> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-04.md).

# 2026.03.04

### Release date: 15-March-2026

### Summary

#### Added

* **8 Detectors:** 1 Medium, 5 Low, 2 Informational
* **8 Variations:** 3 High, 4 Medium, 1 Low

#### Modified Logic

* **720 Detectors:** 18 High, 76 Medium, 246 Low, 380 Informational
* **23 Variations:** 8 Medium, 11 Low, 4 Informational

#### Modified Metadata

* **5 Detectors:** 5 Informational

### Added

* \[Low] [Data exfiltration from cloud database](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-exfiltration-from-cloud-database)
  * \[High] Data exfiltration from cloud database containing sensitive data from a production account toa foreign account
  * \[High] Suspicious data exfiltration from cloud database
* \[Low] [Possible phishing attack via Microsoft Teams](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-phishing-attack-via-microsoft-teams)
  * \[High] Potential phishing attack with post compromise stages had been detected
  * \[Medium] Potential phishing attack via Microsoft Teams has been detected
  * \[Medium] Potential phishing attack with post compromise activities in Microsoft Teams has been detected
* \[Medium] [Azure Privilege Escalation Using an Application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/azure-privilege-escalation-using-an-application)
* \[Low] [Possible Insider Threat Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-insider-threat-activity)
  * \[Medium] Indicate Insider Threat Activity
* \[Low] [Potential extraction of NAA Account Credentials in Microsoft Configuration Manager](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-extraction-of-naa-account-credentials-in-microsoft-configuration-manager)
  * \[Medium] Suspicious extraction of NAA Account Credentials in Microsoft Configuration Manager
* \[Low] [Suspicious LDAP queries followed by shared folder access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ldap-queries-followed-by-shared-folder-access)
* \[Informational] [Windows CGO, actor process and action module with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-process-and-action-module-with-anomalous-characteristics)
  * \[Low] Windows CGO, actor process and action module with very anomalous characteristics
* \[Informational] [A Cloud DB instance was exported to an unknown destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-cloud-db-instance-was-exported-to-an-unknown-destination)

### Modified Logic

* \[High] [A Successful VPN connection from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-vpn-connection-from-tor)
* \[High] [A Successful login from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-login-from-tor)
* \[High] [A successful SSO sign-in from TOR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-successful-sso-sign-in-from-tor)
* \[High] [Bronze-Bit exploit](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bronze-bit-exploit)
* \[High] [Cloud penetration testing tool activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cloud-penetration-testing-tool-activity)
* \[High] [Copy a process memory file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-process-memory-file)
* \[High] [Hydra Password Brute-Force Tool Execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hydra-password-brute-force-tool-execution)
* \[High] [Memory dumping with comsvcs.dll](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/memory-dumping-with-comsvcs-dll)
* \[High] [Mimikatz command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mimikatz-command-line-arguments)
* \[High] [Netcat makes or gets connections](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/netcat-makes-or-gets-connections)
* \[High] [Possible Distributed File System Namespace Management (DFSNM) abuse](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-distributed-file-system-namespace-management-dfsnm-abuse)
* \[High] [Possible brute force or configuration change attempt on cytool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-or-configuration-change-attempt-on-cytool)
* \[High] [PowerShell used to remove mailbox export request logs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-used-to-remove-mailbox-export-request-logs)
* \[High] [Remote service command execution from an uncommon source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-service-command-execution-from-an-uncommon-source)
* \[High] [Suspicious dump of ntds.dit using Shadow Copy with ntdsutil/vssadmin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dump-of-ntds-dit-using-shadow-copy-with-ntdsutil-vssadmin)
* \[High] [Suspicious usage of File Server Remote VSS Protocol (FSRVP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-file-server-remote-vss-protocol-fsrvp)
* \[High] [Unicode RTL Override Character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unicode-rtl-override-character)
* \[High] [Wbadmin deleted files in quiet mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wbadmin-deleted-files-in-quiet-mode)
* \[Medium] [A Possible crypto miner was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-crypto-miner-was-detected-on-a-host)
* \[Medium] [A TCP stream was created directly in a shell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-tcp-stream-was-created-directly-in-a-shell)
* \[Medium] [A contained executable from a mounted share initiated a suspicious outbound network connection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-executable-from-a-mounted-share-initiated-a-suspicious-outbound-network-connection)
* \[Medium] [A contained executable was executed by an unusual process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-executable-was-executed-by-an-unusual-process)
* \[Medium] [A contained process attempted to escape using the 'notify on release' feature](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-contained-process-attempted-to-escape-using-the-notify-on-release-feature)
* \[Medium] [A machine certificate was issued with a mismatch](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-machine-certificate-was-issued-with-a-mismatch)
* \[Medium] [A new machine attempted Kerberos delegation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-new-machine-attempted-kerberos-delegation)
* \[Medium] [A process was executed with a command line obfuscated by Unicode character substitution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitution)
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-process)
  * \[Medium] A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process which was executed by untrusted causality actor - Modified Logic
  * \[Low] A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process which was executed by a scheduled task - Added
* \[Medium] [A suspicious executable with multiple file extensions was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-executable-with-multiple-file-extensions-was-created)
* \[Medium] [An internal Cloud resource performed port scan on external networks](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-internal-cloud-resource-performed-port-scan-on-external-networks)
* \[Medium] [Autorun.inf created in root C drive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/autorun-inf-created-in-root-c-drive)
* \[Medium] [Bitsadmin.exe persistence using command-line callback](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitsadmin-exe-persistence-using-command-line-callback)
* \[Medium] [Commonly abused AutoIT script connects to an external domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-autoit-script-connects-to-an-external-domain)
* \[Medium] [Discovery of misconfigured certificate templates using LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-misconfigured-certificate-templates-using-ldap)
* \[Medium] [Encoded information using Windows certificate management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/encoded-information-using-windows-certificate-management-tool)
* \[Medium] [Executable created to disk by lsass.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-created-to-disk-by-lsass-exe)
* \[Medium] [Fodhelper.exe UAC bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/fodhelper-exe-uac-bypass)
* \[Medium] [Indirect command execution using the Program Compatibility Assistant](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indirect-command-execution-using-the-program-compatibility-assistant)
* \[Medium] [Kerberos Traffic from Non-Standard Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-traffic-from-non-standard-process)
* \[Medium] [Kerberos User Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-user-enumeration)
* \[Medium] [Kubernetes vulnerability scanner activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-vulnerability-scanner-activity)
* \[Medium] [LSASS dump file written to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lsass-dump-file-written-to-disk)
* \[Medium] [Machine account was added to a domain admins group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/machine-account-was-added-to-a-domain-admins-group)
* \[Medium] [Mailbox Client Access Setting (CAS) changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mailbox-client-access-setting-cas-changed)
* \[Medium] [Manipulation of netsh helper DLLs Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-netsh-helper-dlls-registry-keys)
* \[Medium] [Microsoft Office Process Spawning a Suspicious One-Liner](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-process-spawning-a-suspicious-one-liner)
* \[Medium] [NTLM Hash Harvesting](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-hash-harvesting)
* \[Medium] [New Administrative Behavior](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-administrative-behavior)
* \[Medium] [Phantom DLL Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/phantom-dll-loading)
* \[Medium] [Possible Persistence via group policy Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-persistence-via-group-policy-registry-keys)
* \[Medium] [Possible RDP session hijacking using tscon.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-rdp-session-hijacking-using-tscon-exe)
* \[Medium] [Possible Search For Password Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-search-for-password-files)
* \[Medium] [Possible code downloading from a remote host by Regsvr32](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-code-downloading-from-a-remote-host-by-regsvr32)
* \[Medium] [Possible collection of screen captures with Windows Problem Steps Recorder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-collection-of-screen-captures-with-windows-problem-steps-recorder)
* \[Medium] [Possible compromised machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-compromised-machine-account)
* \[Medium] [Possible malicious .NET compilation started by a commonly abused process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-malicious-net-compilation-started-by-a-commonly-abused-process)
* \[Medium] [Possible new DHCP server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-new-dhcp-server)
* \[Low -> Medium] [Potential Phishing has been detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-phishing-has-been-detected)
  * \[Medium] Potential Brand Impersonation has been detected - Removed
  * \[Medium] Potential Business Email Compromise has been detected - Modified Metadata
  * \[Medium] Potential Exfiltration has been detected - Added
  * \[Medium] Potential Phishing has been detected - Removed
  * \[Medium] Potential Spear Phishing has been detected - Modified Metadata
* \[Medium] [PowerShell suspicious flags](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-suspicious-flags)
* \[Medium] [PowerShell used to export mailbox contents](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-used-to-export-mailbox-contents)
* \[Medium] [Procdump executed from an atypical directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/procdump-executed-from-an-atypical-directory)
* \[Medium] [RDP Connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connection-to-localhost)
* \[Medium] [Random-Looking Domain Names](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/random-looking-domain-names)
* \[Medium] [Remote WMI process execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-wmi-process-execution)
* \[Medium] [Rundll32.exe running with no command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-running-with-no-command-line-arguments)
* \[Medium] [Rundll32.exe spawns conhost.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-spawns-conhost-exe)
* \[Informational] [SSO Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-password-spray)
  * \[Medium] SSO Password Spray Threat Detected - Modified Logic
  * \[Low] SSO Password Spray Activity Observed - Modified Logic
* \[Medium] [Script file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/script-file-added-to-startup-related-registry-keys)
* \[Medium] [Service ticket request with a spoofed sAMAccountName](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/service-ticket-request-with-a-spoofed-samaccountname)
* \[Medium] [Sudoedit Brute force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudoedit-brute-force-attempt)
* \[Medium] [Suspicious .NET process loads an MSBuild DLL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-net-process-loads-an-msbuild-dll)
* \[Medium] [Suspicious Encrypting File System Remote call (EFSRPC) to domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-encrypting-file-system-remote-call-efsrpc-to-domain-controller)
* \[Medium] [Suspicious HTTP parameters detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-http-parameters-detected)
* \[Medium] [Suspicious Kubernetes pod token access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-kubernetes-pod-token-access)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) net function was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-net-function-was-executed)
* \[Medium] [Suspicious PowerSploit's recon module (PowerView) used to search for exposed hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powersploit-s-recon-module-powerview-used-to-search-for-exposed-hosts)
* \[Medium] [Suspicious Process Spawned by wininit.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawned-by-wininit-exe)
* \[Medium] [Suspicious SearchProtocolHost.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-searchprotocolhost-exe-parent-process)
* \[Medium] [Suspicious authentication package registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-authentication-package-registered)
* \[Medium] [Suspicious authentication with Azure Password Hash Sync user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-authentication-with-azure-password-hash-sync-user)
* \[Medium] [Suspicious certutil command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-command-line)
* \[Medium] [Suspicious dNSHostName attribute change to DC name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dnshostname-attribute-change-to-dc-name)
* \[Medium] [Suspicious disablement of the Windows Firewall using PowerShell commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-disablement-of-the-windows-firewall-using-powershell-commands)
* \[Medium] [Suspicious hidden user created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-hidden-user-created)
* \[Medium] [Suspicious print processor registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-print-processor-registered)
* \[Informational] [Suspicious secrets dump activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-secrets-dump-activity)
  * \[Medium] An identity extracted every secret within the organization across multiple regions - Added
* \[Medium] [Suspicious time provider registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-time-provider-registered)
* \[Medium] [TGT request with a spoofed sAMAccountName - Event log](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-event-log)
* \[Medium] [TGT request with a spoofed sAMAccountName - Network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tgt-request-with-a-spoofed-samaccountname-network)
* \[Medium] [The CA policy EditFlags was queried](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/the-ca-policy-editflags-was-queried)
* \[Medium] [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dll-sideloading-from-a-logical-cd-rom-iso-device)
* \[Medium] [Uncommon Service Create/Config](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-service-create-config)
* \[Medium] [Uncommon SetWindowsHookEx API invocation of a possible keylogger](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-setwindowshookex-api-invocation-of-a-possible-keylogger)
* \[Medium] [Uncommon jsp file write by a Java process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-jsp-file-write-by-a-java-process)
* \[Medium] [Unsigned process injecting into a Windows system binary with no command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-injecting-into-a-windows-system-binary-with-no-command-line)
* \[Medium] [Unusual process access to ld.so.preload file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-access-to-ld-so-preload-file)
* \[Medium] [Windows Installer exploitation for local privilege escalation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-installer-exploitation-for-local-privilege-escalation)
* \[Medium] [Windows LOLBIN executable connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-lolbin-executable-connected-to-a-rare-external-host)
* \[Low] [A commonly abused process connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-cloud-resource)
* \[Low] [A commonly abused process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-commonly-abused-process-connected-to-a-rare-external-host)
* \[Low] [A compiled HTML help file wrote a script file to the disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compiled-html-help-file-wrote-a-script-file-to-the-disk)
* \[Low] [A computer account was promoted to DC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-computer-account-was-promoted-to-dc)
* \[Low] [A disabled user attempted to log in to a VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-log-in-to-a-vpn)
* \[Low] [A process queried the ADFS database decryption key via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-queried-the-adfs-database-decryption-key-via-ldap)
* \[Low] [A rare FTP user has been detected on an existing FTP server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-server)
* \[Low] [A rare file path was added to the AppInit\_DLLs registry value](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-file-path-was-added-to-the-appinit-dlls-registry-value)
* \[Low] [A remote service was created via RPC over SMB](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-remote-service-was-created-via-rpc-over-smb)
* \[Low] [A suspicious direct syscall was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-direct-syscall-was-executed)
* \[Low] [A suspicious process enrolled for a certificate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-process-enrolled-for-a-certificate)
* \[Low] [A user connected a new USB storage device to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-multiple-hosts)
* \[Low] [A user modified the CA audit policy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-modified-the-ca-audit-policy)
* \[Low] [A user rejected an SSO request from an unusual country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-rejected-an-sso-request-from-an-unusual-country)
* \[Low] [A user sent multiple TGT requests to irregular service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-sent-multiple-tgt-requests-to-irregular-service)
* \[Low] [Abnormal ICMP echo (PING) to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-icmp-echo-ping-to-multiple-hosts)
* \[Low] [Abnormal RPC traffic to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rpc-traffic-to-multiple-hosts)
* \[Low] [Abnormal SMB activity to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-smb-activity-to-multiple-hosts)
* \[Low] [Abnormal communication with a rare combination of TLS and HTTP User Agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-with-a-rare-combination-of-tls-and-http-user-agent)
* \[Low] [Abnormal network communication through TOR using an uncommon port](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-through-tor-using-an-uncommon-port)
* \[Low] [Abnormal sensitive RPC traffic to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-sensitive-rpc-traffic-to-multiple-hosts)
* \[Low] [Account probing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/account-probing)
* \[Low] [An uncommon executable was remotely written over SMB to an uncommon destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-executable-was-remotely-written-over-smb-to-an-uncommon-destination)
* \[Low] [An uncommon service was started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-service-was-started)
* \[Low] [An unpopular process accessed the microphone on the host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unpopular-process-accessed-the-microphone-on-the-host)
* \[Low] [Attempt to execute a command on a remote host using PsExec.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/attempt-to-execute-a-command-on-a-remote-host-using-psexec-exe)
* \[Low] [Authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-by-a-honey-user)
* \[Low] [Cached credentials discovery with cmdkey](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/cached-credentials-discovery-with-cmdkey)
* \[Low] [Certutil pfx parsing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/certutil-pfx-parsing)
* \[Low] [Change of sudo caching configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/change-of-sudo-caching-configuration)
* \[Low] [ClickFix - PowerShell executed through the run application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clickfix-powershell-executed-through-the-run-application)
* \[Low] [Command running with COMSPEC in the command line argument](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-running-with-comspec-in-the-command-line-argument)
* \[Low] [Compressing data using python](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compressing-data-using-python)
* \[Low] [Conhost.exe spawned a suspicious cmd process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/conhost-exe-spawned-a-suspicious-cmd-process)
* \[Low] [Contained process execution with a rare GitHub URL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/contained-process-execution-with-a-rare-github-url)
* \[Low] [Copy a user's GnuPG directory with rsync](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/copy-a-user-s-gnupg-directory-with-rsync)
* \[Low] [DNS Tunneling](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dns-tunneling)
* \[Low] [Delayed Deletion of Files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/delayed-deletion-of-files)
* \[Low] [Discovery of accounts with pre-authentication disabled via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-accounts-with-pre-authentication-disabled-via-ldap)
* \[Low] [Download a script using the python requests module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-a-script-using-the-python-requests-module)
* \[Low] [Elevation to SYSTEM via services](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/elevation-to-system-via-services)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-right-to-left-override-unicode-character)
* \[Low] [Email was received from an unknown sender using a disposable domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-sender-using-a-disposable-domain)
* \[Low] [Email with file-sharing link containing auto-download parameter](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-file-sharing-link-containing-auto-download-parameter)
* \[Low] [Excessive user account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/excessive-user-account-lockouts)
* \[Low] [Executable or Script file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-or-script-file-written-by-a-web-server-process)
* \[Low] [Execution of an uncommon process at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binary)
* \[Low] [Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage-by-windows-system-binary)
* \[Low] [Execution of command from within a Kubernetes pod using kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-command-from-within-a-kubernetes-pod-using-kubelet-credentials)
* \[Low] [Execution of dllhost.exe with an empty command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-dllhost-exe-with-an-empty-command-line)
* \[Low] [Extracting credentials from Unix files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/extracting-credentials-from-unix-files)
* \[Low] [FTP Connection Using an Anonymous Login or Default Credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ftp-connection-using-an-anonymous-login-or-default-credentials)
* \[Low] [Failed Connections](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-connections)
* \[Low] [Failed DNS](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-dns)
* \[Informational] [Globally uncommon high entropy module was loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-module-was-loaded)
  * \[Low] Globally uncommon high entropy module was loaded by process which was executed by a scheduled task - Added
* \[Informational] [Globally uncommon image load from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-image-load-from-a-signed-process)
  * \[Low] Globally uncommon image load from an injected thread in a signed process - Modified Logic
* \[Informational] [Globally uncommon injection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-injection-from-a-signed-process)
  * \[Low] Globally uncommon injection from a signed process which was executed by a scheduled task - Added
* \[Low] [Globally uncommon root domain from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-from-a-signed-process)
* \[Low] [Globally uncommon root-domain port combination from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-from-a-signed-process)
* \[Low] [HTTP with suspicious characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/http-with-suspicious-characteristics)
* \[Low] [Image file execution options (IFEO) registry key set](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/image-file-execution-options-ifeo-registry-key-set)
* \[Low] [Impossible traveler - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-sso)
* \[Low] [Impossible traveler - VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impossible-traveler-vpn)
* \[Informational] [Injection into rundll32.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/injection-into-rundll32-exe)
  * \[Low] Injection into rundll32.exe which was executed by a scheduled task - Added
* \[Low] [Installation of a new System-V service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/installation-of-a-new-system-v-service)
* \[Low] [Interactive at.exe privilege escalation method](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-at-exe-privilege-escalation-method)
* \[Low] [Interactive local account enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-local-account-enumeration)
* \[Low] [Interactive login by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-by-a-service-account)
* \[Low] [Kerberos Pre-Auth Failures by Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-pre-auth-failures-by-host)
* \[Low] [Keylogging using system commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/keylogging-using-system-commands)
* \[Low] [Known service display name with uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-display-name-with-uncommon-image-path)
* \[Low] [Known service name with an uncommon image-path](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/known-service-name-with-an-uncommon-image-path)
* \[Low] [LDAP AD CS Enumeration via Attack Tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-ad-cs-enumeration-via-attack-tool)
* \[Low] [LDAP search query from an unpopular and unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-search-query-from-an-unpopular-and-unsigned-process)
* \[Low] [LOLBIN process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-process-executed-with-a-high-integrity-level)
* \[Low] [Large Upload (FTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-ftp)
* \[Low] [Large Upload (Generic)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-generic)
* \[Low] [Large Upload (HTTPS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-https)
* \[Low] [Large Upload (SMTP)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/large-upload-smtp)
* \[Low] [Linux system firewall was modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-system-firewall-was-modified)
* \[Low] [Login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/login-attempt-by-a-honey-user)
* \[Low] [Machine Account NTLM Relay](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/machine-account-ntlm-relay)
* \[Low] [Masquerading as a default local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/masquerading-as-a-default-local-account)
* \[Low] [Masquerading as the Linux crond process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/masquerading-as-the-linux-crond-process)
* \[Low] [Microsoft Office adds a value to autostart Registry key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-adds-a-value-to-autostart-registry-key)
* \[Low] [Microsoft Office injects code into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-injects-code-into-a-process)
* \[Low] [Microsoft Office process spawns a commonly abused process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-office-process-spawns-a-commonly-abused-process)
* \[Low] [Modification of NTLM restrictions in the Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-ntlm-restrictions-in-the-registry)
* \[Low] [Mount command was executed from within a Kubernetes pod to list all the attached filesystems](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mount-command-was-executed-from-within-a-kubernetes-pod-to-list-all-the-attached-filesystems)
* \[Low] [MpCmdRun.exe was used to download files into the system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mpcmdrun-exe-was-used-to-download-files-into-the-system)
* \[Low] [Mshta.exe launched with suspicious arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-launched-with-suspicious-arguments)
* \[Low] [Mshta.exe spawns from a browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mshta-exe-spawns-from-a-browser-process)
* \[Low] [Multiple Rare LOLBIN Process Executions by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-rare-lolbin-process-executions-by-user)
* \[Low] [Multiple Suspicious FTP Login Attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-suspicious-ftp-login-attempts)
* \[Low] [Multiple Weakly-Encrypted Kerberos Tickets Received](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-weakly-encrypted-kerberos-tickets-received)
* \[Low] [Multiple discovery commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands)
* \[Low] [Multiple discovery commands on a Windows host by the same process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands-on-a-windows-host-by-the-same-process)
* \[Low] [Multiple suspicious user accounts were created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-suspicious-user-accounts-were-created)
* \[Low] [Multiple uncommon SSH Servers with the same Server host key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-uncommon-ssh-servers-with-the-same-server-host-key)
* \[Low] [Multiple user accounts failed login due to account lockouts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-failed-login-due-to-account-lockouts)
* \[Low] [NTDS.dit file written by an uncommon executable](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntds-dit-file-written-by-an-uncommon-executable)
* \[Low] [NTLM Brute Force on a Service Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force-on-a-service-account)
* \[Low] [NTLM Brute Force on an Administrator Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force-on-an-administrator-account)
* \[Low] [New FTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-ftp-server)
* \[Low] [New Shared User Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-shared-user-account)
* \[Low] [New addition to Windows Defender exclusion list](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-addition-to-windows-defender-exclusion-list)
* \[Low] [Non-browser access to a pastebin-like site](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/non-browser-access-to-a-pastebin-like-site)
* \[Low] [Office process accessed an unusual .LNK file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-accessed-an-unusual-lnk-file)
* \[Low] [Office process spawned with suspicious command-line arguments](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/office-process-spawned-with-suspicious-command-line-arguments)
* \[Low] [Okta FastPass reported phishing attack suspected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/okta-fastpass-reported-phishing-attack-suspected)
* \[Low] [Outlook files accessed by an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outlook-files-accessed-by-an-unsigned-process)
* \[Low] [Possible DCSync from a non domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dcsync-from-a-non-domain-controller)
* \[Low] [Possible DLL Search Order Hijacking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-search-order-hijacking)
* \[Low] [Possible Kerberoasting without SPNs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberoasting-without-spns)
* \[Low] [Possible Kerberos relay attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberos-relay-attack)
* \[Low] [Possible Pass-the-Hash](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-pass-the-hash)
* \[Low] [Possible external RDP Brute-Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-external-rdp-brute-force)
* \[Low] [Possible network service discovery via command-line tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-service-discovery-via-command-line-tool)
* \[Low] [Possible network sniffing attempt via tcpdump or tshark](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-network-sniffing-attempt-via-tcpdump-or-tshark)
* \[Low] [Possible path traversal via HTTP request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-path-traversal-via-http-request)
* \[Low] [Possible webshell file written by a web server process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-webshell-file-written-by-a-web-server-process)
* \[Low] [Potential SCCM credential harvesting using WMI detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-sccm-credential-harvesting-using-wmi-detected)
* \[Low] [PowerShell Initiates a Network Connection to GitHub](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-initiates-a-network-connection-to-github)
* \[Low] [PowerShell runs suspicious base64-encoded commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-runs-suspicious-base64-encoded-commands)
* \[Low] [RDP connections enabled remotely via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-connections-enabled-remotely-via-registry)
* \[Low] [Rare LDAP enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ldap-enumeration)
* \[Low] [Rare RDP session to a remote host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-rdp-session-to-a-remote-host)
* \[Low] [Rare SMB session to a remote host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-smb-session-to-a-remote-host)
* \[Low] [Rare SSH Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ssh-session)
* \[Low] [Rare Unsigned Process Spawned by Office Process Under Suspicious Directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-spawned-by-office-process-under-suspicious-directory)
* \[Low] [Rare Windows Remote Management (WinRM) HTTP Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-windows-remote-management-winrm-http-activity)
* \[Low] [Rare binary connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-binary-connected-to-a-rare-cloud-resource)
* \[Low] [Rare binary connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-binary-connected-to-a-rare-external-host)
* \[Low] [Rare communication over email ports to external email server by unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-communication-over-email-ports-to-external-email-server-by-unsigned-process)
* \[Low] [Rare file transfer over SMB protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-file-transfer-over-smb-protocol)
* \[Low] [Rare process created an SSH session to an uncommon cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-cloud-resource)
* \[Low] [Rare process created an SSH session to an uncommon external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-created-an-ssh-session-to-an-uncommon-external-host)
* \[Low] [Rare process executed by an AppleScript](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-executed-by-an-applescript)
* \[Low] [Rare process with VNC server capabilities started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-with-vnc-server-capabilities-started)
* \[Low] [Rare security product signed executable executed in the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-security-product-signed-executable-executed-in-the-network)
* \[Low] [Rare service DLL was added to the registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-service-dll-was-added-to-the-registry)
* \[Low] [Rare unsigned process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unsigned-process-execution-by-scheduled-task)
* \[Low] [Reading bash command history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/reading-bash-command-history-file)
* \[Low] [Recurring access to rare IP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-ip)
* \[Low] [Recurring access to rare domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-access-to-rare-domain)
* \[Low] [Recurring rare domain access from an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-from-an-unsigned-process)
* \[Low] [Recurring rare domain access to dynamic DNS domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/recurring-rare-domain-access-to-dynamic-dns-domain)
* \[Low] [Remote DCOM command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-dcom-command-execution)
* \[Low] [Remote command execution via wmic.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-command-execution-via-wmic-exe)
* \[Low] [Remote service start from an uncommon source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-service-start-from-an-uncommon-source)
* \[Low] [Rundll32.exe executes a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-executes-a-rare-unsigned-module)
* \[Informational] [SCCM log files enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sccm-log-files-enumeration)
  * \[Low] Suspicious SCCM log files enumeration - Modified Logic
* \[Low] [SMB Traffic from Non-Standard Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/smb-traffic-from-non-standard-process)
* \[Low] [SPNs cleared from a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/spns-cleared-from-a-machine-account)
* \[Low] [SSO authentication attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-attempt-by-a-honey-user)
* \[Low] [SSO authentication by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-machine-account)
* \[Low] [SSO authentication by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-authentication-by-a-service-account)
* \[Low] [SUID/GUID permission discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suid-guid-permission-discovery)
* \[Low] [Scheduled Task hidden by registry modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scheduled-task-hidden-by-registry-modification)
* \[Low] [Screensaver process executed from Users or temporary folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/screensaver-process-executed-from-users-or-temporary-folder)
* \[Low] [Scripting engine connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scripting-engine-connected-to-a-rare-external-host)
* \[Low] [SecureBoot was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/secureboot-was-disabled)
* \[Low] [Sending unusual file(s) to an external address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sending-unusual-file-s-to-an-external-address)
* \[Low] [Setuid and Setgid file bit manipulation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/setuid-and-setgid-file-bit-manipulation)
* \[Low] [Short-lived user account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/short-lived-user-account)
* \[Informational] [Signed process performed an unpopular injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-injection)
  * \[Low] Signed process executed by a scheduled task performed an unpopular injection - Added
* \[Low] [Spam Bot Traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/spam-bot-traffic)
* \[Low] [Stored credentials exported using credwiz.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/stored-credentials-exported-using-credwiz-exe)
* \[Low] [Subdomain Fuzzing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/subdomain-fuzzing)
* \[Low] [Suspicious Certutil AD CS contact](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certutil-ad-cs-contact)
* \[Low] [Suspicious DotNet log file created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dotnet-log-file-created)
* \[Low] [Suspicious ICMP packet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-icmp-packet)
* \[Low] [Suspicious ICMP traffic that resembles smurf attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-icmp-traffic-that-resembles-smurf-attack)
* \[Low] [Suspicious Kerberos Pre-Auth Failures by Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-kerberos-pre-auth-failures-by-host)
* \[Low] [Suspicious LDAP search query executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ldap-search-query-executed)
* \[Low] [Suspicious PowerShell Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-command-line)
* \[Low] [Suspicious PowerShell Enumeration of Running Processes](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-powershell-enumeration-of-running-processes)
* \[Low] [Suspicious Print System Remote Protocol usage by a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-print-system-remote-protocol-usage-by-a-process)
* \[Low] [Suspicious Process Spawned by Adobe Reader](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawned-by-adobe-reader)
* \[Low] [Suspicious RunOnce Parent Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-runonce-parent-process)
* \[Low] [Suspicious SMB connection from domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-smb-connection-from-domain-controller)
* \[Low] [Suspicious SSH Downgrade](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ssh-downgrade)
* \[Low] [Suspicious Udev driver rule execution manipulation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-udev-driver-rule-execution-manipulation)
* \[Low] [Suspicious access of the System Management Container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-of-the-system-management-container)
* \[Low] [Suspicious account attribute modification that matches that of another account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-account-attribute-modification-that-matches-that-of-another-account)
* \[Low] [Suspicious container orchestration job](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-orchestration-job)
* \[Low] [Suspicious data encryption](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-data-encryption)
* \[Low] [Suspicious disablement of the Windows Firewall](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-disablement-of-the-windows-firewall)
* \[Low] [Suspicious failed HTTP request - potential Spring4Shell exploit](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-failed-http-request-potential-spring4shell-exploit)
* \[Low] [Suspicious modification of the AdminSDHolder's ACL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-modification-of-the-adminsdholder-s-acl)
* \[Low] [Suspicious module load using direct syscall](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-module-load-using-direct-syscall)
* \[Low] [Suspicious process accessed certificate files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-accessed-certificate-files)
* \[Low] [Suspicious process modified RC script file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-modified-rc-script-file)
* \[Low] [Suspicious runonce.exe parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-runonce-exe-parent-process)
* \[Low] [Suspicious sAMAccountName change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-samaccountname-change)
* \[Low] [Suspicious setspn.exe execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-setspn-exe-execution)
* \[Low] [Suspicious sshpass command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sshpass-command-execution)
* \[Low] [Suspicious systemd timer activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-systemd-timer-activity)
* \[Low] [Svchost.exe loads a rare unsigned module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/svchost-exe-loads-a-rare-unsigned-module)
* \[Low] [System information discovery via psinfo.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-information-discovery-via-psinfo-exe)
* \[Low] [The Linux system firewall was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/the-linux-system-firewall-was-disabled)
* \[Low] [Uncommon ARP cache listing via arp.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-arp-cache-listing-via-arp-exe)
* \[Low] [Uncommon AT task-job creation by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-at-task-job-creation-by-user)
* \[Low] [Uncommon IP Configuration Listing via ipconfig.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ip-configuration-listing-via-ipconfig-exe)
* \[Low] [Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ntwritevirtualmemoryremote-api-invocation-with-a-pe-header-buffer)
* \[Low] [Uncommon PowerShell commands used to create or alter scheduled task parameters](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-powershell-commands-used-to-create-or-alter-scheduled-task-parameters)
* \[Low] [Uncommon SSH session was established](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-ssh-session-was-established)
* \[Low] [Uncommon Security Support Provider (SSP) registered via a registry key](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-security-support-provider-ssp-registered-via-a-registry-key)
* \[Low] [Uncommon VNC server communication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-vnc-server-communication)
* \[Low] [Uncommon access to Microsoft Teams credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-microsoft-teams-credential-files)
* \[Low] [Uncommon attempt to clear shell history](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-to-clear-shell-history)
* \[Low] [Uncommon creation or access operation of sensitive shadow copy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-creation-or-access-operation-of-sensitive-shadow-copy)
* \[Low] [Uncommon driver loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-driver-loaded)
* \[Low] [Uncommon execution of ODBCConf](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-execution-of-odbcconf)
* \[Low] [Uncommon file access over WebDAV](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-file-access-over-webdav)
* \[Low] [Uncommon local scheduled task creation via schtasks.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-local-scheduled-task-creation-via-schtasks-exe)
* \[Low] [Uncommon msiexec execution of an arbitrary file from a remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-msiexec-execution-of-an-arbitrary-file-from-a-remote-location)
* \[Low] [Uncommon remote monitoring and management tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-monitoring-and-management-tool)
* \[Low] [Uncommon remote scheduled task creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-scheduled-task-creation)
* \[Low] [Uncommon remote service start via sc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-remote-service-start-via-sc-exe)
* \[Low] [Uncommon reverse SSH tunnel to external domain/ip](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-reverse-ssh-tunnel-to-external-domain-ip)
* \[Low] [Uncommon routing table listing via route.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-routing-table-listing-via-route-exe)
* \[Low] [Uncommon sensitive registry hive dump](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-registry-hive-dump)
* \[Low] [Unprivileged process opened a registry hive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unprivileged-process-opened-a-registry-hive)
* \[Informational] [Unsigned DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-hijack-into-a-microsoft-process)
  * \[Low] Unsigned DLL Hijack into a Microsoft process which was executed by a scheduled task - Added
* \[Informational] [Unsigned DLL Side-Loading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-dll-side-loading)
  * \[Low] Unsigned DLL Side-Loading which was executed by a scheduled task - Added
* \[Low] [Unsigned and unpopular process performed a DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-a-dll-injection)
* \[Low] [Unsigned and unpopular process performed an injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-and-unpopular-process-performed-an-injection)
  * \[Low] Unsigned and unpopular process executed by a scheduled task performed an injection - Added
* \[Low] [Unsigned process creates a scheduled task via file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-creates-a-scheduled-task-via-file-access)
* \[Low] [Unusual AWS credentials creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-credentials-creation)
* \[Low] [Unusual AWS user added to group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-aws-user-added-to-group)
* \[Low] [Unusual Azure AD sync module load](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-azure-ad-sync-module-load)
* \[Low] [Unusual CIM repository file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cim-repository-file-access)
* \[Low] [Unusual CertLog Remote File Write](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-certlog-remote-file-write)
* \[Low] [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-encrypting-file-system-remote-call-efsrpc-to-domain-controller)
* \[Low] [Unusual Kubernetes dashboard communication from a pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-dashboard-communication-from-a-pod)
* \[Low] [Unusual Lolbins Process Spawned by InstallUtil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-lolbins-process-spawned-by-installutil-exe)
* \[Low] [Unusual Netsh PortProxy rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-netsh-portproxy-rule)
* \[Low] [Unusual Process Spawned by Nginx in Ingress-Nginx pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-spawned-by-nginx-in-ingress-nginx-pod)
* \[Low] [Unusual compressed file password protection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-compressed-file-password-protection)
* \[Low] [Unusual process accessed FTP Client credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-ftp-client-credentials)
* \[Low] [Unusual process accessed a crypto wallet's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-crypto-wallet-s-files)
* \[Low] [Unusual process accessed a messaging app's files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-messaging-app-s-files)
* \[Low] [Unusual process accessed a web browser history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-web-browser-history-file)
* \[Low] [User added to the SMS Admins local group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-to-the-sms-admins-local-group)
* \[Low] [User collected remote shared files in an archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-collected-remote-shared-files-in-an-archive)
* \[Low] [User set insecure CA registry setting for global SANs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-set-insecure-ca-registry-setting-for-global-sans)
* \[Low] [VPN login attempt by a honey user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-attempt-by-a-honey-user)
* \[Low] [VPN login by a service account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-by-a-service-account)
* \[Low] [Weakly-Encrypted Kerberos Ticket Requested](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-ticket-requested)
* \[Low] [Windows Event Log was cleared using wevtutil.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-log-was-cleared-using-wevtutil-exe)
* \[Low] [WmiPrvSe.exe Rare Child Command Line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wmiprvse-exe-rare-child-command-line)
* \[Low] [Wscript/Cscript loads .NET DLLs](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wscript-cscript-loads-net-dlls)
* \[Low] [Wsmprovhost.exe Rare Child Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wsmprovhost-exe-rare-child-process)
* \[Informational] [A LOLBIN was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-lolbin-was-copied-to-a-different-location)
* \[Informational] [A Torrent client was detected on a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-torrent-client-was-detected-on-a-host)
* \[Informational] [A WMI subscriber was created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-wmi-subscriber-was-created)
* \[Informational] [A browser extension was installed or loaded in an uncommon way](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-browser-extension-was-installed-or-loaded-in-an-uncommon-way)
* \[Informational] [A browser was opened in private mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-browser-was-opened-in-private-mode)
* \[Informational] [A compressed file was exfiltrated over SSH](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-compressed-file-was-exfiltrated-over-ssh)
* \[Informational] [A disabled user attempted to authenticate via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-authenticate-via-sso)
* \[Informational] [A disabled user attempted to log in](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-disabled-user-attempted-to-log-in)
* \[Informational] [A non-browser process accessed a website UI](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-non-browser-process-accessed-a-website-ui)
* \[Informational] [A possible risky login to Azure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-possible-risky-login-to-azure)
* \[Informational] [A process connected to a rare cloud resource](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-cloud-resource)
* \[Informational] [A process connected to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-a-rare-external-host)
* \[Informational] [A process connected to rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-connected-to-rare-external-host)
* \[Informational] [A process is masquerading as a common Microsoft product](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-is-masquerading-as-a-common-microsoft-product)
* \[Informational] [A process modified an SSH authorized\_keys file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-process-modified-an-ssh-authorized-keys-file)
* \[Informational] [A rare local administrator login](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-rare-local-administrator-login)
* \[Informational] [A service was disabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-service-was-disabled)
* \[Informational] [A suspicious process queried AD CS objects via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-suspicious-process-queried-ad-cs-objects-via-ldap)
* \[Informational] [A third-party utility was copied to a different location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-third-party-utility-was-copied-to-a-different-location)
* \[Informational] [A user accessed an abnormal number of files on a remote shared folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-files-on-a-remote-shared-folder)
* \[Informational] [A user accessed an abnormal number of remote shared folders](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-abnormal-number-of-remote-shared-folders)
* \[Informational] [A user accessed an uncommon AppID](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-an-uncommon-appid)
* \[Informational] [A user accessed multiple time-consuming websites](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-time-consuming-websites)
* \[Informational] [A user accessed multiple unusual resources via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-accessed-multiple-unusual-resources-via-sso)
* \[Informational] [A user account was modified to password never expires](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-account-was-modified-to-password-never-expires)
* \[Informational] [A user added a Windows firewall rule](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-added-a-windows-firewall-rule)
* \[Informational] [A user authenticated with weak NTLM to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-authenticated-with-weak-ntlm-to-multiple-hosts)
* \[Informational] [A user certificate was issued with a mismatch](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-certificate-was-issued-with-a-mismatch)
* \[Informational] [A user changed the Windows system time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-changed-the-windows-system-time)
* \[Informational] [A user connected a USB storage device for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-usb-storage-device-for-the-first-time)
* \[Informational] [A user connected a new USB storage device to a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-a-new-usb-storage-device-to-a-host)
* \[Informational] [A user connected from a new country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-from-a-new-country)
* \[Informational] [A user connected to a VPN from a new country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-connected-to-a-vpn-from-a-new-country)
* \[Informational] [A user created a pfx file for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-created-a-pfx-file-for-the-first-time)
* \[Informational] [A user created an abnormal password-protected archive](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-created-an-abnormal-password-protected-archive)
* \[Informational] [A user enabled a default local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-enabled-a-default-local-account)
* \[Informational] [A user established an SMB connection to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-established-an-smb-connection-to-multiple-hosts)
* \[Informational] [A user executed multiple LDAP enumeration queries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-executed-multiple-ldap-enumeration-queries)
* \[Informational] [A user logged in at an unusual time via SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-sso)
* \[Informational] [A user logged in at an unusual time via VPN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-at-an-unusual-time-via-vpn)
* \[Informational] [A user logged in from an abnormal country or ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-from-an-abnormal-country-or-asn)
* \[Informational] [A user logged on to multiple workstations via Schannel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-on-to-multiple-workstations-via-schannel)
* \[Informational] [A user performed suspiciously massive file activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-performed-suspiciously-massive-file-activity)
* \[Informational] [A user printed an unusual number of files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-printed-an-unusual-number-of-files)
* \[Informational] [A user queried AD CS objects via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-queried-ad-cs-objects-via-ldap)
* \[Informational] [A user received multiple weakly encrypted service tickets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-received-multiple-weakly-encrypted-service-tickets)
* \[Informational] [A user requested multiple service tickets](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-requested-multiple-service-tickets)
* \[Informational] [A user took numerous screenshots](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-took-numerous-screenshots)
* \[Informational] [A user was added to a Windows security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-was-added-to-a-windows-security-group)
* \[Informational] [AWS EC2 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
  * \[Informational] AWS PrivateLink discovery operation - Added
  * \[Informational] AWS Site-to-Site VPN discovery operation - Added
  * \[Informational] AWS VPC discovery operation - Added
* \[Informational] [AWS EC2 infrastructure enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-ec2-infrastructure-enumeration-activity)
* \[Informational] [Abnormal Communication to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-communication-to-a-rare-domain)
* \[Informational] [Abnormal File Activity in SCCMContentLib Shared Folder by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-file-activity-in-sccmcontentlib-shared-folder-by-user)
* \[Informational] [Abnormal RDP connections to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-rdp-connections-to-multiple-hosts)
* \[Informational] [Abnormal Recurring Communications to a Rare Domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-recurring-communications-to-a-rare-domain)
* \[Informational] [Abnormal SMB scanning activity to multiple hosts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-smb-scanning-activity-to-multiple-hosts)
* \[Informational] [Abnormal User Login to Domain Controller](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-user-login-to-domain-controller)
* \[Informational] [Abnormal connections to a dormant host from a newly seen endpoint](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-connections-to-a-dormant-host-from-a-newly-seen-endpoint)
* \[Informational] [Abnormal network communication with a rare combination of HTTP User Agent and HTTP Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-network-communication-with-a-rare-combination-of-http-user-agent-and-http-server)
* \[Informational] [Abnormal process connection to default Meterpreter port](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/abnormal-process-connection-to-default-meterpreter-port)
* \[Informational] [Access to Kubernetes CA certificate file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubernetes-ca-certificate-file)
* \[Informational] [Access to Kubernetes configuration file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubernetes-configuration-file)
* \[Informational] [Access to kubelet credentials file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-kubelet-credentials-file)
* \[Informational] [Access to sensitive host files from within a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/access-to-sensitive-host-files-from-within-a-kubernetes-pod)
* \[Informational] [Adding execution privileges](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/adding-execution-privileges)
* \[Informational] [Administrator groups enumerated via LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/administrator-groups-enumerated-via-ldap)
* \[Informational] [An uncommon RDP session from a managed host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-rdp-session-from-a-managed-host)
* \[Informational] [An uncommon RDP session was established](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-rdp-session-was-established)
* \[Informational] [An uncommon file added to startup-related Registry keys](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-added-to-startup-related-registry-keys)
* \[Informational] [An uncommon file was created in the startup folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-uncommon-file-was-created-in-the-startup-folder)
* \[Informational] [An unusual archive file creation by a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-unusual-archive-file-creation-by-a-user)
* \[Informational] [AppleScript executed a shell script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-executed-a-shell-script)
* \[Informational] [AppleScript interpreter dynamic library loaded into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-interpreter-dynamic-library-loaded-into-a-process)
* \[Informational] [AppleScript process executed with a rare command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/applescript-process-executed-with-a-rare-command-line)
* \[Informational] [Authentication Attempt From a Dormant Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/authentication-attempt-from-a-dormant-account)
* \[Informational] [Browser Extension Installed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/browser-extension-installed)
* \[Informational] [Browser bookmark files accessed by a rare non-browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/browser-bookmark-files-accessed-by-a-rare-non-browser-process)
* \[Informational] [Brute-force attempt on a local account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/brute-force-attempt-on-a-local-account)
* \[Informational] [Command execution in a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-in-a-kubernetes-pod)
* \[Informational] [Command execution via wmiexec](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/command-execution-via-wmiexec)
* \[Informational] [Common third-party software name masquerading](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-third-party-software-name-masquerading)
* \[Informational] [Commonly abused AutoIT script drops an executable file to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-autoit-script-drops-an-executable-file-to-disk)
* \[Informational] [Commonly abused process launched as a system service](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-process-launched-as-a-system-service)
* \[Informational] [Creation or modification of the default command executed when opening an application](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/creation-or-modification-of-the-default-command-executed-when-opening-an-application)
* \[Informational] [DSC (Desired State Configuration) lateral movement using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dsc-desired-state-configuration-lateral-movement-using-powershell)
* \[Informational] [Deletion of AD CS certificate database entries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/deletion-of-ad-cs-certificate-database-entries)
* \[Informational] [Discovery of host users via WMIC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/discovery-of-host-users-via-wmic)
* \[Informational] [Download pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/download-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Email attachment with a potentially malicious file extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-a-potentially-malicious-file-extension)
* \[Informational] [Email attachment with multiple extensions](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-with-multiple-extensions)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-attachment-s-with-potentially-malicious-mime-type)
* \[Informational] [Email containing a link with an IP address convention was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-link-with-an-ip-address-convention-was-detected)
* \[Informational] [Email containing a redirected link](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-containing-a-redirected-link)
* \[Informational] [Email contains URL delivering high-risk file type](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-contains-url-delivering-high-risk-file-type)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-values)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversation)
* \[Informational] [Email was received from an unknown address using a public provider domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-was-received-from-an-unknown-address-using-a-public-provider-domain)
* \[Informational] [Email with URL shortener detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/email-with-url-shortener-detected)
* \[Informational] [Executable moved to Windows system folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/executable-moved-to-windows-system-folder)
* \[Informational] [Execution of an uncommon process at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-at-an-early-startup-stage)
* \[Informational] [Execution of an uncommon process with a local/domain user SID at an early startup stage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage)
* \[Informational] [Execution of masqueraded third-party utility](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-masqueraded-third-party-utility)
* \[Informational] [Execution of renamed lolbin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-renamed-lolbin)
* \[Informational] [External Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-login-password-spray)
* \[Informational] [External email display name impersonation of internal personnel](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-display-name-impersonation-of-internal-personnel)
* \[Informational] [External email with a single internal recipient hidden in BCC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/external-email-with-a-single-internal-recipient-hidden-in-bcc)
* \[Informational] [Failed Login For Locked-Out Account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-login-for-locked-out-account)
* \[Informational] [Failed Login For a Long Username With Special Characters](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/failed-login-for-a-long-username-with-special-characters)
* \[Informational] [File transfer from unusual IP using known tools](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/file-transfer-from-unusual-ip-using-known-tools)
* \[Informational] [First SSO Resource Access in the Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-resource-access-in-the-organization)
* \[Informational] [First SSO access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-for-user)
* \[Informational] [First SSO access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-sso-access-from-asn-in-organization)
* \[Informational] [First VPN access attempt from a country in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-attempt-from-a-country-in-organization)
* \[Informational] [First VPN access from ASN for user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-for-user)
* \[Informational] [First VPN access from ASN in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-vpn-access-from-asn-in-organization)
* \[Informational] [First connection from a country in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-connection-from-a-country-in-organization)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/first-seen-email-from-mailbox-owner-to-external-recipient-s-address-in-the-last-30-days)
  * \[Informational] First-time email from mailbox owner to a single external recipient in the last 30 days - Removed
* \[Informational] [Globally uncommon IP address by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-by-a-common-process-sha256)
* \[Informational] [Globally uncommon IP address connection from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-ip-address-connection-from-a-signed-process)
* \[Informational] [Globally uncommon high entropy process was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-high-entropy-process-was-executed)
* \[Informational] [Globally uncommon process execution from a signed process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-process-execution-from-a-signed-process)
* \[Informational] [Globally uncommon root-domain port combination by a common process (sha256)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/globally-uncommon-root-domain-port-combination-by-a-common-process-sha256)
* \[Informational] [Hidden Attribute was added to a file using attrib.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hidden-attribute-was-added-to-a-file-using-attrib-exe)
* \[Informational] [IP Rotation Pattern in SSO Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ip-rotation-pattern-in-sso-spray)
* \[Informational] [Increase in Job-Related Site Visits](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/increase-in-job-related-site-visits)
* \[Informational] [Indicator blocking](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/indicator-blocking)
* \[Informational] [Intense SSO failures](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/intense-sso-failures)
* \[Informational] [Interactive login by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-by-a-machine-account)
* \[Informational] [Interactive login from a shared user account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/interactive-login-from-a-shared-user-account)
* \[Informational] [Internal Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/internal-login-password-spray)
* \[Informational] [Iptables configuration command was executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iptables-configuration-command-was-executed)
* \[Informational] [Kerberos Pre-Auth Failures by User and Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-pre-auth-failures-by-user-and-host)
* \[Informational] [Key credential attribute modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/key-credential-attribute-modification)
* \[Informational] [Kubernetes API server communication from within a pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-api-server-communication-from-within-a-pod)
* \[Informational] [Kubernetes environment enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-environment-enumeration-activity)
* \[Informational] [Kubernetes nsenter container escape](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-nsenter-container-escape)
* \[Informational] [Kubernetes secret enumeration activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-secret-enumeration-activity)
* \[Informational] [Kubernetes version disclosure](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kubernetes-version-disclosure)
* \[Informational] [LDAP traffic from non-standard process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ldap-traffic-from-non-standard-process)
* \[Informational] [LOLBAS executable injects into another process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbas-executable-injects-into-another-process)
* \[Informational] [LOLBIN created a PSScriptPolicyTest PowerShell script file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/lolbin-created-a-psscriptpolicytest-powershell-script-file)
* \[Informational] [Linux local user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-local-user-account-creation)
* \[Informational] [Linux network share discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-network-share-discovery)
* \[Informational] [Linux process execution with a rare GitHub URL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/linux-process-execution-with-a-rare-github-url)
* \[Informational] [Local account discovery](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-account-discovery)
* \[Informational] [Local group enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration)
* \[Informational] [Local group enumeration via RPC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-group-enumeration-via-rpc)
* \[Informational] [Local user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-account-creation)
* \[Informational] [Local user account creation by a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-account-creation-by-a-machine-account)
* \[Informational] [Local user enumeration via SAMR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/local-user-enumeration-via-samr)
* \[Informational] [Login by a dormant user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/login-by-a-dormant-user)
* \[Informational] [MSI accessed a web page running a server-side script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msi-accessed-a-web-page-running-a-server-side-script)
* \[Informational] [Massive file activity abnormal to process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-activity-abnormal-to-process)
* \[Informational] [Massive file compression by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-file-compression-by-user)
* \[Informational] [Massive upload to a rare storage or mail domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/massive-upload-to-a-rare-storage-or-mail-domain)
* \[Informational] [Member added to a Windows local security group](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/member-added-to-a-windows-local-security-group)
* \[Informational] [Microsoft Configuration Manager device registration and policy request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-configuration-manager-device-registration-and-policy-request)
* \[Informational] [Modification of PAM](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-pam)
* \[Informational] [Moniker link detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/moniker-link-detected-in-url-s)
* \[Informational] [Msiexec execution of an executable from an uncommon remote location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msiexec-execution-of-an-executable-from-an-uncommon-remote-location)
* \[Informational] [Multiple Okta MFA requests sent to a user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-okta-mfa-requests-sent-to-a-user)
* \[Informational] [Multiple Rare Process Executions in Organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-rare-process-executions-in-organization)
* \[Informational] [Multiple TGT requests for users without Kerberos pre-authentication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-tgt-requests-for-users-without-kerberos-pre-authentication)
* \[Informational] [Multiple discovery commands on a Linux host by the same process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-commands-on-a-linux-host-by-the-same-process)
* \[Informational] [Multiple discovery-like commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-discovery-like-commands)
* \[Informational] [Multiple user accounts were deleted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-user-accounts-were-deleted)
* \[Informational] [Multiple users authenticated with weak NTLM to a host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-users-authenticated-with-weak-ntlm-to-a-host)
* \[Informational] [NTLM Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-brute-force)
* \[Informational] [NTLM Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-password-spray)
* \[Informational] [NTLM Relay](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ntlm-relay)
* \[Informational] [Near-empty email from an external sender](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/near-empty-email-from-an-external-sender)
* \[Informational] [New process created via a WMI call](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipients)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-contains-file-sharing-service-link-sent-to-external-recipient)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-time)
* \[Informational] [Outbound email to an address hosted by a public email service provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/outbound-email-to-an-address-hosted-by-a-public-email-service-provider)
* \[Informational] [PKINIT TGT authentication request](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/pkinit-tgt-authentication-request)
* \[Informational] [Permission Groups discovery commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/permission-groups-discovery-commands)
* \[Informational] [Ping to localhost from an uncommon, unsigned parent process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ping-to-localhost-from-an-uncommon-unsigned-parent-process)
* \[Informational] [Port Scan](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/port-scan)
* \[Informational] [Possible Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-attempt)
* \[Informational] [Possible DLL Hijack into a Microsoft process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-dll-hijack-into-a-microsoft-process)
* \[Informational] [Possible Email collection using Outlook RPC](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-email-collection-using-outlook-rpc)
* \[Informational] [Possible GPO Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-gpo-enumeration)
* \[Informational] [Possible IPFS traffic was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ipfs-traffic-was-detected)
* \[Informational] [Possible Impossible Travel Pattern - SSO](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-impossible-travel-pattern-sso)
* \[Informational] [Possible Kerberos User Enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-kerberos-user-enumeration)
* \[Informational] [Possible LDAP Enumeration Tool Usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-tool-usage)
* \[Informational] [Possible LDAP Enumeration of Microsoft Configuration Manager](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-of-microsoft-configuration-manager)
* \[Informational] [Possible LDAP enumeration by unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-ldap-enumeration-by-unsigned-process)
* \[Informational] [Possible Privilege Escalation using Delegated MSA account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-privilege-escalation-using-delegated-msa-account)
* \[Informational] [Possible SPN enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-spn-enumeration)
* \[Informational] [Possible TGT reuse from different hosts (pass the ticket)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-tgt-reuse-from-different-hosts-pass-the-ticket)
* \[Informational] [Possible authentication coercion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-authentication-coercion)
* \[Informational] [Possible binary padding using dd](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-binary-padding-using-dd)
* \[Informational] [Possible brute force on sudo user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-brute-force-on-sudo-user)
* \[Informational] [Possible data exfiltration over a USB storage device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-data-exfiltration-over-a-usb-storage-device)
* \[Informational] [Possible data obfuscation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-data-obfuscation)
* \[Informational] [Possible internal data exfiltration over a USB storage device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-internal-data-exfiltration-over-a-usb-storage-device)
* \[Informational] [Possible use of IPFS was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-use-of-ipfs-was-detected)
* \[Informational] [Possible use of a networking driver for network sniffing](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-use-of-a-networking-driver-for-network-sniffing)
* \[Informational] [Potential DCSync by an unusual user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-dcsync-by-an-unusual-user)
* \[Informational] [Potential NTLM Relay Attack](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-ntlm-relay-attack)
* \[Informational] [Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-ntlm-relay-attack-against-a-microsoft-configuration-manager-site-server)
* \[Informational] [Potential spoofing of internal domain spotted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-spoofing-of-internal-domain-spotted)
* \[Informational] [PowerShell pfx certificate extraction](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-pfx-certificate-extraction)
* \[Informational] [Privileged certificate request via certificate template](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/privileged-certificate-request-via-certificate-template)
* \[Informational] [PsExec was executed with a suspicious command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/psexec-was-executed-with-a-suspicious-command-line)
* \[Informational] [Punycode characters detected in URL(s)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/punycode-characters-detected-in-url-s)
* \[Informational] [Python HTTP server started](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/python-http-server-started)
* \[Informational] [RDP from an unmanaged endpoint in a typically managed subnet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rdp-from-an-unmanaged-endpoint-in-a-typically-managed-subnet)
* \[Informational] [Rare AppID usage to a rare destination](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-appid-usage-to-a-rare-destination)
* \[Informational] [Rare DCOM RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-dcom-rpc-activity)
* \[Informational] [Rare LOLBIN Process Execution by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-lolbin-process-execution-by-user)
* \[Informational] [Rare MS-Update Server was detected](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-server-was-detected)
* \[Informational] [Rare MS-Update traffic over HTTP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ms-update-traffic-over-http)
* \[Informational] [Rare NTLM Access By User To Host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-access-by-user-to-host)
* \[Informational] [Rare NTLM Usage by User](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-ntlm-usage-by-user)
* \[Informational] [Rare Remote Service (SVCCTL) RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-remote-service-svcctl-rpc-activity)
* \[Informational] [Rare SMTP/S Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-smtp-s-session)
* \[Informational] [Rare Scheduled Task RPC activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-rpc-activity)
* \[Informational] [Rare Unix process divided files by size](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-unix-process-divided-files-by-size)
* \[Informational] [Rare WinRM Session](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-winrm-session)
* \[Informational] [Rare access to known advertising domains](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-access-to-known-advertising-domains)
* \[Informational] [Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-connection-to-external-ip-address-or-host-by-an-application-using-rmi-iiop-or-ldap-protocol)
* \[Informational] [Rare machine account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-machine-account-creation)
* \[Informational] [Rare process accessed a Keychain file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-accessed-a-keychain-file)
* \[Informational] [Rare process execution by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-execution-by-user)
* \[Informational] [Rare process execution in organization](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-execution-in-organization)
* \[Informational] [Rare process spawned by srvany.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-process-spawned-by-srvany-exe)
* \[Informational] [Rare scheduled task created](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-scheduled-task-created)
* \[Informational] [Rare signature signed executable executed in the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rare-signature-signed-executable-executed-in-the-network)
* \[Informational] [Rarely seen URL(s) within a well-known domain detected in your organization's email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-email)
* \[Informational] [Registration of Uncommon .NET Services and/or Assemblies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/registration-of-uncommon-net-services-and-or-assemblies)
* \[Informational] [Remote PsExec-like command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-psexec-like-command-execution)
* \[Informational] [Remote account enumeration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-account-enumeration)
* \[Informational] [Remote code execution into Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/remote-code-execution-into-kubernetes-pod)
* \[Informational] [Retrieval of kubelet credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/retrieval-of-kubelet-credentials)
* \[Informational] [Run downloaded script using pipe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/run-downloaded-script-using-pipe)
* \[Informational] [SSH authentication brute force attempts](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ssh-authentication-brute-force-attempts)
* \[Informational] [SSO Brute Force](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-brute-force)
* \[Informational] [SSO with abnormal operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-operating-system)
* \[Informational] [SSO with abnormal user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-abnormal-user-agent)
* \[Informational] [SSO with new operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sso-with-new-operating-system)
* \[Informational] [Scrcons.exe Rare Child Process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scrcons-exe-rare-child-process)
* \[Informational] [Security tools detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/security-tools-detection-attempt)
* \[Informational] [Sensitive account password reset attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-account-password-reset-attempt)
* \[Informational] [Sensitive browser credential files accessed by a rare non browser process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-process)
* \[Informational] [Service execution via sc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/service-execution-via-sc-exe)
* \[Informational] [Signed process performed an unpopular DLL injection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/signed-process-performed-an-unpopular-dll-injection)
* \[Informational] [Single account excessively locked out](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/single-account-excessively-locked-out)
* \[Informational] [Space after filename](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/space-after-filename)
* \[Informational] [Sudden spike in outbound email volume](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/sudden-spike-in-outbound-email-volume)
* \[Informational] [Suspicious AMSI decode attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-amsi-decode-attempt)
* \[Informational] [Suspicious Azure AD interactive sign-in using PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-azure-ad-interactive-sign-in-using-powershell)
* \[Informational] [Suspicious DKIM Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dkim-result)
* \[Informational] [Suspicious DMARC result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dmarc-result)
* \[Informational] [Suspicious DNS traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dns-traffic)
* \[Informational] [Suspicious External RDP Login](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-external-rdp-login)
* \[Informational] [Suspicious NTLM authentication with machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-ntlm-authentication-with-machine-account)
* \[Informational] [Suspicious SPF Result](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-spf-result)
* \[Informational] [Suspicious SSO access from ASN](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-access-from-asn)
* \[Informational] [Suspicious SSO authentication](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-sso-authentication)
* \[Informational] [Suspicious Unicode character detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-unicode-character-detected-in-email)
* \[Informational] [Suspicious access to cloud credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-cloud-credential-files)
* \[Informational] [Suspicious access to shadow file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-access-to-shadow-file)
* \[Informational] [Suspicious active setup registered](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-active-setup-registered)
* \[Informational] [Suspicious certificate template modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-certificate-template-modification)
* \[Informational] [Suspicious container reconnaissance activity in a Kubernetes pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-reconnaissance-activity-in-a-kubernetes-pod)
* \[Informational] [Suspicious container runtime connection from within a Kubernetes Pod](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-container-runtime-connection-from-within-a-kubernetes-pod)
* \[Informational] [Suspicious curl user agent](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-curl-user-agent)
* \[Informational] [Suspicious docker image download from an unusual repository](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-docker-image-download-from-an-unusual-repository)
* \[Informational] [Suspicious domain user account creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-domain-user-account-creation)
* \[Informational] [Suspicious process accessed a site masquerading as Google](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-accessed-a-site-masquerading-as-google)
* \[Informational] [Suspicious process executed with a high integrity level](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-executed-with-a-high-integrity-level)
* \[Informational] [Suspicious process execution from tmp folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-execution-from-tmp-folder)
* \[Informational] [Suspicious process execution in a privileged container](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-execution-in-a-privileged-container)
* \[Informational] [Suspicious process loads a known PowerShell module](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-loads-a-known-powershell-module)
* \[Informational] [Suspicious proxy environment variable setting](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-proxy-environment-variable-setting)
* \[Informational] [Suspicious reconnaissance using LDAP](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-reconnaissance-using-ldap)
* \[Informational] [Suspicious successful RDP connection to localhost](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-successful-rdp-connection-to-localhost)
* \[Informational] [Suspicious usage of Microsoft's Active Directory PowerShell module remote discovery cmdlet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-microsoft-s-active-directory-powershell-module-remote-discovery-cmdlet)
* \[Informational] [System profiling WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-profiling-wmi-query-execution)
* \[Informational] [System shutdown or reboot](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/system-shutdown-or-reboot)
* \[Informational] [Tampering with Internet Explorer Protected Mode configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-internet-explorer-protected-mode-configuration)
* \[Informational] [Tampering with the Windows User Account Controls (UAC) configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-the-windows-user-account-controls-uac-configuration)
* \[Informational] [Uncommon DotNet module load relationship](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-dotnet-module-load-relationship)
* \[Informational] [Uncommon GetClipboardData API function invocation of a possible information stealer](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-getclipboarddata-api-function-invocation-of-a-possible-information-stealer)
* \[Informational] [Uncommon Launch Agent persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-agent-persistency-was-registered-or-modified)
* \[Informational] [Uncommon Launch Daemon persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-launch-daemon-persistency-was-registered-or-modified)
* \[Informational] [Uncommon Linux process communication to a rare external host](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-process-communication-to-a-rare-external-host)
* \[Informational] [Uncommon Linux remote shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-remote-shell-command-execution)
* \[Informational] [Uncommon Linux shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-linux-shell-command-execution)
* \[Informational] [Uncommon Managed Object Format (MOF) compiler usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-managed-object-format-mof-compiler-usage)
* \[Informational] [Uncommon RDP connection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-rdp-connection)
* \[Informational] [Uncommon SQL like command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sql-like-command-line)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-url-domain-s-in-your-organization-detected-in-email)
* \[Informational] [Uncommon WPAD queries](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-wpad-queries)
* \[Informational] [Uncommon access to /etc/passwd](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-etc-passwd)
* \[Informational] [Uncommon access to cloud platforms' sensitive files by a scripting engine](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-access-to-cloud-platforms-sensitive-files-by-a-scripting-engine)
* \[Informational] [Uncommon attempt at discovering a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-discovering-a-sensitive-file)
* \[Informational] [Uncommon attempt at grabbing credentials from a sensitive file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-attempt-at-grabbing-credentials-from-a-sensitive-file)
* \[Informational] [Uncommon browser extension loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-browser-extension-loaded)
* \[Informational] [Uncommon cloud CLI tool usage](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-cloud-cli-tool-usage)
* \[Informational] [Uncommon communication to an instant messaging server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-communication-to-an-instant-messaging-server)
* \[Informational] [Uncommon kernel module load](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-kernel-module-load)
* \[Informational] [Uncommon login item persistency was registered or modified](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-login-item-persistency-was-registered-or-modified)
* \[Informational] [Uncommon macOS shell command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-macos-shell-command-execution)
* \[Informational] [Uncommon net group command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-group-command-execution)
* \[Informational] [Uncommon net localgroup command execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-command-execution)
* \[Informational] [Uncommon net localgroup execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-net-localgroup-execution)
* \[Informational] [Uncommon network tunnel creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-network-tunnel-creation)
* \[Informational] [Uncommon recurring rare external host access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-recurring-rare-external-host-access)
* \[Informational] [Uncommon sensitive filesystem registry hive access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-sensitive-filesystem-registry-hive-access)
* \[Informational] [Uncommon service stop operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-service-stop-operation)
* \[Informational] [Uncommon signed process execution by scheduled task](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-signed-process-execution-by-scheduled-task)
* \[Informational] [Uncommon user management via net.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-user-management-via-net-exe)
* \[Informational] [Unique client computer model was detected via MS-Update protocol](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unique-client-computer-model-was-detected-via-ms-update-protocol)
* \[Informational] [Unpopular domains detected in email URLs for a recipient](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-domains-detected-in-email-urls-for-a-recipient)
* \[Informational] [Unpopular rsync process execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unpopular-rsync-process-execution)
* \[Informational] [Unrecognized internal address (AAD mismatch)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unrecognized-internal-address-aad-mismatch)
* \[Informational] [Unrecognized sender address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unrecognized sender domain](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [Unusual ADConnect database file access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-adconnect-database-file-access)
* \[Informational] [Unusual DB process spawning a shell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-db-process-spawning-a-shell)
* \[Informational] [Unusual Kubernetes service account file read](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-kubernetes-service-account-file-read)
* \[Informational] [Unusual SSH Activity](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ssh-activity)
* \[Informational] [Unusual SSH activity that resembles SSH proxy](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-ssh-activity-that-resembles-ssh-proxy)
* \[Informational] [Unusual access to the AD Sync credential files](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-the-ad-sync-credential-files)
* \[Informational] [Unusual access to the Windows Internal Database on an ADFS server](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-access-to-the-windows-internal-database-on-an-adfs-server)
* \[Informational] [Unusual attachment volume in outbound emails](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-attachment-volume-in-outbound-emails)
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-cloud-instance-metadata-service-imds-access)
* \[Informational] [Unusual display name in From header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-display-name-in-from-header)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-hostname-for-the-sending-mail-server-in-the-email-headers)
* \[Informational] [Unusual internal access to network device management interface](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-internal-access-to-network-device-management-interface)
* \[Informational] [Unusual process accessed a macOS notes DB file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-a-macos-notes-db-file)
* \[Informational] [Unusual process accessed the PowerShell history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-the-powershell-history-file)
* \[Informational] [Unusual process accessed web browser cookies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-cookies)
* \[Informational] [Unusual process accessed web browser credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-process-accessed-web-browser-credentials)
* \[Informational] [Unusual use of a 'SysInternals' tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-use-of-a-sysinternals-tool)
* \[Informational] [Unusual user account enablement](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-account-enablement)
* \[Informational] [Unusual user account unlock](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-user-account-unlock)
* \[Informational] [Unusual weak authentication by user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unusual-weak-authentication-by-user)
* \[Informational] [Upload pattern that resembles Peer to Peer traffic](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/upload-pattern-that-resembles-peer-to-peer-traffic)
* \[Informational] [Usage of homograph characters detected in an email](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-attachment-s-name)
* \[Informational] [Usage of homograph characters detected in an email's from header](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-homograph-characters-detected-in-an-email-s-from-header)
* \[Informational] [User account delegation change](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-account-delegation-change)
* \[Informational] [User added SID History to an account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-sid-history-to-an-account)
* \[Informational] [User added to a group and removed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-added-to-a-group-and-removed)
* \[Informational] [User and Group Enumeration via SAMR](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-and-group-enumeration-via-samr)
* \[Informational] [User attempted to connect from a suspicious country](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-attempted-to-connect-from-a-suspicious-country)
* \[Informational] [User discovery via WMI query execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-discovery-via-wmi-query-execution)
* \[Informational] [User signed in to an application via Power Automate for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-signed-in-to-an-application-via-power-automate-for-the-first-time)
* \[Informational] [VM Detection attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vm-detection-attempt)
* \[Informational] [VM Detection attempt on Linux](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vm-detection-attempt-on-linux)
* \[Informational] [VPN Login Password Spray](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-password-spray)
* \[Informational] [VPN access with an abnormal operating system](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-access-with-an-abnormal-operating-system)
* \[Informational] [VPN login Brute-Force attempt](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-brute-force-attempt)
* \[Informational] [VPN login by a dormant user](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-by-a-dormant-user)
* \[Informational] [VPN login with a machine account](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vpn-login-with-a-machine-account)
* \[Informational] [Vulnerable certificate template loaded](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/vulnerable-certificate-template-loaded)
* \[Informational] [Weakly-Encrypted Kerberos TGT Response](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/weakly-encrypted-kerberos-tgt-response)
* \[Informational] [Web server CGO executed an uncommon process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/web-server-cgo-executed-an-uncommon-process)
* \[Informational] [WebDAV drive mounted from net.exe over HTTPS](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/webdav-drive-mounted-from-net-exe-over-https)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/well-known-brand-in-sender-headers-with-header-inconsistencies)
* \[Informational] [Windows CGO, actor and action processes with anomalous characteristics](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-cgo-actor-and-action-processes-with-anomalous-characteristics)
* \[Informational] [Windows event logs were cleared with PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-logs-were-cleared-with-powershell)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/x-forefront-antispam-report-has-flagged-this-email-as-a-potential-threat)

### Modified Metadata

* \[Informational] [A user logged in to the AWS console for the first time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/a-user-logged-in-to-the-aws-console-for-the-first-time)
* \[Informational] [AWS S3 discovery operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/)
* \[Informational] [AWS console login without MFA](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-console-login-without-mfa)
* \[Informational] [An identity initiated a download of multiple cloud objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/an-identity-initiated-a-download-of-multiple-cloud-objects)
* \[Informational] [Potential creation of persistent cloud credentials](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/potential-creation-of-persistent-cloud-credentials)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-03-04.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
