> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-25.md).

# 2026.02.25

### Release date: 10-March-2026

### Summary

#### Added

* **14 Detectors:** 2 Low, 12 Informational
* **36 Variations:** 2 High, 10 Medium, 23 Low, 1 Informational

#### Removed

* **6 Detectors:** 1 Low, 5 Informational
* **17 Variations:** 1 High, 6 Medium, 6 Low, 4 Informational

#### Modified Logic

* **249 Detectors:** 2 High, 7 Medium, 44 Low, 196 Informational
* **52 Variations:** 7 High, 16 Medium, 21 Low, 8 Informational

#### Modified Metadata

* **7 Detectors:** 2 Low, 5 Informational
* **6 Variations:** 1 High, 4 Low, 1 Informational

### Added

* \[Informational] [Uncommon net group command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-group-command-execution)
  * \[High] Uncommon unsigned net group administrators command execution
  * \[High] Uncommon unsigned net group administrators command execution - fixed localization issues
  * \[Medium] Uncommon administrator net group execution by scripting engine or command prompt
  * \[Medium] Uncommon net group administrators command execution
  * \[Low] Uncommon net group execution
  * \[Low] Uncommon remote net group administrators command execution
  * \[Low] Uncommon remote net group execution
* \[Informational] [Uncommon Linux process communication to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-process-communication-to-a-rare-external-host)
  * \[Medium] Uncommon Linux process communication to a rare external host by an automated penetration testing tool
  * \[Low] Uncommon Linux process communication to a rare external host identified as global anomaly
  * \[Low] Uncommon Linux process communication to a rare external host involving a code sharing website
  * \[Low] Uncommon Linux process communication to a rare external host involving a low-prevalence process connecting to a rare Top-Level Domain
  * \[Low] Uncommon Linux process communication to a rare external host using a data transfer tool
  * \[Low] Uncommon Linux process communication to a rare external host with an external IP in the command line
* \[Informational] [Uncommon access to /etc/passwd](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-etc-passwd)
  * \[Medium] Uncommon access to /etc/passwd by a potential Webshell
  * \[Medium] Uncommon access to /etc/passwd by a potentially known credential dumper or enumeration script
  * \[Medium] Uncommon access to /etc/passwd by a security testing tool
  * \[Low] Uncommon access to /etc/passwd from temporary or world writable directories
  * \[Low] Uncommon access to /etc/passwd using an interactive binary
  * \[Low] Uncommon access to /etc/passwd using an interactive shell
  * \[Low] Uncommon access to /etc/passwd via a new inline bash script
  * \[Low] Uncommon access to /etc/passwd with additional sensitive files in the command line
  * \[Low] Uncommon access to /etc/passwd with both /etc/passwd and /etc/shadow in the command line
  * \[Low] Uncommon access to /etc/passwd, involving a network utility
  * \[Low] Uncommon link creation to /etc/passwd
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
  * \[Medium] Uncommon net localgroup administrators command execution by a web server process or CGO
  * \[Medium] Uncommon remote net localgroup execution
  * \[Medium] Uncommon unsigned net localgroup administrators command execution
  * \[Medium] Uncommon unsigned net localgroup administrators command execution - fixed localization issues
  * \[Low] Uncommon administrator net localgroup execution by scripting engine or command prompt
  * \[Low] Uncommon net localgroup administrators command execution
  * \[Low] Uncommon net localgroup execution
* \[Informational] [AWS Security Service Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-security-service-enumeration)
  * \[Low] AWS Multiple Security Services Enumeration
* \[Informational] [LOLBAS executable injects into another process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbas-executable-injects-into-another-process)
  * \[Low] LOLBAS executable injects into another process under an uncommon CGO
* \[Low] [Machine Account NTLM Relay](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/machine-account-ntlm-relay)
* \[Informational] [Sensitive browser credential files accessed by a rare non browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process)
  * \[Low] Sensitive browser credential files accessed by a rare non browser process from a commonly abused directory
* \[Informational] [Suspicious AWS SSM parameters retrieval activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-aws-ssm-parameters-retrieval-activity)
  * \[Low] A non admin identity extracted multiple secrets within the organization across multiple regions
* \[Low] [Suspicious Kerberos Pre-Auth Failures by Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-kerberos-pre-auth-failures-by-host)
* \[Informational] [A cloud storage configuration was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-configuration-was-modified)
* \[Informational] [AWS console login without MFA](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-console-login-without-mfa)
* \[Informational] [An RDS snapshot was exported to an unknown bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-bucket)
  * \[Informational] Failed RDS snapshot export attempt to an unknown bucket
* \[Informational] [Unusual internal access to network device management interface](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-internal-access-to-network-device-management-interface)

### Removed

* \[Informational] Uncommon net group command execution
  * \[High] Uncommon unsigned net group administrators command execution
  * \[Medium] Uncommon administrator net group execution by scripting engine or command prompt
  * \[Medium] Uncommon net group administrators command execution
  * \[Low] Uncommon net group execution
  * \[Low] Uncommon remote net group administrators command execution
  * \[Low] Uncommon remote net group execution
* \[Informational] LOLBAS executable injects into another process
  * \[Medium] Rare LOLBAS executable injects into another process
  * \[Informational] LOLBAS executable injects into another process using process hollowing
  * \[Informational] LOLBAS executable that's used to host DLLs injects into another process
  * \[Informational] LOLBAS executable that's used to host DLLs injects into another process
  * \[Informational] Scripting engine injects into another process
* \[Informational] Uncommon net localgroup command execution
  * \[Medium] Uncommon administrator net localgroup execution by scripting engine or command prompt
  * \[Medium] Uncommon net localgroup administrators command execution by a web server process or CGO
  * \[Medium] Uncommon unsigned net localgroup administrators command execution
  * \[Low] Uncommon net localgroup administrators command execution
  * \[Low] Uncommon net localgroup execution
  * \[Low] Uncommon remote net localgroup execution
* \[Low] Sensitive browser credential files accessed by a rare non browser process
* \[Informational] A cloud storage configuration was modified
* \[Informational] Unpopular URL(s) detected in email

### Modified Logic

* \[Low] [ClickFix - PowerShell executed through the run application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clickfix-powershell-executed-through-the-run-application)
  * \[High] ClickFix - Schedule task PowerShell command executed through the run application - Added
* \[High] [Cloud penetration testing tool activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-penetration-testing-tool-activity)
* \[Informational] [Compute activity in dormant cloud region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compute-activity-in-dormant-cloud-region)
  * \[High] Compute activity in dormant cloud region by a compromised AWS access key - Modified Metadata
  * \[Informational] Compute activity in dormant cloud region from a non-VPN IP address - Added
* \[Informational] [Multiple cloud snapshots export](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-cloud-snapshots-export)
  * \[High] 062ca644-b34a-4d95-9ddb-41bce814f5a9 - Added
  * \[High] f17228e4\_558f\_46bd\_bb83\_5c26896ef9bb - Removed
* \[Informational] [Remote usage of AWS Lambda's role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-aws-lambda-s-role)
  * \[High] Remote command line usage of AWS Lambda's role - Removed
  * \[High] Remote command line usage of AWS Lambda's role - Added
* \[High] [Suspicious API call from a Tor exit node](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-api-call-from-a-tor-exit-node)
* \[Informational] [Unsigned DLL Side-Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-side-loading)
  * \[High] DLL Side-Loading of module bearing an invalid Microsoft signature - Modified Logic
  * \[Medium] Unsigned DLL Side-Loading to a signed microsoft process by a rare causality actor - Modified Logic
  * \[Low] Unsigned high entropy DLL Side-Loading by untrusted causality actor - Modified Logic
* \[Medium] [A Kubernetes dashboard service account was used outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-dashboard-service-account-was-used-outside-the-cluster)
* \[Medium] [A cloud storage object was copied to a foreign cloud account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-storage-object-was-copied-to-a-foreign-cloud-account)
* \[Low] [A process queried the ADFS database decryption key via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap)
  * \[Medium] A process explicitly queried the ADFS database decryption key (DKM key) via LDAP - Modified Logic
* \[Medium] [Azure AD PIM alert disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-alert-disabled)
* \[Low] [Azure account deletion by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-deletion-by-a-non-standard-account)
  * \[Medium] A suspicious Azure account deletion by a non-standard account - Modified Logic
* \[Informational] [Azure application credentials added](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-credentials-added)
  * \[Medium] Suspicious credential operation on an Azure application - Modified Logic
  * \[Low] Unusual certificate operation on an Azure application - Modified Logic
* \[Medium] [Cloud snapshot of a database or storage instance was publicly shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-snapshot-of-a-database-or-storage-instance-was-publicly-shared)
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
  * \[Medium] Globally uncommon and very rare image load from a signed process - Modified Logic
* \[Medium] [Kubernetes vulnerability scanning tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-vulnerability-scanning-tool-usage)
  * \[Medium] External Kubernetes vulnerability scanning tool usage - Modified Logic
* \[Low] [LOLBIN process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-process-executed-with-a-high-integrity-level)
  * \[Medium] LOLBIN process executed with a high integrity level by a web server process or CGO - Modified Logic
* \[Low] [Multiple user accounts failed login due to account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts)
  * \[Medium] Excessive user account login failure due to lockout from a suspicious source - Removed
  * \[Medium] Excessive user account login failure due to lockout from a suspicious source - Added
* \[Low] [Possible DCSync from a non domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dcsync-from-a-non-domain-controller)
  * \[Medium] Possible DCSync from an internet-facing server - Removed
  * \[Medium] Possible DCSync from an internet-facing server - Added
* \[Medium] [Script file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/script-file-added-to-startup-related-registry-keys)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) net function was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed)
* \[Low] [Suspicious usage of EC2 token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-ec2-token)
  * \[Medium] Suspicious usage of EC2 token - Modified Logic
* \[Informational] [Uncommon SQL like command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sql-like-command-line)
  * \[Medium] Uncommon SQL like command line executed by a remote actor - Modified Metadata
  * \[Medium] Uncommon SQL like command line executed by an RMM tool - Modified Logic
  * \[Low] Uncommon SQL like command line executed by an uncommon CGO - Modified Logic
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
  * \[Medium] Uncommon attempt at discovering a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
  * \[Medium] Uncommon attempt at grabbing credentials from a sensitive file by a potentially known credential dumper or enumeration script - Modified Logic
* \[Low] [A Backup vault policy was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-backup-vault-policy-was-modified)
* \[Informational] [A Kubernetes node service account activity from external IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-node-service-account-activity-from-external-ip)
  * \[Low] A Kubernetes node service account was used outside the cluster - Modified Logic
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
  * \[Low] UNIX LOLBIN process connected to a rare external host - Modified Logic
* \[Low] [A rare file path was added to the AppInit\_DLLs registry value](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value)
* \[Low] [AWS S3 bucket was exposed to public access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-s3-bucket-was-exposed-to-public-access)
* \[Low] [AWS data asset shared public](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-data-asset-shared-public)
* \[Informational] [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server)
  * \[Low] Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server where both the User Agent and the HTTP Server are rare - Removed
  * \[Low] Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server where both the User Agent and the HTTP Server are rare - Added
* \[Informational] [An AWS database service master user password was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-aws-database-service-master-user-password-was-changed)
  * \[Low] An AWS Database Service master user password was changed from an unusual country - Modified Logic
* \[Low] [An RDS snapshot was exported to an unknown S3 bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-rds-snapshot-was-exported-to-an-unknown-s3-bucket)
* \[Low] [Authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-by-a-honey-user)
* \[Low] [Azure AD PIM role settings change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-role-settings-change)
* \[Low] [Azure Event Hub Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-event-hub-deletion)
* \[Low] [Azure domain federation settings modification attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-domain-federation-settings-modification-attempt)
* \[Informational] [Azure storage account cross-tenant object replication was enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-cross-tenant-object-replication-was-enabled)
  * \[Low] Azure storage account cross-tenant object replication was enabled for the first time in a subscription - Modified Metadata
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] [Executable or Script file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-or-script-file-written-by-a-web-server-process)
  * \[Low] Executable or Script file written by a web server process with connections from various sources and high web traffic - Modified Logic
* \[Informational] [External user added a link to a Microsoft Teams chat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-added-a-link-to-a-microsoft-teams-chat)
  * \[Low] An external user sent a link via Microsoft Teams with suspicious parameters - Modified Logic
* \[Low] [First Azure AD PowerShell operation for a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-azure-ad-powershell-operation-for-a-user)
* \[Informational] [First VPN access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-for-user)
  * \[Low] Unusual VPN access from ASN - Modified Metadata
* \[Low] [GCP data asset shared public](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-data-asset-shared-public)
* \[Informational] [Globally uncommon high entropy process was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-process-was-executed)
  * \[Low] Globally uncommon high entropy process was executed by a web server process or CGO - Modified Logic
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
  * \[Informational] SSO impossible traveler from a VPN or proxy - Removed
  * \[Informational] SSO impossible traveler from a VPN or proxy - Added
* \[Informational] [Kubernetes service account activity outside the cluster](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-service-account-activity-outside-the-cluster)
  * \[Low] Kubernetes service account activity outside the cluster from non-cloud IP - Modified Logic
* \[Low] [MFA was disabled for an Azure identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mfa-was-disabled-for-an-azure-identity)
* \[Low] [Multiple Azure AD admin role removals](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-azure-ad-admin-role-removals)
* \[Low] [Possible DLL Search Order Hijacking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-search-order-hijacking)
  * \[Low] Possible DLL Search Order Hijacking - DLL downloaded from an uncommon source - Modified Metadata
  * \[Low] Possible DLL Search Order Hijacking - DLL extracted from an internet-downloaded archive - Modified Metadata
  * \[Low] Possible DLL Search Order Hijacking by DLL Substitution - Modified Metadata
* \[Low] [Possible multistage attack in Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-multistage-attack-in-microsoft-teams)
* \[Low] [Possible webshell file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-webshell-file-written-by-a-web-server-process)
  * \[Low] Possible webshell file written by a web server process with connections from various sources and high web traffic - Modified Logic
* \[Low] [Potential kubelet impersonation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-kubelet-impersonation-attempt)
* \[Low] [Rare unsigned process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task)
* \[Low] [Remote usage of an AWS service token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-aws-service-token)
* \[Low] [Remote usage of an Azure Managed Identity token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-managed-identity-token)
* \[Low] [Risk indicators detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [SSH authentication brute force attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ssh-authentication-brute-force-attempts)
  * \[Low] Successful SSH Brute Force - Removed
  * \[Low] Successful SSH Brute Force - Added
* \[Low] [SSO authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-attempt-by-a-honey-user)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Suspicious EBS snapshots deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ebs-snapshots-deletion)
* \[Low] [Suspicious access to Kubernetes API with kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-kubernetes-api-with-kubelet-credentials)
* \[Low] [Suspicious activity on logging bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-activity-on-logging-bucket)
* \[Low] [Suspicious identity downloaded multiple objects from a bucket](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-identity-downloaded-multiple-objects-from-a-bucket)
* \[Low] [Uncommon ARP cache listing via arp.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe)
* \[Low] [Uncommon local scheduled task creation via schtasks.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe)
* \[Low] [Uncommon remote monitoring and management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-monitoring-and-management-tool)
* \[Low] [Uncommon remote scheduled task creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-scheduled-task-creation)
* \[Low] [VPN login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-attempt-by-a-honey-user)
* \[Low -> Informational] [Windows event logs were cleared with PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-logs-were-cleared-with-powershell)
  * \[Low] Windows event logs were cleared with uncommon PowerShell command line - Added
* \[Informational] [A Kubernetes ConfigMap was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-configmap-was-created-or-deleted)
* \[Informational] [A Kubernetes Cronjob was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cronjob-was-created)
* \[Informational] [A Kubernetes cluster role binding was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-role-binding-was-created-or-deleted)
* \[Informational] [A Kubernetes cluster was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-cluster-was-created-or-deleted)
* \[Informational] [A Kubernetes ephemeral container was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-ephemeral-container-was-created)
* \[Informational] [A Kubernetes namespace was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-namespace-was-created-or-deleted)
* \[Informational] [A Kubernetes role binding was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-role-binding-was-created-or-deleted)
* \[Informational] [A Kubernetes secret was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-secret-was-created-or-deleted)
* \[Informational] [A Kubernetes service account was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-account-was-created-or-deleted)
* \[Informational] [A Kubernetes service was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-kubernetes-service-was-created-or-deleted)
* \[Informational] [A cloud identity created or modified a security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-created-or-modified-a-security-group)
* \[Informational] [A cloud identity executed an API call from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-executed-an-api-call-from-an-unusual-country)
* \[Informational] [A cloud identity invoked IAM related persistence operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-invoked-iam-related-persistence-operations)
* \[Informational] [A cloud identity started a Cloud Shell session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-identity-started-a-cloud-shell-session)
* \[Informational] [A cloud instance was stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-instance-was-stopped)
* \[Informational] [A cloud snapshot of AWS database or storage was modified or shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-snapshot-of-aws-database-or-storage-was-modified-or-shared)
* \[Informational] [A compute-attached identity executed API calls outside the instance's region](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-region)
* \[Informational] [A container registry was created or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-container-registry-was-created-or-deleted)
* \[Informational] [A possible risky login to Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-risky-login-to-azure)
* \[Informational] [AWS Backup recovery point deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-backup-recovery-point-deletion)
* \[Informational] [AWS EBS enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-enumeration-activity)
* \[Informational] [AWS EBS snapshot deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ebs-snapshot-deletion)
* \[Informational] [AWS EC2 infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-infrastructure-enumeration-activity)
* \[Informational] [AWS Flow Logs deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-flow-logs-deletion)
* \[Informational] [AWS Lambda infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-lambda-infrastructure-enumeration-activity)
* \[Informational] [AWS Password Policy Discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-password-policy-discovery)
* \[Informational] [AWS S3 Buckets enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-s3-buckets-enumeration-activity)
* \[Informational] [AWS S3 object deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS SSM parameters discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-parameters-discovery)
* \[Informational] [AWS SSM parameters retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ssm-parameters-retrieval)
* \[Informational] [AWS Secrets Manager Access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS Secrets Manager discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-secrets-manager-discovery)
* \[Informational] [AWS Storage Gateway enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-storage-gateway-enumeration)
* \[Informational] [AWS Storage Gateway file share enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-storage-gateway-file-share-enumeration)
* \[Informational] [AWS Transfer Family server created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-transfer-family-server-created)
* \[Informational] [AWS principals discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-principals-discovery)
* \[Informational] [AWS resource discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-resource-discovery)
* \[Informational] [An Azure Firewall rule collection group was modified or deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-firewall-rule-collection-group-was-modified-or-deleted)
* \[Informational] [An Azure Key Vault key was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-azure-key-vault-key-was-modified)
* \[Informational] [An EBS snapshot block was downloaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-ebs-snapshot-block-was-downloaded)
* \[Informational] [An identity accessed a backup cloud storage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-a-backup-cloud-storage)
* \[Informational] [An identity accessed a cloud storage for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-accessed-a-cloud-storage-for-the-first-time)
* \[Informational] [An identity accessed cloud storage containing sensitive data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [An identity attached an administrative policy to an IAM user or role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-attached-an-administrative-policy-to-an-iam-user-or-role)
* \[Informational] [An identity created or updated password for an IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-created-or-updated-password-for-an-iam-user)
* \[Informational] [An identity initiated a download of multiple cloud objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects)
* \[Informational] [An identity performed a suspicious download of multiple cloud storage objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objects)
* \[Informational] [An uncommon RDP session from a managed host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-rdp-session-from-a-managed-host)
* \[Informational] [An unknown account was invited to the AWS organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unknown-account-was-invited-to-the-aws-organization)
* \[Informational] [An unusual cloud identity was granted permissions to a BigQuery resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-cloud-identity-was-granted-permissions-to-a-bigquery-resource)
* \[Informational] [An unusual read activity of cloud object](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-read-activity-of-cloud-object)
* \[Informational] [Authentication method added to an Azure account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-method-added-to-an-azure-account)
* \[Informational] [Azure AD PIM elevation request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-pim-elevation-request)
* \[Informational] [Azure AD account unlock/password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-ad-account-unlock-password-reset-attempt)
* \[Informational] [Azure Automation Account Creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-account-creation)
* \[Informational] [Azure Automation Runbook Creation/Modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-creation-modification)
* \[Informational] [Azure Automation Runbook Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-automation-runbook-deletion)
* \[Informational] [Azure Key Vault modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-key-vault-modification)
* \[Informational] [Azure Resource Group Deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-resource-group-deletion)
* \[Informational] [Azure Temporary Access Pass (TAP) registered to an account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-temporary-access-pass-tap-registered-to-an-account)
* \[Informational] [Azure account creation by a non-standard account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-account-creation-by-a-non-standard-account)
* \[Informational] [Azure application consent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-application-consent)
* \[Informational] [Azure device code authentication flow used](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-device-code-authentication-flow-used)
* \[Informational] [Azure storage account blob anonymous access is enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-blob-anonymous-access-is-enabled)
* \[Informational] [Azure storage account was publicly shared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-storage-account-was-publicly-shared)
* \[Informational] [BigQuery table or query results exfiltrated to a foreign project](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bigquery-table-or-query-results-exfiltrated-to-a-foreign-project)
* \[Informational] [BitLocker key retrieval](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitlocker-key-retrieval)
* \[Informational] [Bucket's block public access setting turned off](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bucket-s-block-public-access-setting-turned-off)
* \[Informational] [Bucket's object ownership controls were modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bucket-s-object-ownership-controls-were-modified)
* \[Informational] [Cloud access key creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-access-key-creation)
  * \[Informational] Successful access key creation by an unusual identity type - Modified Metadata
  * \[Informational] Unusual successful cloud access key creation - Modified Metadata
* \[Informational] [Cloud compute instance user data script modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-instance-user-data-script-modification)
* \[Informational] [Cloud compute serial console access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-serial-console-access)
* \[Informational] [Cloud compute volume creation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-compute-volume-creation-attempt)
* \[Informational] [Cloud email infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-email-infrastructure-enumeration-activity)
* \[Informational] [Cloud infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-infrastructure-enumeration-activity)
* \[Informational] [Cloud instance creation attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-instance-creation-attempt)
* \[Informational] [Cloud instance deletion attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-instance-deletion-attempt)
* \[Informational] [Cloud resource logging was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-resource-logging-was-disabled)
* \[Informational] [Cloud snapshot created or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-snapshot-created-or-modified)
* \[Informational] [Cloud user performed multiple actions that were denied](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-user-performed-multiple-actions-that-were-denied)
* \[Informational] [CloudTrail logging deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloudtrail-logging-deletion)
* \[Informational] [Data encryption was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-encryption-was-disabled)
* \[Informational] [Deletion of multiple cloud resources](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/deletion-of-multiple-cloud-resources)
* \[Informational] [Device Registration Policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/device-registration-policy-modification)
* \[Informational] [EBS volume attachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-attachment-attempt)
* \[Informational] [EBS volume detachment attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ebs-volume-detachment-attempt)
* \[Informational] [EC2 instance Amazon machine image was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ec2-instance-amazon-machine-image-was-created)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [External Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-login-password-spray)
  * \[Informational] External Login Password Spray from Multiple Source Hosts - Added
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [External user created a Microsoft Teams conversation with suspicious operations](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-created-a-microsoft-teams-conversation-with-suspicious-operations)
* \[Informational] [External user started a Microsoft Teams conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-user-started-a-microsoft-teams-conversation)
* \[Informational] [First SSO Resource Access in the Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-resource-access-in-the-organization)
* \[Informational] [First SSO access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-for-user)
* \[Informational] [First SSO access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-in-organization)
* \[Informational] [First VPN access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-in-organization)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
* \[Informational] [Foreign account was granted permissions to S3 bucket via resource-based policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/foreign-account-was-granted-permissions-to-s3-bucket-via-resource-based-policy)
* \[Informational] [GCP logging sink modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/gcp-logging-sink-modification)
* \[Informational] [Globally uncommon IP address by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256)
* \[Informational] [IAM Enumeration sequence](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-enumeration-sequence)
* \[Informational] [IAM User added to an IAM group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-user-added-to-an-iam-group)
* \[Informational] [IAM inline policy was added to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-group)
* \[Informational] [IAM inline policy was added to role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-role)
* \[Informational] [IAM inline policy was added to user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-inline-policy-was-added-to-user)
* \[Informational] [IAM instance profile associations were described](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-associations-were-described)
* \[Informational] [IAM instance profile was associated with EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-associated-with-ec2-instance)
* \[Informational] [IAM instance profile was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-created)
* \[Informational] [IAM instance profile was replaced for EC2 instance](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-instance-profile-was-replaced-for-ec2-instance)
* \[Informational] [IAM instance profiles were listed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [IAM policy default version was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-default-version-was-changed)
* \[Informational] [IAM policy version was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-version-was-created)
* \[Informational] [IAM policy was attached to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-was-attached-to-group)
* \[Informational] [IAM policy was attached to role](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-policy-was-attached-to-role)
* \[Informational] [IAM role trust policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-trust-policy-modification)
* \[Informational] [IAM role was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-was-created)
* \[Informational] [IAM role-attached managed policies were listed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iam-role-attached-managed-policies-were-listed)
* \[Informational] [Kubernetes cluster events deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-cluster-events-deletion)
* \[Informational] [Kubernetes enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-enumeration-activity)
* \[Informational] [Kubernetes network policy modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-network-policy-modification)
* \[Informational] [Log enumeration via cloud native logging service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/log-enumeration-via-cloud-native-logging-service)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Multiple failed logins from a single IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-failed-logins-from-a-single-ip)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [Network sniffing detected in Cloud environment](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/network-sniffing-detected-in-cloud-environment)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Okta account reset password attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-reset-password-attempt)
* \[Informational] [Okta account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock)
* \[Informational] [Okta account unlock by admin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-account-unlock-by-admin)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Owner added to Azure application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/owner-added-to-azure-application)
* \[Informational] [Possible DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-hijack-into-a-microsoft-process)
  * \[Informational] Possible DLL Side-Loading into a Microsoft process from a suspicious folder - Removed
  * \[Informational] Possible DLL Side-Loading into a Microsoft process from a suspicious folder - Added
* \[Informational] [Potential Okta access limit breach](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-okta-access-limit-breach)
* \[Informational] [Potential creation of persistent cloud credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-creation-of-persistent-cloud-credentials)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Rare NTLM Access By User To Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-access-by-user-to-host)
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Remote usage of VM Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-vm-service-account-token)
* \[Informational] [Remote usage of an App engine Service Account token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-app-engine-service-account-token)
* \[Informational] [Remote usage of an Azure Service Principal token](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-usage-of-an-azure-service-principal-token)
* \[Informational] [Retrieval of cloud compute EC2 instance user data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/retrieval-of-cloud-compute-ec2-instance-user-data)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [Serial console access was enabled in AWS account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/serial-console-access-was-enabled-in-aws-account)
* \[Informational] [Storage enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/storage-enumeration-activity)
* \[Informational] [Suspicious SSO access from ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-access-from-asn)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Uncommon signed process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unrecognized sender domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unusual AWS CLI/SDK activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-cli-sdk-activity)
* \[Informational] [Unusual AWS S3 objects deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-s3-objects-deletion)
* \[Informational] [Unusual AWS systems manager activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-systems-manager-activity)
* \[Informational] [Unusual Conditional Access operation for an identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-conditional-access-operation-for-an-identity)
* \[Informational] [Unusual Identity and Access Management (IAM) activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-identity-and-access-management-iam-activity)
* \[Informational] [Unusual Kubernetes secret access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-secret-access)
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
* \[Informational] [Unusual key management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-key-management-activity)
* \[Informational] [Unusual resource modification by newly seen IAM user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-resource-modification-by-newly-seen-iam-user)
* \[Informational] [Unusual secret management activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-secret-management-activity)
* \[Informational] [Unusual user-agent for a cloud identity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-agent-for-a-cloud-identity)
* \[Informational] [Unverified domain added to Azure AD](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unverified-domain-added-to-azure-ad)
* \[Informational] [User attempted to connect from a suspicious country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country)
* \[Informational] [Web server CGO executed an uncommon process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/web-server-cgo-executed-an-uncommon-process)
* \[Informational] [Windows CGO, actor and action processes with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics)

### Modified Metadata

* \[Informational] [Suspicious process loads a known PowerShell module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-loads-a-known-powershell-module)
  * \[High] Office process loads a known PowerShell DLL - Modified Metadata
* \[Informational] [Execution of an uncommon process at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage)
  * \[Medium -> Low] Execution of an uncommon process at an early startup stage with suspicious characteristics - Modified Metadata
* \[Low] [Execution of an uncommon process at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary)
  * \[Medium -> Low] Execution of an uncommon process at an early startup stage by Windows system binary with suspicious characteristics - Modified Metadata
* \[Informational] [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage)
  * \[Medium -> Low] Execution of an uncommon process with a local/domain user SID at an early startup stage with suspicious characteristics - Modified Metadata
* \[Low] [Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage-by-windows-system-binary)
  * \[Medium -> Low] Execution of an uncommon process with a local/domain user SID at an early startup stage with a suspicious characteristics by Windows system binary - Modified Metadata
* \[Informational] [Local group enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration)
  * \[Low -> Informational] Local group enumeration using a builtin Windows binary - Modified Metadata
* \[Informational] [Rare DLP rule match by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dlp-rule-match-by-user)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-02-25.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
