Uncommon net group command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-group-command-execution)
  * \[Low] Uncommon remote net group administrators command execution - Modified Metadata
  * \[Low] Uncommon remote net group execution - Modified Metadata
* \[Low] [Uncommon sensitive registry hive dump](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-registry-hive-dump)
* \[Informational] [Uncommon signed process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task)
  * \[Low] Rare signed process execution by scheduled task - Modified Metadata
* \[Low] [Unsigned and unpopular process performed an injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-an-injection)
* \[Low] [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-encrypting-file-system-remote-call-efsrpc-to-domain-controller)
* \[Low] [Unusual Lolbins Process Spawned by InstallUtil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe)
* \[Low] [Unusual Netsh PortProxy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-netsh-portproxy-rule)
* \[Low] [Windows Event Log was cleared using wevtutil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-log-was-cleared-using-wevtutil-exe)
* \[Low] [Wscript/Cscript loads .NET DLLs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wscript-cscript-loads-net-dlls)
* \[Informational] [A Google Workspace Role privilege was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-role-privilege-was-deleted)
* \[Informational] [A Google Workspace identity performed an unusual admin console activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-performed-an-unusual-admin-console-activity)
* \[Informational] [A Google Workspace identity used the security investigation tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-identity-used-the-security-investigation-tool)
* \[Informational] [A Google Workspace user was removed from a group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-google-workspace-user-was-removed-from-a-group)
* \[Informational] [A Kubernetes Cronjob was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cronjob-was-created)
* \[Informational] [A Kubernetes DaemonSet was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-daemonset-was-created)
* \[Informational] [A Kubernetes Pod was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-pod-was-deleted)
* \[Informational] [A Kubernetes ReplicaSet was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-replicaset-was-created)
* \[Informational] [A Kubernetes cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-was-created-or-deleted)
* \[Informational] [A Kubernetes ephemeral container was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-ephemeral-container-was-created)
* \[Informational] [A Kubernetes namespace was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-namespace-was-created-or-deleted)
* \[Informational] [A Kubernetes service was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-was-created-or-deleted)
* \[Informational] [A LOLBIN was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-lolbin-was-copied-to-a-different-location)
* \[Informational] [A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-new-server-was-added-to-an-azure-active-directory-hybrid-health-adfs-environment)
* \[Informational] [A Service Principal was removed from Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-service-principal-was-removed-from-azure)
* \[Informational] [A Torrent client was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-torrent-client-was-detected-on-a-host)
  * \[Informational] 0891f007-4666-4ed4-9a7e-2fa724b925e4 - Modified Metadata
* \[Informational] [A WMI subscriber was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-wmi-subscriber-was-created)
* \[Informational] [A browser extension was installed or loaded in an uncommon way](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-browser-extension-was-installed-or-loaded-in-an-uncommon-way)
* \[Informational] [A compressed file was exfiltrated over SSH](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compressed-file-was-exfiltrated-over-ssh)
* \[Informational] [A container registry was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-container-registry-was-created-or-deleted)
* \[Informational] [A process modified an SSH authorized\_keys file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-modified-an-ssh-authorized-keys-file)
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process)
* \[Informational] [A third-party application was authorized to access the Google Workspace APIs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-application-was-authorized-to-access-the-google-workspace-apis)
* \[Informational] [A third-party application's access to the Google Workspace domain's resources was revoked](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revoked)
* \[Informational] [A third-party utility was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-utility-was-copied-to-a-different-location)
* \[Informational] [A user accessed multiple time-consuming websites](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-time-consuming-websites)
* \[Informational] [A user connected a new USB storage device to a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-a-host)
* \[Informational] [A user created an abnormal password-protected archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-created-an-abnormal-password-protected-archive)
* \[Informational] [ADFind queries Active Directory for Exchange groups](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS Backup recovery point deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-backup-recovery-point-deletion)
* \[Informational] [AWS CloudWatch log group deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudwatch-log-group-deletion)
* \[Informational] [AWS CloudWatch log stream deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-cloudwatch-log-stream-deletion)
* \[Informational] [AWS Config Recorder stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-config-recorder-stopped)
* \[Informational] [AWS EBS snapshot deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-snapshot-deletion)
* \[Informational] [AWS EC2 instance exported into S3](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-instance-exported-into-s3)
* \[Informational] [AWS IAM resource group deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-iam-resource-group-deletion)
* \[Informational] [AWS RDS cluster deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-rds-cluster-deletion)
* \[Informational] [AWS S3 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS S3 object deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS SES account sending settings modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ses-account-sending-settings-modified)
* \[Informational] [AWS SSM parameters retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-parameters-retrieval)
  * \[Informational] Unusual AWS SSM parameters retrieval - Modified Metadata
* \[Informational] [AWS SecurityHub findings were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-securityhub-findings-were-modified)
* \[Informational] [AWS config resource deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-config-resource-deletion)
* \[Informational] [AWS network ACL rule creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-network-acl-rule-creation)
* \[Informational] [AWS network ACL rule deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-network-acl-rule-deletion)
* \[Informational] [AWS root account activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-root-account-activity)
* \[Informational] [AWS support case creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-support-case-creation)
* \[Informational] [Abnormal Allocation of compute resources in multiple regions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-allocation-of-compute-resources-in-multiple-regions)
* \[Informational] [Abnormal Communication to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-to-a-rare-domain)
* \[Informational] [Abnormal RDP connections to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts)
* \[Informational] [Abnormal Recurring Communications to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain)
* \[Informational] [Access to Kubernetes CA certificate file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubernetes-ca-certificate-file)
* \[Informational] [Adding execution privileges](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/adding-execution-privileges)
  * \[Informational] Adding execution privileges in a Kubernetes pod - Modified Metadata
* \[Informational] [Admin privileges were granted to a Google Workspace user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/admin-privileges-were-granted-to-a-google-workspace-user)
* \[Informational] [An AWS EFS File-share mount was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-efs-file-share-mount-was-deleted)
* \[Informational] [An AWS EFS file-share was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-efs-file-share-was-deleted)
* \[Informational] [An AWS EKS cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-eks-cluster-was-created-or-deleted)
* \[Informational] [An AWS GuardDuty IP set was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-guardduty-ip-set-was-created)
* \[Informational] [An AWS Lambda Function was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-lambda-function-was-created)
* \[Informational] [An AWS RDS Global Cluster Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-rds-global-cluster-deletion)
* \[Informational] [An AWS RDS instance was created from a snapshot](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-rds-instance-was-created-from-a-snapshot)
* \[Informational] [An AWS Route 53 domain was transferred to another AWS account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-route-53-domain-was-transferred-to-another-aws-account)
* \[Informational] [An AWS S3 bucket configuration was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-s3-bucket-configuration-was-modified)
* \[Informational] [An AWS SAML provider was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-saml-provider-was-modified)
* \[Informational] [An AWS SES identity was deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-ses-identity-was-deleted)
* \[Informational] [An Azure DNS Zone was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-dns-zone-was-modified)
* \[Informational] [An Azure Firewall was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-was-modified)
* \[Informational] [An Azure Key Vault was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-key-vault-was-modified)
* \[Informational] [An Azure Kubernetes Cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-cluster-was-created-or-deleted)
* \[Informational] [An Azure Kubernetes Role or Cluster-Role was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-role-or-cluster-role-was-modified)
* \[Informational] [An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-role-binding-or-cluster-role-binding-was-modified-or-deleted)
* \[Informational] [An Azure Kubernetes Service Account was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-kubernetes-service-account-was-modified-or-deleted)
* \[Informational] [An Azure Network Security Group was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-network-security-group-was-modified)
* \[Informational] [An Azure Point-to-Site VPN was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-point-to-site-vpn-was-modified)
* \[Informational] [An Azure VPN Connection was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-vpn-connection-was-modified)
* \[Informational] [An Azure firewall rule group was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-rule-group-was-modified)
* \[Informational] [An Azure identity performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-identity-performed-multiple-actions-that-were-denied)
* \[Informational] [An Azure virtual network Device was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-virtual-network-device-was-modified)
* \[Informational] [An Azure virtual network was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-virtual-network-was-modified)
* \[Informational] [An Email address was added to AWS SES](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-email-address-was-added-to-aws-ses)
* \[Informational] [An IAM group was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-iam-group-was-created)
* \[Informational] [An app was added to Google Marketplace](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-added-to-google-marketplace)
* \[Informational] [An app was added to the Google Workspace trusted OAuth apps list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-app-was-added-to-the-google-workspace-trusted-oauth-apps-list)
* \[Informational] [An identity accessed Azure Kubernetes Secrets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-azure-kubernetes-secrets)
* \[Informational] [An identity accessed a cloud storage for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-a-cloud-storage-for-the-first-time)
* \[Informational] [An identity started an AWS SSM session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-started-an-aws-ssm-session)
* \[Informational] [An operation was performed by an identity from a domain that was not seen in the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organization)
* \[Informational] [AppleScript process executed with a rare command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-process-executed-with-a-rare-command-line)
* \[Informational] [Aurora DB cluster stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aurora-db-cluster-stopped)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
* \[Informational] [Azure Automation Runbook Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-deletion)
* \[Informational] [Azure Event Hub Authorization rule creation/modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-event-hub-authorization-rule-creation-modification)
* \[Informational] [Azure Key Vault Secrets were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-secrets-were-modified)
* \[Informational] [Azure Key Vault modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-modification)
* \[Informational] [Azure Kubernetes events were deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-kubernetes-events-were-deleted)
* \[Informational] [Azure Storage Account key generated](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-key-generated)
* \[Informational] [Azure device code authentication flow used](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-device-code-authentication-flow-used)
* \[Informational] [Azure diagnostic configuration deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-diagnostic-configuration-deletion)
* \[Informational] [Azure virtual machine commands execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-virtual-machine-commands-execution)
* \[Informational] [Cloud Organizational policy was created or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-organizational-policy-was-created-or-modified)
* \[Informational] [Cloud Watch alarm deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-watch-alarm-deletion)
* \[Informational] [Cloud email service activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-email-service-activity)
* \[Informational] [Cloud identity reached a throttling API rate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-identity-reached-a-throttling-api-rate)
  * \[Informational] Cloud identity reached an unusual throttling API rate - Modified Metadata
* \[Informational] [Cloud user performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied)
* \[Informational] [Command enumeration via sudo](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Command execution in a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-in-a-kubernetes-pod)
* \[Informational] [Commonly abused AutoIT script drops an executable file to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-autoit-script-drops-an-executable-file-to-disk)
* \[Informational] [Data encryption was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-encryption-was-disabled)
* \[Informational] [EC2 snapshot attribute has been modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage)
* \[Informational] [GCP Firewall Rule Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-firewall-rule-modification)
* \[Informational] [GCP Firewall Rule creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-firewall-rule-creation)
* \[Informational] [GCP IAM Role Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-iam-role-deletion)
* \[Informational] [GCP IAM Service Account Key Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-iam-service-account-key-deletion)
* \[Informational] [GCP Logging Bucket Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-bucket-deletion)
* \[Informational] [GCP Pub/Sub Subscription Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-pub-sub-subscription-deletion)
* \[Informational] [GCP Pub/Sub Topic Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-pub-sub-topic-deletion)
* \[Informational] [GCP Service Account Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-deletion)
* \[Informational] [GCP Service Account Disable](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-disable)
* \[Informational] [GCP Service Account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-creation)
* \[Informational] [GCP Service Account key creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-service-account-key-creation)
* \[Informational] [GCP Storage Bucket Configuration Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-configuration-modification)
* \[Informational] [GCP Storage Bucket Permissions Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-permissions-modification)
* \[Informational] [GCP Storage Bucket deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-storage-bucket-deletion)
* \[Informational] [GCP VPC Firewall Rule Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-vpc-firewall-rule-deletion)
* \[Informational] [GCP Virtual Private Cloud (VPC) Network Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-cloud-vpc-network-deletion)
* \[Informational] [GCP Virtual Private Network Route Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-network-route-creation)
* \[Informational] [GCP Virtual Private Network Route Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-virtual-private-network-route-deletion)
* \[Informational] [GCP logging sink modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-sink-modification)
* \[Informational] [GCP sensitive Cloud Run role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-cloud-run-role-granted)
* \[Informational] [GCP sensitive Deployment Manager role granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-sensitive-deployment-manager-role-granted)
* \[Informational] [Globally uncommon IP address by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256)
* \[Informational] [Globally uncommon IP address connection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-connection-from-a-signed-process)
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
* \[Informational] [Globally uncommon root-domain port combination by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-by-a-common-process-sha256)
* \[Informational] [Gmail delegation was turned on for the organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gmail-delegation-was-turned-on-for-the-organization)
* \[Informational] [Google Workspace organizational unit was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-organizational-unit-was-modified)
* \[Informational] [Google Workspace third-party application's security settings were changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/google-workspace-third-party-application-s-security-settings-were-changed)
* \[Informational] [Granting Access to an Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/granting-access-to-an-account)
* \[Informational] [IAM Enumeration sequence](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-enumeration-sequence)
* \[Informational] [IAM instance profiles were listed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Indicator blocking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indicator-blocking)
* \[Informational] [Injection into rundll32.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/injection-into-rundll32-exe)
* \[Informational] [Installation of networking security tools](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Kubernetes cluster events deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-cluster-events-deletion)
* \[Informational] [Kubernetes network policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-network-policy-modification)
* \[Informational] [Kubernetes nsenter container escape](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-nsenter-container-escape)
* \[Informational] [Kubernetes secret enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-secret-enumeration-activity)
* \[Informational] [LOLBAS executable injects into another process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbas-executable-injects-into-another-process)
* \[Informational] [Local account discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-account-discovery)
* \[Informational] [Login by a dormant user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/login-by-a-dormant-user)
* \[Informational] [MFA device was removed/deactivated from an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-device-was-removed-deactivated-from-an-iam-user)
* \[Informational] [MSI accessed a web page running a server-side script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script)
* \[Informational] [Modification of PAM](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-pam)
* \[Informational] [Modification or Deletion of an Azure Application Gateway Detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-or-deletion-of-an-azure-application-gateway-detected)
* \[Informational] [Network sniffing detected in Cloud environment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/network-sniffing-detected-in-cloud-environment)
* \[Informational] [New process created via a WMI call](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [OneDrive file download](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/onedrive-file-download)
* \[Informational] [Outlook creates an executable file on disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Possible authentication coercion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-authentication-coercion)
* \[Informational] [Possible data obfuscation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-data-obfuscation)
* \[Informational] [Possible use of a networking driver for network sniffing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-use-of-a-networking-driver-for-network-sniffing)
* \[Informational] [Potential Network Sniffing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Potential creation of persistent cloud credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-creation-of-persistent-cloud-credentials)
* \[Informational] [Privileged certificate request via certificate template](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/privileged-certificate-request-via-certificate-template)
* \[Informational] [Rare AppID usage to a rare destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-appid-usage-to-a-rare-destination)
* \[Informational] [Rare MS-Update Server was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-server-was-detected)
* \[Informational] [Rare MS-Update traffic over HTTP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-traffic-over-http)
* \[Informational] [Rare NTLM Access By User To Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-access-by-user-to-host)
* \[Informational] [Rare Scheduled Task RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-rpc-activity)
* \[Informational] [Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-connection-to-external-ip-address-or-host-by-an-application-using-rmi-iiop-or-ldap-protocol)
* \[Informational] [Remote code execution into Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-code-execution-into-kubernetes-pod)
* \[Informational] [Remote usage of VM Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-vm-service-account-token)
* \[Informational] [Remote usage of an Azure Service Principal token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-service-principal-token)
* \[Informational] [Run downloaded script using pipe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/run-downloaded-script-using-pipe)
* \[Informational] [S3 configuration deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/s3-configuration-deletion)
* \[Informational] [SaaS suspicious external domain user activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/saas-suspicious-external-domain-user-activity)
* \[Informational] [Service execution via sc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/service-execution-via-sc-exe)
* \[Informational] [Shell binary copied to another location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Signed process performed an unpopular DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-dll-injection)
* \[Informational] [Signed process performed an unpopular injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-injection)
* \[Informational] [Suspicious container runtime connection from within a Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-runtime-connection-from-within-a-kubernetes-pod)
* \[Informational] [Suspicious curl user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-curl-user-agent)
* \[Informational] [Suspicious process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-executed-with-a-high-integrity-level)
* \[Informational] [Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-microsoft-s-active-directory-powershell-module-remote-discovery-cmdlet)
* \[Informational] [Tampering with Internet Explorer Protected Mode configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-internet-explorer-protected-mode-configuration)
* \[Informational] [Tampering with the Windows User Account Controls (UAC) configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-the-windows-user-account-controls-uac-configuration)
* \[Informational] [Uncommon DotNet module load relationship](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dotnet-module-load-relationship)
* \[Informational] [Uncommon Linux remote shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-remote-shell-command-execution)
* \[Informational] [Uncommon Linux shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-shell-command-execution)
* \[Informational] [Uncommon Managed Object Format (MOF) compiler usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-managed-object-format-mof-compiler-usage)
* \[Informational] [Uncommon access to cloud platforms' sensitive files by a scripting engine](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine)
* \[Informational] [Uncommon cloud CLI tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-cloud-cli-tool-usage)
* \[Informational] [Uncommon increase in Azure Microsoft Graph API request sizes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-increase-in-azure-microsoft-graph-api-request-sizes)
* \[Informational] [Uncommon sensitive filesystem registry hive access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-filesystem-registry-hive-access)
* \[Informational] [Uncommon service stop operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-service-stop-operation)
* \[Informational] [Unique client computer model was detected via MS-Update protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol)
* \[Informational] [Unpopular rsync process execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-rsync-process-execution)
* \[Informational] [Unusual AWS systems manager activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-systems-manager-activity)
* \[Informational] [Unusual IAM enumeration activity by a non-user Identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-iam-enumeration-activity-by-a-non-user-identity)
* \[Informational] [Unusual access to Microsoft 365 storage services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-microsoft-365-storage-services)
* \[Informational] [Unusual certificate management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-certificate-management-activity)
* \[Informational] [Unusual key management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-key-management-activity)
* \[Informational] [Unusual secret management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-secret-management-activity)
* \[Informational] [Unusual use of a 'SysInternals' tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-use-of-a-sysinternals-tool)
* \[Informational] [Upload pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Weakly-Encrypted Kerberos TGT Response](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-tgt-response)
* \[Informational] [Windows CGO, actor and action processes with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics)
* \[Informational] [Windows Security audit log was cleared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-04.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
