> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-26.md).

# 2026.08.26

### Release date: 06-September-2026

### Summary

#### Added

* **11 Detectors:** 1 Medium, 2 Low, 8 Informational
* **21 Variations:** 1 High, 7 Medium, 11 Low, 2 Informational

#### Removed

* **1 Detector:** 1 Informational

#### Modified Logic

* **180 Detectors:** 1 High, 3 Medium, 24 Low, 152 Informational
* **82 Variations:** 14 High, 39 Medium, 14 Low, 15 Informational

#### Modified Metadata

* **365 Detectors:** 8 High, 40 Medium, 82 Low, 235 Informational
* **45 Variations:** 7 High, 9 Medium, 27 Low, 2 Informational

### Added

* \[Medium] [JS runtime attempted to read Git authentication tokens](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/js-runtime-attempted-to-read-git-authentication-tokens)
  * \[High] Uncommon JS runtime attempted to read Git authentication tokens
* \[Low] [AWS Route53 DNS Resolver query logging configuration deletion](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/aws-route53-dns-resolver-query-logging-configuration-deletion)
  * \[Medium] Successful AWS Route53 DNS Resolver query logging configuration deletion by a non-admin identity
* \[Informational] [KMS key policy was changed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kms-key-policy-was-changed)
  * \[Medium] KMS key policy was modified to include a foreign principal
  * \[Medium] Unusual KMS key policy modification
  * \[Low] Failed attempt to change KMS key policy
* \[Informational] [Multiple alerts associated with a single RDP connection](broken://spaces/5O67gr80iLneA56jiuO2/pages/LDPyPdPLRjDYAv9tczaO)
  * \[Medium] Multiple elevated severity alerts associated with a single RDP connection
  * \[Low] Diverse alerts associated with a single RDP connection
  * \[Low] Multiple alerts associated with a single RDP connection - high risk-processes
  * \[Low] Pre-connection activity alongside abnormal RDP connection
* \[Informational] [Uncommon user management via net command](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-user-management-via-net-command)
  * \[Medium] Uncommon user management via net command by a renamed lolbin
  * \[Medium] Uncommon user management via net command by a web server process or CGO
  * \[Medium] Uncommon user management via net command by an untrusted CGO
  * \[Low] Uncommon user management via net command by a remote management tool (RMM)
  * \[Low] Uncommon user management via net command by an untrusted actor process
* \[Informational] [Mass deletion of versioned S3 objects](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/mass-deletion-of-versioned-s3-objects)
  * \[Low] Mass deletion of versioned S3 objects from a bucket containing sensitive data
  * \[Low] Mass deletion of versioned S3 objects from a production account
  * \[Informational] Mass deletion of versioned S3 objects deviating from the identity baseline
* \[Low] [Multiple alerts of different MITRE tactics were seen](broken://spaces/5O67gr80iLneA56jiuO2/pages/I6dy1YQgwqttnln177hY)
* \[Informational] [Multiple mail items were accessed in a short period of time](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/multiple-mail-items-were-accessed-in-a-short-period-of-time)
  * \[Low] Multiple mail items were accessed in a short period of time with anomalous properties
* \[Informational] [Single IP accessed mail items of multiple users](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/single-ip-accessed-mail-items-of-multiple-users)
  * \[Low] Single IP accessed mail items of multiple users with suspicious characteristics
* \[Informational] [User mail items accessed from multiple IPs in the same subnet](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-mail-items-accessed-from-multiple-ips-in-the-same-subnet)
  * \[Low] User mail items accessed from rotating IPs in same subnet with anomalous properties
* \[Informational] [Uncommon command was executed on a device](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-command-was-executed-on-a-device)
  * \[Informational] Uncommon sensitive command was executed on a device

### Removed

* \[Informational] Uncommon user management via net.exe

### Modified Logic

* \[High] [A successful SSO sign-in from TOR](broken://spaces/5O67gr80iLneA56jiuO2/pages/l6Iofv96gu23ZUXNOtjc)
* \[Informational] [AI-determined combination of risky alerts under the same causality](broken://spaces/5O67gr80iLneA56jiuO2/pages/p9Wcxpx0VpzVoohla0B9)
  * \[High] AI-determined combination of risky alerts under the same causality: AD enumeration with AV/FW products enumeration - Added
  * \[High] AI-determined combination of risky alerts under the same causality: AD enumeration with MSBuild execution - Added
  * \[High] AI-determined combination of risky alerts under the same causality: AD enumeration with shadow copy access - Added
  * \[High] AI-determined combination of risky alerts under the same causality: RAR archive creation with password protection and unsigned temp process - Added
  * \[High] AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, possible arp reconnaissance, unsigned process running from a temporary directory - Added
  * \[High] AI-determined combination of risky alerts under the same causality: boot config modification with shadow copy access - Added
  * \[High] AI-determined combination of risky alerts under the same causality: file permission changes with boot config modification and unsigned temp process - Added
  * \[High] AI-determined combination of risky alerts under the same causality: manipulation of mmc registry configuration, powershell possibly attempting to execute as administrator - Added
  * \[High] AI-determined combination of risky alerts under the same causality: mshta exe launched with suspicious arguments, unsigned process running from a temporary directory - Added
  * \[High] AI-determined combination of risky alerts under the same causality: new service created via command line, suspicious powershell command line, powershell calling invoke expression argument - Added
  * \[High] AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, suspicious powershell command line, powershell calling invoke expression argument - Added
  * \[High] AI-determined combination of risky alerts under the same causality: unsigned temp process with WMI shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: AD enumeration with PsExec remote execution and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: AD enumeration with Windows Defender manipulation - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: AD enumeration with new service creation and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: BootExecute manipulation with shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: Defender manipulation with new service creation and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: Defender manipulation with shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: MSBuild execution with boot config modification and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: PowerShell download with shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: PowerShell download with suspicious command line and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: a scripting engine was called to run in command line, suspicious powershell command line - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: changing permissions or ownership of a file or folder, bitsadmin exe used to download data - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: commonly abused process executed with obfuscated characters, unsigned process running from a temporary directory, manipulation of Windows defender configuration - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: interface enumeration using netsh, possible arp reconnaissance, new service created via command line - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: manipulation of bootexecute registry run key, dumping registry hives with passwords - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit exe, execution of regsvcs regasm with uncommon paths - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: modification of Windows boot configuration using bcdedit.exe and msbuild.exe execution - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: new service created via command line, powershell creates a new service - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: new service creation with shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: ping executed with loopback address, msbuild execution, registration of uncommon net services and or assemblies, unsigned process running from a temporary directory - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: ping loopback with PowerShell admin attempt and unsigned temp process - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: ping loopback with shadow copy access - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: powershell running with download in the command line, powershell calling invoke expression argument, query startup programs using wmic exe - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: rundll32 loads a known abused dll, execution of regsvcs regasm with uncommon paths - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, a scripting engine was called to run in command line, new service created via command line - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, msbuild execution - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, powershell running with download in the command line, powershell calling invoke expression argument - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: uncommon ip configuration listing via ipconfig exe, uncommon arp cache listing via arp exe, new service created via command line - Added
  * \[Medium] AI-determined combination of risky alerts under the same causality: uncommon local scheduled task creation via schtasks exe, suspicious powershell command line - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, powershell running with download in the command line - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: active directory enumeration using built in nltest exe, suspicious setspn exe execution - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: powershell script executed from a temporary directory, possible arp reconnaissance, unsigned process running from a temporary directory - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: suspicious powershell command line, powershell calling invoke expression argument - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: suspicious powershell command line, unsigned process running from a temporary directory - Added
  * \[Low] AI-determined combination of risky alerts under the same causality: task scheduled by commonly abused host process, commonly abused process executed with obfuscated characters, powershell running with download in the command line, suspicious powershell command line - Added
* \[Informational] [Msiexec execution of an executable from an uncommon remote location](broken://spaces/5O67gr80iLneA56jiuO2/pages/8vJYzFgYhRkyt0WUeL1x)
  * \[High] Msiexec execution of an executable from an uncommon remote location by an RMM tool - Added
  * \[High] Msiexec execution of an executable from an uncommon remote location with a specific port - Modified Metadata
  * \[Medium] Msiexec execution of an executable from an uncommon remote location without properties - Modified Metadata
* \[Informational] [Access to sensitive host files from within a Kubernetes pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/iiSOU7Ry6LumsCeVYeWb)
  * \[Medium] Access to sensitive host files from within a Kubernetes pod via an interactive shell - Modified Logic
* \[Informational] [Exchange email-hiding inbox rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/6T6sVmq50nEsUx6hAlNt)
  * \[Medium] Possible BEC Exchange email-hiding inbox rule - Modified Logic
  * \[Medium] Suspicious Exchange email-hiding inbox rule - Modified Logic
  * \[Medium] Suspicious catch-all Exchange email-hiding inbox rule - Added
  * \[Low] Abnormal Exchange email-hiding inbox rule - Modified Logic
* \[Informational] [Exchange email-hiding transport rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/1ui3K9aQ3EWw8bomiyNT)
  * \[Medium] Suspicious Exchange email-hiding transport rule - Modified Logic
* \[Medium] [Kubernetes vulnerability scanning tool usage](broken://spaces/5O67gr80iLneA56jiuO2/pages/Q9dJVR4FniZztcbgBNlP)
* \[Medium] [New Administrative Behavior](broken://spaces/5O67gr80iLneA56jiuO2/pages/lSbEzhUcoYzJq8F4FEHM)
* \[Informational] [Possible Brute Force in universal authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/YOQ8JgEfuIUj36BOt2jj)
  * \[Medium] Brute Force in universal authentication involving a honey user - Modified Metadata
  * \[Informational] Abnormal Brute Force in universal authentication - Modified Metadata
* \[Informational] [Possible Password Spray in universal authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/l5e5Rcht6pvLDJETuwFY)
  * \[Medium] Password Spray in universal authentication involving a honey user - Modified Metadata
* \[Medium] [Potential Phishing has been detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/ZW7MrHGYUx40swpKX5xE)
* \[Low] [SSO authentication attempt by a honey user](broken://spaces/5O67gr80iLneA56jiuO2/pages/4uL5AX5L6ziBnyeBthy8)
  * \[Medium] Abnormal SSO authentication by a honey user - Modified Logic
* \[Informational] [Unusual Kubernetes service account file read](broken://spaces/5O67gr80iLneA56jiuO2/pages/xRZoznMTGRMDjU2ZEngV)
  * \[Medium] Suspicious Kubernetes service account token read via an interactive shell - Modified Logic
* \[Informational] [Unusual cloud Instance Metadata Service (IMDS) access](broken://spaces/5O67gr80iLneA56jiuO2/pages/kV8oYC4AXbQGOtI8dZmP)
  * \[Medium] Unusual cloud Instance Metadata Service (IMDS) access from a lightweight JavaScript runtime executing a script - Added
* \[Low] [A user rejected an SSO request from an unusual country](broken://spaces/5O67gr80iLneA56jiuO2/pages/GIBGYdddNRCVO6XEZcpv)
* \[Low] [Abnormal SMB activity to multiple hosts](broken://spaces/5O67gr80iLneA56jiuO2/pages/JrrcpqM87cBebHblUciI)
* \[Low] [An S3 replication policy to an unknown bucket was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/m1sPV43FZCQVTuqxwi9I)
* \[Low] [Email attachment with Right-to-Left Override Unicode character](broken://spaces/5O67gr80iLneA56jiuO2/pages/sphehN57vRGrBSpISXCp)
* \[Informational] [Email contains URL delivering high-risk file type](broken://spaces/5O67gr80iLneA56jiuO2/pages/K3EyoIu2pYiiLON26iAn)
  * \[Low] External email with URL delivers blocked file types - Modified Logic
* \[Low] [Email was received from an unknown sender using a disposable domain](broken://spaces/5O67gr80iLneA56jiuO2/pages/sMql7SEe61kc84AycXsF)
* \[Low] [Email with file-sharing link containing auto-download parameter](broken://spaces/5O67gr80iLneA56jiuO2/pages/ndHae0M8T02ZOCFJvhny)
  * \[Low] External email with file-sharing link containing auto-download parameter - Modified Logic
* \[Informational] [Exchange compliance search created](broken://spaces/5O67gr80iLneA56jiuO2/pages/cEyEJrg9STpLu6R7OlyE)
  * \[Low] Suspicious Exchange compliance search created - Modified Logic
* \[Low] [Executable or Script file written by a web server process](broken://spaces/5O67gr80iLneA56jiuO2/pages/0rzFTwtkCPK9NsPp6TKt)
* \[Low] [Execution of command from within a Kubernetes pod using kubelet credentials](broken://spaces/5O67gr80iLneA56jiuO2/pages/ksBsZI5oXbSCy9m7bwFs)
* \[Informational] [Foreign account was granted permissions to S3 bucket via resource-based policy](broken://spaces/5O67gr80iLneA56jiuO2/pages/yTnwCQRkhBkTKePouftp)
  * \[Low] Foreign account was granted permissions to S3 bucket via resource-based policy with suspicious indicators - Modified Logic
* \[Low] [Impossible traveler - SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/YkIdzUtQybtzmdMCtQlh)
* \[Low] [Kubernetes pod creation from unknown container image registry](broken://spaces/5O67gr80iLneA56jiuO2/pages/VtxVfNEZH7T9p4tNstyt)
* \[Low] [Mount command was executed from within a Kubernetes pod to list all the attached filesystems](broken://spaces/5O67gr80iLneA56jiuO2/pages/FYrJwdKg3YTq6JTkvCAD)
* \[Low] [New cloud identity created with administrative policy](broken://spaces/5O67gr80iLneA56jiuO2/pages/tLOLyJRoZguLaC3us4AA)
* \[Informational] [Possible Impossible Travel Pattern - SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/RPF4sjJlSZP1AbdDMdX3)
  * \[Low] Azure First-Seen Device - Impossible Traveler - Modified Metadata
  * \[Low] Rare Country Login - Impossible Traveler (SSO) - Modified Metadata
* \[Low] [Possible phishing attack via Microsoft Teams](broken://spaces/5O67gr80iLneA56jiuO2/pages/edx3oaaKmPPDBxemJ2ku)
* \[Low] [Rare SMB session to a remote host](broken://spaces/5O67gr80iLneA56jiuO2/pages/nkdytjk03uMpKx8adL1j)
* \[Low] [SSO authentication by a machine account](broken://spaces/5O67gr80iLneA56jiuO2/pages/rZDEG73mpqDEVq3p3uvY)
* \[Low] [SSO authentication by a service account](broken://spaces/5O67gr80iLneA56jiuO2/pages/OKQrQzqGUrccxXtyJv06)
* \[Low] [Sending unusual file(s) to an external address](broken://spaces/5O67gr80iLneA56jiuO2/pages/htWFFFxzGh4VQd18SyX7)
* \[Informational] [Suspicious Unicode character detected in email](broken://spaces/5O67gr80iLneA56jiuO2/pages/k2iCQIskjntHjGoOTHgN)
  * \[Low] Phishing terms obfuscation using Unicode characters detected in email - Modified Logic
* \[Low] [Suspicious access to Kubernetes API with kubelet credentials](broken://spaces/5O67gr80iLneA56jiuO2/pages/q4obN95pJfMmD85sh89e)
* \[Low] [Suspicious account attribute modification that matches that of another account](broken://spaces/5O67gr80iLneA56jiuO2/pages/PNTDl6EgFE8ETKvn7M92)
* \[Low] [Training simulation email detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/a2Ou1rrPsiOaMSezTGK9)
* \[Low] [Unsigned process creates a scheduled task via file access](broken://spaces/5O67gr80iLneA56jiuO2/pages/GEdUyDaQvnzyBIgNkXdC)
* \[Low] [Unusual Kubernetes dashboard communication from a pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/kyzJcnwz9bCzebdAzF5H)
* \[Low] [Unusual Process Spawned by Nginx in Ingress-Nginx pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/89nI9dU89b34EbMDeOmB)
* \[Informational] [A Kubernetes ConfigMap was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/M7m9cgXF3hBVnTqezm4z)
* \[Informational] [A Kubernetes Cronjob was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/ieIxGmPBmOUnxxMvuAL5)
* \[Informational] [A Kubernetes DaemonSet was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/2zpFMMdKRcYyedRsWOvU)
* \[Informational] [A Kubernetes Pod was created with a sidecar container](broken://spaces/5O67gr80iLneA56jiuO2/pages/p06jKmKOAUxVnLcQjNcj)
* \[Informational] [A Kubernetes Pod was deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/dwh7Ryx7FvfK19DtkDeL)
* \[Informational] [A Kubernetes ReplicaSet was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/FmlK7U1sv0ELiB10BNbS)
* \[Informational] [A Kubernetes StatefulSet was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/LlkSnO9gVTzMOqNT036c)
* \[Informational] [A Kubernetes cluster role binding was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/bjJRrp0RZTpaKdhRptl7)
* \[Informational] [A Kubernetes cluster role was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/AFFHTf8czQuJ2k68cb3w)
* \[Informational] [A Kubernetes deployment was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/KBBxBx6VspuPEq4EV9I6)
* \[Informational] [A Kubernetes ephemeral container was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/x9vaGox28WA0xLeqfXNW)
* \[Informational] [A Kubernetes namespace was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/LtzVoZyE47f3eUt3KOv7)
* \[Informational] [A Kubernetes node service account activity from external IP](broken://spaces/5O67gr80iLneA56jiuO2/pages/K8XeTYmh4CPoR0enjV3D)
* \[Informational] [A Kubernetes role binding was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/Qt6ZPu778BC50csXFkmX)
* \[Informational] [A Kubernetes secret was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/EFrQ046mhcpbVtwmevZ3)
* \[Informational] [A Kubernetes service account executed an unusual API call](broken://spaces/5O67gr80iLneA56jiuO2/pages/Kft9hPavKsdTYIdfpoGZ)
* \[Informational] [A Kubernetes service account has enumerated its permissions](broken://spaces/5O67gr80iLneA56jiuO2/pages/psihSaJMElRdT3aL8adE)
* \[Informational] [A Kubernetes service account was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/ypQeDMSz18jV6EO6yKMx)
* \[Informational] [A Kubernetes service was created or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/8FbjG0MHc1q0Ke0gJ1PY)
* \[Informational] [A cloud identity invoked IAM related persistence operations](broken://spaces/5O67gr80iLneA56jiuO2/pages/VvaE0AKeuyzxpIaTj9Yj)
* \[Informational] [A disabled user attempted to authenticate via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/SxeFM8MGY1SPNtZvqow7)
* \[Informational] [A possible risky login to Azure](broken://spaces/5O67gr80iLneA56jiuO2/pages/i5ZNdqBJN09lHn5W1aPV)
* \[Informational] [A user accessed multiple unusual resources via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/NH9eHEqiPcKUzkq5H8wF)
* \[Informational] [A user connected from a new country](broken://spaces/5O67gr80iLneA56jiuO2/pages/lC2FatUi0AnvyRSJNKzu)
* \[Informational] [A user logged in at an unusual time via SSO](broken://spaces/5O67gr80iLneA56jiuO2/pages/jFVw4i8UoB1SPXY7BsIX)
* \[Informational] [A user logged in to the AWS console for the first time](broken://spaces/5O67gr80iLneA56jiuO2/pages/zBWHg5sUOC5HFb30a6gW)
* \[Informational] [Abnormal Communication to a Rare Domain](broken://spaces/5O67gr80iLneA56jiuO2/pages/n6GiHZ2wnHA67wnAfV2X)
* \[Informational] [Abnormal Recurring Communications to a Rare Domain](broken://spaces/5O67gr80iLneA56jiuO2/pages/urtwxmmJBKohSCK7MaJh)
* \[Informational] [Abnormal connections to a dormant host from a newly seen endpoint](broken://spaces/5O67gr80iLneA56jiuO2/pages/B5V7462qQeDUF99OuiCx)
* \[Informational] [An AWS S3 bucket configuration was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/UV8DoVHrCUBV0wTP0l8x)
* \[Informational] [An identity disabled bucket logging](broken://spaces/5O67gr80iLneA56jiuO2/pages/iowlqz3WrsHrDP5Wm40Q)
* \[Informational] [An identity started an AWS SSM session](broken://spaces/5O67gr80iLneA56jiuO2/pages/w88kCkaPSkwqjEFAzP3c)
* \[Informational] [An inactive user attempted to authenticate](broken://spaces/5O67gr80iLneA56jiuO2/pages/6mHta6ojXWm64Lp0YIvU)
* \[Informational] [Azure Blob Container Access Level Modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/OX1mgTHwHCfhDamtVoK0)
* \[Informational] [Bucket's block public access setting turned off](broken://spaces/5O67gr80iLneA56jiuO2/pages/0J1ABIVR09YcrgC8TziG)
* \[Informational] [Bucket's object ownership controls were modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/Y8RAZN0kH2f5OCDMRE4y)
* \[Informational] [Cloud access key creation](broken://spaces/5O67gr80iLneA56jiuO2/pages/VuWhcWbe5f0u4OcSE780)
* \[Informational] [Command execution in a Kubernetes pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/GMyYqSEJ4m0keYDTrM7j)
* \[Informational] [Denied API call by a Kubernetes service account](broken://spaces/5O67gr80iLneA56jiuO2/pages/0cQEemPQNQYGVTXbzUkC)
* \[Informational] [Display text URL differs from actual URL](broken://spaces/5O67gr80iLneA56jiuO2/pages/Nnid8FUWeDWPBR0iDbff)
* \[Informational] [Email attachment with a potentially malicious file extension](broken://spaces/5O67gr80iLneA56jiuO2/pages/KeBQroYg59giSTxCtdY9)
* \[Informational] [Email attachment with multiple extensions](broken://spaces/5O67gr80iLneA56jiuO2/pages/jsYnqHaBMOCpKsYE1dar)
* \[Informational] [Email attachment(s) with potentially malicious MIME type](broken://spaces/5O67gr80iLneA56jiuO2/pages/Uz8lw3zqeFvTYm5XFoem)
* \[Informational] [Email containing a link with an IP address convention was detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/IzeLANxj7iLCSsCKdGvx)
* \[Informational] [Email containing a redirected link](broken://spaces/5O67gr80iLneA56jiuO2/pages/JC5cy28yKeVIpYDyVMym)
* \[Informational] [Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values](broken://spaces/5O67gr80iLneA56jiuO2/pages/fEj9qGrKQqdkD2uOmiKr)
* \[Informational] [Email mimics replies or forwards without an actual ongoing conversation](broken://spaces/5O67gr80iLneA56jiuO2/pages/TAg82QZbKea4BMcM6XIQ)
* \[Informational] [Email sent using an automated system or script detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/IUhg25ldORWvacQ1Q92k)
* \[Informational] [Email was received from an unknown address using a public provider domain](broken://spaces/5O67gr80iLneA56jiuO2/pages/EG0H21bzfznUBFywi5Fs)
* \[Informational] [Email with URL shortener detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/I0F4vyCMRaoPXvz6zFI8)
* \[Informational] [External email display name impersonation of internal personnel](broken://spaces/5O67gr80iLneA56jiuO2/pages/wrnR7BFciqTz90Q1TVhb)
* \[Informational] [External email with a single internal recipient hidden in BCC](broken://spaces/5O67gr80iLneA56jiuO2/pages/Rh0enioMyj8Tl25plDx6)
* \[Informational] [First SSO Resource Access in the Organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/gq1LdpGl8JzmMMNp36Ae)
* \[Informational] [First SSO access from ASN for user](broken://spaces/5O67gr80iLneA56jiuO2/pages/FyUbaZfqVy7PgkZVEcFV)
  * \[Informational] Google Workspace - First SSO access from ASN for user - Modified Logic
* \[Informational] [First SSO access from ASN in organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/ngCCbVwIDLaIfZL8JJdl)
  * \[Informational] Google Workspace - First SSO access from ASN in organization - Modified Logic
* \[Informational] [First connection from a country in organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/FIMCM9JyVH2wTqVN7ErR)
* \[Informational] [First-seen email from mailbox owner to external recipient's address in the last 30 days](broken://spaces/5O67gr80iLneA56jiuO2/pages/gubzm5iKyB7QFJi4OTOo)
  * \[Informational] First-time email from mailbox owner to the external recipient's domain in the last 30 days - Modified Logic
  * \[Informational] First-time email from organization with the external recipient in the last 30 days - Modified Logic
  * \[Informational] First-time email from organization's domain to the external recipient in the last 30 days - Modified Logic
  * \[Informational] First-time email from organization's domain with the external recipient's domain in the last 30 days - Modified Logic
  * \[Informational] First-time outbound email from mailbox owner to multiple external recipients without any internal recipients in the last 30 days - Modified Logic
* \[Informational] [First-time attachment exchange](broken://spaces/5O67gr80iLneA56jiuO2/pages/oQUigZ1QqGF0HauBCXLB)
* \[Informational] [GCP Service Account creation](broken://spaces/5O67gr80iLneA56jiuO2/pages/5htXr3MY9kStUXTurkz8)
* \[Informational] [GCP Storage Bucket Configuration Modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/oxCsa7rsiWkIIYz2TVx9)
* \[Informational] [GCP Storage Bucket Permissions Modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/ps5QrLa9eo4hWhrpJDKi)
* \[Informational] [Globally uncommon image load from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/4LQEO2b8QQS1NtHkdxqQ)
* \[Informational] [IAM inline policy was added to role](broken://spaces/5O67gr80iLneA56jiuO2/pages/8S3nCrQSzOA67qqivOAc)
* \[Informational] [IAM inline policy was added to user](broken://spaces/5O67gr80iLneA56jiuO2/pages/qspxBTC47qjdAUlYQnml)
* \[Informational] [IAM role was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/TYzSNN07lXFf0zif418c)
* \[Informational] [IP Rotation Pattern in SSO Spray](broken://spaces/5O67gr80iLneA56jiuO2/pages/mHIJl93IEfdYBhrf3Pa2)
* \[Informational] [Initial person-to-person email contact](broken://spaces/5O67gr80iLneA56jiuO2/pages/GxrlDmnCXVvO6ZvUDchN)
* \[Informational] [Intense SSO failures](broken://spaces/5O67gr80iLneA56jiuO2/pages/CQ1CjZHIere2PcggNso8)
* \[Informational] [Kubelet server communication from a pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/yvXbhiWeYxyd7iBttSAT)
* \[Informational] [Kubernetes API server communication from within a pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/5GiI51hCeoKMUA0LYW4l)
* \[Informational] [Kubernetes Pod Created With Sensitive Volume](broken://spaces/5O67gr80iLneA56jiuO2/pages/pH7gRMmgHnrd7nb8XJbj)
* \[Informational] [Kubernetes Pod Created with host Inter Process Communications (IPC) namespace](broken://spaces/5O67gr80iLneA56jiuO2/pages/WxvrITK2G9GszaRbW8Ko)
* \[Informational] [Kubernetes Pod created with host process ID (PID) namespace](broken://spaces/5O67gr80iLneA56jiuO2/pages/cTi3qBv0MRDlroesHyIk)
* \[Informational] [Kubernetes Privileged Pod Creation](broken://spaces/5O67gr80iLneA56jiuO2/pages/ScdcS81wjgsQSJYP0j2y)
* \[Informational] [Kubernetes admission controller activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/l9IXlPvi0we75AeGMNam)
* \[Informational] [Kubernetes cluster events deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/syneqs1PKmSSarej52ar)
* \[Informational] [Kubernetes environment enumeration activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/O5GwHdMySCmN7RtCQCYt)
* \[Informational] [Kubernetes network policy modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/Zb46lH3WiqZoR6bsYaMV)
* \[Informational] [Kubernetes nsenter container escape](broken://spaces/5O67gr80iLneA56jiuO2/pages/AjqN3AZj4PRTE3JfE3KU)
* \[Informational] [Kubernetes pod creation with host network](broken://spaces/5O67gr80iLneA56jiuO2/pages/AZ6IMr8UAgitx44xCuGK)
* \[Informational] [Kubernetes secret enumeration activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/CnRATSUOd7l7m2evySMu)
* \[Informational] [Kubernetes secrets enumeration for the first time](broken://spaces/5O67gr80iLneA56jiuO2/pages/qpwSVRjwrDuyMF6Y1gip)
* \[Informational] [Kubernetes service account activity outside the cluster](broken://spaces/5O67gr80iLneA56jiuO2/pages/uACAKyz0ZXAcj71bzDdP)
* \[Informational] [Kubernetes version disclosure](broken://spaces/5O67gr80iLneA56jiuO2/pages/3FR4O3M4butBZN3s1s7C)
* \[Informational] [MFA device was removed/deactivated from an IAM user](broken://spaces/5O67gr80iLneA56jiuO2/pages/yIF7YWyIUM8eUBmj5yxW)
* \[Informational] [Massive file activity abnormal to process](broken://spaces/5O67gr80iLneA56jiuO2/pages/BglVkccr0n4YavQzmSSV)
* \[Informational] [Moniker link detected in URL(s)](broken://spaces/5O67gr80iLneA56jiuO2/pages/ad5hLZxhhT3Km7C0U1bK)
* \[Informational] [Multiple Okta MFA requests sent to a user](broken://spaces/5O67gr80iLneA56jiuO2/pages/WQamBlkPTbj7q3imjbEA)
* \[Informational] [Near-empty email from an external sender](broken://spaces/5O67gr80iLneA56jiuO2/pages/n7AAPNLwzrrm99VLODIJ)
* \[Informational] [Numerous emails sent by a single sender to multiple internal recipients](broken://spaces/5O67gr80iLneA56jiuO2/pages/KevGJlUDaGqUoJUmuxJJ)
* \[Informational] [Outbound email contains file-sharing service link sent to external recipient](broken://spaces/5O67gr80iLneA56jiuO2/pages/8qz5ucyROK8RcnG9Vqbu)
* \[Informational] [Outbound email includes an external BCC recipient observed for the first time](broken://spaces/5O67gr80iLneA56jiuO2/pages/rRmkY6ZGPCSIWjbCgm5s)
* \[Informational] [Outbound email to an address hosted by a public email service provider](broken://spaces/5O67gr80iLneA56jiuO2/pages/i9SRPjZN6XmwdfMjbAQN)
* \[Informational] [Port Scan](broken://spaces/5O67gr80iLneA56jiuO2/pages/VpTObwTIg557LRvTrSDU)
* \[Informational] [Potential spoofing of internal domain spotted](broken://spaces/5O67gr80iLneA56jiuO2/pages/CFKHgN6DQQsi7u3jEFWo)
* \[Informational] [Quarantined email released to recipients](broken://spaces/5O67gr80iLneA56jiuO2/pages/ndiEgrPtILqPovfbEY8N)
* \[Informational] [Rarely seen sender address in the organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/WlvAsGxBJ4EE43zysoOv)
* \[Informational] [Rarely seen sender domain in the organization](broken://spaces/5O67gr80iLneA56jiuO2/pages/VdEChpKTJ6BccTJ8ip8D)
* \[Informational] [Remote code execution into Kubernetes Pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/GL7ftWmjeAToxACu1Idd)
* \[Informational] [S3 configuration deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/DxME62rvfdHMLMVXX6UG)
* \[Informational] [SSO Brute Force](broken://spaces/5O67gr80iLneA56jiuO2/pages/NTqIaZGFy806o4UU141r)
* \[Informational] [SSO Password Spray](broken://spaces/5O67gr80iLneA56jiuO2/pages/kyeZ8ow8uOOpPOrmqQpo)
* \[Informational] [SSO with abnormal operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/ydIpP8Ir02iMSFmjPxje)
* \[Informational] [SSO with abnormal user agent](broken://spaces/5O67gr80iLneA56jiuO2/pages/LxiLIKyfnS4H3YHBpzBA)
* \[Informational] [SSO with new operating system](broken://spaces/5O67gr80iLneA56jiuO2/pages/KLkmbuK8DWiTGinWme5e)
* \[Informational] [Successful universal authentication with suspicious features](broken://spaces/5O67gr80iLneA56jiuO2/pages/yLTPEE2iaKoDiP1MB0rl)
* \[Informational] [Sudden spike in outbound email volume](broken://spaces/5O67gr80iLneA56jiuO2/pages/cPgBwAb0N7ZbmrfEyTTH)
* \[Informational] [Suspicious DKIM Result](broken://spaces/5O67gr80iLneA56jiuO2/pages/EfEPnxad24Bts1mXmDX4)
  * \[Informational] DKIM results lacking sender correlation - Modified Metadata
  * \[Informational] Known domain DKIM deviation - Modified Metadata
  * \[Informational] Known domain suspicious DKIM result - Modified Metadata
  * \[Informational] Lack DKIM signature from typically signing domains - Modified Metadata
* \[Informational] [Suspicious DMARC result](broken://spaces/5O67gr80iLneA56jiuO2/pages/hxJzF8AxlYqydxmRzWxA)
* \[Informational] [Suspicious SPF Result](broken://spaces/5O67gr80iLneA56jiuO2/pages/heLUz31u2DWV6dFF71CS)
  * \[Informational] Internal domain SPF deviation - Modified Logic
  * \[Informational] Known domain SPF deviation - Modified Metadata
* \[Informational] [Suspicious SSO access from ASN](broken://spaces/5O67gr80iLneA56jiuO2/pages/3hCnafpvxH4MFvtjRuIJ)
* \[Informational] [Suspicious SSO authentication](broken://spaces/5O67gr80iLneA56jiuO2/pages/lZFr9XqsoBQpJvpyF5Xl)
* \[Informational] [Suspicious brand affiliation detected](broken://spaces/5O67gr80iLneA56jiuO2/pages/zwfiRlnrmvIJ6H7rXbHm)
* \[Informational] [Suspicious container reconnaissance activity in a Kubernetes pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/xPiYW3ORVCd3Apqoz2Iq)
* \[Informational] [Suspicious container runtime connection from within a Kubernetes Pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/4OWqHvHvIajXEp1sx0oK)
* \[Informational] [Suspicious process execution in a privileged container](broken://spaces/5O67gr80iLneA56jiuO2/pages/iJ2AC6lvyCPqM7e4AGNU)
* \[Informational] [Suspicious sender exhibiting automated sending patterns](broken://spaces/5O67gr80iLneA56jiuO2/pages/Zrg7wrVjgmNvgqPUHdrP)
* \[Informational] [Suspicious sending domain with sender address randomization](broken://spaces/5O67gr80iLneA56jiuO2/pages/GiVdrz7LDYcb9FsWlfoB)
* \[Informational] [Uncommon URL domain(s) in your organization detected in email](broken://spaces/5O67gr80iLneA56jiuO2/pages/Lf7YyDzaYWjRH8EE5ijV)
* \[Informational] [Unrecognized internal address (AAD mismatch)](broken://spaces/5O67gr80iLneA56jiuO2/pages/PJooCZ2OkA0NcvwQLkPi)
* \[Informational] [Unusual Kubernetes secret access](broken://spaces/5O67gr80iLneA56jiuO2/pages/F5yAtOTWRMIgeeximblX)
* \[Informational] [Unusual SSH Activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/dmjGzQucIJkwzEGZJ9Ld)
* \[Informational] [Unusual URL(s) sent by a brand were observed in the email](broken://spaces/5O67gr80iLneA56jiuO2/pages/y6VqeLBg6UmtbKkHoOh9)
* \[Informational] [Unusual attachment volume in outbound emails](broken://spaces/5O67gr80iLneA56jiuO2/pages/64BpV0QEe3VbXoSoM5Vt)
* \[Informational] [Unusual certificate management activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/p0S8Zk7GHP96sGpIFZK8)
* \[Informational] [Unusual display name in From header](broken://spaces/5O67gr80iLneA56jiuO2/pages/S5rUOaQKVuOf4PWFAxRz)
* \[Informational] [Unusual exec into a Kubernetes Pod](broken://spaces/5O67gr80iLneA56jiuO2/pages/igP7FQZrzliqKYPlRR3z)
* \[Informational] [Unusual file-sharing links for mailbox owner](broken://spaces/5O67gr80iLneA56jiuO2/pages/VJmz5jvid6l9c5hKDMxt)
* \[Informational] [Unusual hostname for the sending mail server in the email headers](broken://spaces/5O67gr80iLneA56jiuO2/pages/GNUXnHxwbdXgAq2RtKnb)
* \[Informational] [Unusual key management activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/FiKXdkXI1GPWCDB9Tsuk)
* \[Informational] [Unusual secret management activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/2RrMkVZ22kPrUSwy5FjE)
* \[Informational] [Unusual sender IP subnet](broken://spaces/5O67gr80iLneA56jiuO2/pages/g3tJ6TgKpOTQIJGy8XAu)
  * \[Informational] Unusual sender IP subnet associated with internal sender - Modified Logic
* \[Informational] [Usage of homograph characters detected in an email](broken://spaces/5O67gr80iLneA56jiuO2/pages/2cdHmD1GOgI9AvvBZyAt)
* \[Informational] [Usage of homograph characters detected in an email attachment(s) name](broken://spaces/5O67gr80iLneA56jiuO2/pages/6pqKTNIwBOvSxCBzY7iQ)
* \[Informational] [Usage of homograph characters detected in an email's from header](broken://spaces/5O67gr80iLneA56jiuO2/pages/vcsFPRPHkiwSTR3s2WkM)
* \[Informational] [User attempted to connect from a suspicious country](broken://spaces/5O67gr80iLneA56jiuO2/pages/5YFXe1e4UZi9YuAwHetB)
* \[Informational] [Well-known brand in sender headers with header inconsistencies](broken://spaces/5O67gr80iLneA56jiuO2/pages/msUN0jfTgQkpqc2Kcv6Q)
* \[Informational] [X-Forefront-Antispam-Report has flagged this email as a potential threat](broken://spaces/5O67gr80iLneA56jiuO2/pages/x0bAnI779P7Z2B5TJzUL)

### Modified Metadata

* \[Informational] [A process connected to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/AfS7lcX54qr1oRJkZzdK)
  * \[High] MSBuild process connected to a rare external host - Modified Metadata
  * \[Medium] MSBuild process connected to a rare external host - Modified Metadata
* \[High] [Bitsadmin.exe used to upload data](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/bitsadmin-exe-used-to-upload-data)
* \[High] [Encoded VBScript executed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/encoded-vbscript-executed)
* \[High] [EventLog service disabled by a Registry operation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/eventlog-service-disabled-by-a-registry-operation)
* \[Informational] [Globally uncommon IP address by a common process (sha256)](broken://spaces/5O67gr80iLneA56jiuO2/pages/37w6T1PN3nkahNWTeauA)
  * \[High] Globally uncommon IP address by a common process (sha256) from an injected thread - Modified Metadata
* \[Informational] [Globally uncommon root-domain port combination by a common process (sha256)](broken://spaces/5O67gr80iLneA56jiuO2/pages/JjDOcM1VPD0IPsveZ1ut)
  * \[High] Globally uncommon root-domain port combination by a common process (sha256) from an injected thread - Modified Metadata
* \[High] [Possible Distributed File System Namespace Management (DFSNM) abuse](broken://spaces/5O67gr80iLneA56jiuO2/pages/ge6HN6M3XUghjoNtvuOI)
* \[High] [Pubprn.vbs signed script proxy execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/pubprn-vbs-signed-script-proxy-execution)
* \[High] [Regsvr32 may have run code from an untrusted source](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/regsvr32-may-have-run-code-from-an-untrusted-source)
* \[High] [Suspicious executable created in a .NET directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-executable-created-in-a-net-directory)
* \[Low] [Uncommon AppleScript with a potential defense-evasion command was executed via the command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-applescript-with-a-potential-defense-evasion-command-was-executed-via-the-command-line)
  * \[High] Uncommon AppleScript with a potential defense-evasion command was executed via the command line disabling the Gatekeeper security feature - Modified Metadata
  * \[Medium] Uncommon AppleScript with a potential defense-evasion command was executed via the command line manipulating the 'hosts' file - Modified Metadata
  * \[Low] Uncommon AppleScript with a potential defense-evasion command was executed via the command line deleting attributes from a file - Modified Metadata
  * \[Low] Uncommon AppleScript with a potential defense-evasion command was executed via the command line setting a network proxy - Modified Metadata
* \[Low] [Uncommon AppleScript with a potential discovery command was executed via the command line](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/uncommon-applescript-with-a-potential-discovery-command-was-executed-via-the-command-line)
  * \[High] Uncommon AppleScript with a potential discovery command was executed via the command line querying virtual environment information - Modified Metadata
  * \[Medium] Uncommon AppleScript with a potential discovery command was executed via the command line, querying hardware or software information - Modified Metadata
* \[Informational] [Uncommon Linux shell command execution](broken://spaces/5O67gr80iLneA56jiuO2/pages/lGO5psfcQ34TSQdFSa8k)
  * \[High] Uncommon Linux shell command execution disabling firewall - Modified Metadata
  * \[Low] Uncommon Linux shell command execution, possibly granting file execution permissions - Modified Metadata
* \[High] [Unicode RTL Override Character](broken://spaces/5O67gr80iLneA56jiuO2/pages/VjzcFgBsYjFIsaxDRauB)
* \[Low] [Unsigned and unpopular process performed an injection](broken://spaces/5O67gr80iLneA56jiuO2/pages/i92XqTDJAmsxjRtjP0A1)
  * \[High] Unsigned and unpopular process performed injection into svchost.exe - Modified Metadata
* \[Low] [A commonly abused process connected to a rare cloud resource](broken://spaces/5O67gr80iLneA56jiuO2/pages/L9sbm68NAG2gIgznJMv1)
  * \[Medium] A commonly abused renamed process connected to a rare cloud resource - Modified Metadata
* \[Medium] [A process was executed with a command line obfuscated by Unicode character substitution](broken://spaces/5O67gr80iLneA56jiuO2/pages/2jCnm6TghjotMEJuOCXZ)
* \[Medium] [A suspicious executable with multiple file extensions was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/4vFiUxZmQhec1pLjjOF8)
* \[Medium] [AMSI Bypass](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/amsi-bypass)
* \[Informational] [AWS CloudTrail modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/1tDFRIhomlZdOTzoBHfc)
  * \[Medium] AWS CloudTrail modification - Modified Metadata
* \[Medium] [An unsigned process created scheduled task and performed an injection](broken://spaces/5O67gr80iLneA56jiuO2/pages/NR0D8EcQ3Y3KBi9hzyXB)
* \[Medium] [Autorun.inf created in root C drive](broken://spaces/5O67gr80iLneA56jiuO2/pages/fW3yTYBKINYeSpRKxtz3)
* \[Medium] [Azure AD PIM alert disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/lC0KKgJ6my6Itl5GvfRk)
* \[Medium] [Clear logs - using dd and /dev/null](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clear-logs-using-dd-and-dev-null)
* \[Medium] [Delete Volume USN Journal with fsutil](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/delete-volume-usn-journal-with-fsutil)
* \[Medium] [Encoded information using Windows certificate management tool](broken://spaces/5O67gr80iLneA56jiuO2/pages/cDkFWr83w4i5IKGkuJKQ)
* \[Medium] [Executable created to disk by lsass.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/oqDsrVkasV5Wh503SIF7)
* \[Informational] [GCP logging sink modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/4Jd1qlq1n3LjCEMDpSGu)
  * \[Medium] GCP logging sink modification - Modified Metadata
* \[Medium] [Impersonation using Rubeus tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/impersonation-using-rubeus-tool)
* \[Medium] [Indirect command execution using the Program Compatibility Assistant](broken://spaces/5O67gr80iLneA56jiuO2/pages/2V5VOh8aGbmcFq7VTeGZ)
* \[Medium] [Kerberos ticket forging using Impacket ticketer](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/kerberos-ticket-forging-using-impacket-ticketer)
* \[Medium] [Logging was impaired via external encryption key](broken://spaces/5O67gr80iLneA56jiuO2/pages/pahVRRd1YGLkvwMV40GX)
* \[Medium] [Phantom DLL Loading](broken://spaces/5O67gr80iLneA56jiuO2/pages/JNbeVu1miNdf1jxgSsNf)
* \[Medium] [Possible code downloading from a remote host by Regsvr32](broken://spaces/5O67gr80iLneA56jiuO2/pages/e0I6GprMO0XMk24T4pRE)
* \[Medium] [Possible malicious .NET compilation started by a commonly abused process](broken://spaces/5O67gr80iLneA56jiuO2/pages/QYXjo5YzBeWLYdEHiqTP)
* \[Medium] [Procdump executed from an atypical directory](broken://spaces/5O67gr80iLneA56jiuO2/pages/QoheqYdo1Y0U4zZ9BHdC)
* \[Medium] [Process attempts to kill a known security/AV tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/process-attempts-to-kill-a-known-security-av-tool)
* \[Informational] [Rare process accessed a Keychain file](broken://spaces/5O67gr80iLneA56jiuO2/pages/jKyTL5Qsl4s7OdbluWeN)
  * \[Medium] Rare process accessed a Keychain file while installing a new certificate - Modified Metadata
* \[Medium] [Rundll32.exe launches an executable using ordinal numbers argument](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-launches-an-executable-using-ordinal-numbers-argument)
* \[Medium] [Rundll32.exe running with no command-line arguments](broken://spaces/5O67gr80iLneA56jiuO2/pages/JworNQEuLwGxBF11EUH9)
* \[Medium] [Rundll32.exe spawns conhost.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/IYGDhBfqku8m1YiAlvtb)
* \[Medium] [Rundll32.exe was used to run JavaScript](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-was-used-to-run-javascript)
* \[Medium] [Rundll32.exe with 'main' as EntryPoint](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-exe-with-main-as-entrypoint)
* \[Medium] [Suspicious .NET process loads an MSBuild DLL](broken://spaces/5O67gr80iLneA56jiuO2/pages/Yv4yiZqqkHgyZtdQtH0A)
* \[Medium] [Suspicious DLL load using Control.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-dll-load-using-control-exe)
* \[Medium] [Suspicious Process Spawned by wininit.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/T6NPjpVCPSnnVe3IG8rY)
* \[Medium] [Suspicious SearchProtocolHost.exe parent process](broken://spaces/5O67gr80iLneA56jiuO2/pages/eCewRsrvozxYjvW9whZQ)
* \[Medium] [Suspicious authentication with Azure Password Hash Sync user](broken://spaces/5O67gr80iLneA56jiuO2/pages/dtPUnMTGaUxUUeSVf3Vm)
* \[Medium] [Suspicious certutil command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/b0kwQTKRDmNNsefGnQiZ)
* \[Medium] [Suspicious disablement of the Windows Firewall using PowerShell commands](broken://spaces/5O67gr80iLneA56jiuO2/pages/NgEoXF47Rhty8CdfwXgf)
* \[Medium] [Suspicious hidden user created](broken://spaces/5O67gr80iLneA56jiuO2/pages/VzpHBqqhuBzxCXmlz6SJ)
* \[Medium] [Suspicious process spawns MSBuild.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-process-spawns-msbuild-exe)
* \[Medium] [Uncommon DLL-sideloading from a logical CD-ROM (ISO) device](broken://spaces/5O67gr80iLneA56jiuO2/pages/J1njwt1fYd6ze1ymxprK)
* \[Informational] [Uncommon macOS process communication to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/8O9nmOa5qXZusK8xrSQR)
  * \[Medium] Uncommon macOS process communication to a rare external host with a frequently abused TLD - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host related to LOTTunnels - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility and downloading a script - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility and saving data to a temporary folder - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility running by an unsigned process - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host while using a CLI utility to download and change permission - Modified Metadata
  * \[Low] Uncommon macOS process communication to a rare external host with a rare TLD - Modified Metadata
* \[Medium] [Unsigned process injecting into a Windows system binary with no command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/wNk3yOq3bclGLXcoHBkB)
* \[Medium] [Unusual process access to ld.so.preload file](broken://spaces/5O67gr80iLneA56jiuO2/pages/fCL0V0oZzzF2Hj0MXi60)
* \[Informational] [VM Detection attempt on Linux](broken://spaces/5O67gr80iLneA56jiuO2/pages/XHly6WYfVUUQc5w9VRiN)
  * \[Medium] VM Detection attempt on Linux with further reconnaissance commands - Modified Metadata
* \[Medium] [WerFault ReflectDebugger key set in Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/werfault-reflectdebugger-key-set-in-registry)
* \[Medium] [Windows event logs cleared using wmic.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-event-logs-cleared-using-wmic-exe)
* \[Medium] [Windows set to permit unsigned drivers (Test Mode)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-set-to-permit-unsigned-drivers-test-mode)
* \[Medium] [WptsExtensions.dll created to disk](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wptsextensions-dll-created-to-disk)
* \[Low] [A compiled HTML help file wrote a script file to the disk](broken://spaces/5O67gr80iLneA56jiuO2/pages/NjRZD5OszYZfVRL10ove)
* \[Low] [A domain was added to the trusted domains list](broken://spaces/5O67gr80iLneA56jiuO2/pages/apDcVs8pPymv8lipDgPn)
* \[Low] [A user modified the CA audit policy](broken://spaces/5O67gr80iLneA56jiuO2/pages/o1N5i9gMSI3kDYOd8fz1)
* \[Low] [AWS Bedrock model invocation logging deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/ZmMyXf7yU35hz3mx6gcZ)
* \[Low] [AWS Guard-Duty detector deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/oCGZPsiGtAkBrsCaqmcX)
* \[Low] [AWS S3 bucket was exposed to public access](broken://spaces/5O67gr80iLneA56jiuO2/pages/yNcvI0AkMPif3rxIJwsV)
* \[Low] [AWS Security Group remote access allowed from an unknown external IP address](broken://spaces/5O67gr80iLneA56jiuO2/pages/hek8OyPOpxaJcdNe3LoO)
* \[Low] [AWS data asset shared public](broken://spaces/5O67gr80iLneA56jiuO2/pages/zZlR0sUOPM1MY3o4yTSV)
* \[Low] [Accessing bash history file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/accessing-bash-history-file)
* \[Low] [Accessing bash history file using bash commands](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/accessing-bash-history-file-using-bash-commands)
* \[Low] [An Azure Firewall policy deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/vVrLdotDOAW9NMA3Imef)
* \[Low] [Azure AD PIM role settings change](broken://spaces/5O67gr80iLneA56jiuO2/pages/0AWMqXJA9AcUV9bAuIvL)
* \[Low] [Azure Event Hub Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/buNmHqZH9KOyJojdxIVV)
* \[Low] [Azure Network Watcher Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/TXNcOUBmDT9zCFqVUIrN)
* \[Low] [Change of sudo caching configuration](broken://spaces/5O67gr80iLneA56jiuO2/pages/UY5CIzLCsQB4VQjDWbue)
* \[Low] [Conditional Access policy removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/B1oReh2bLcY5f2vjmXis)
* \[Low] [Conhost.exe spawned a suspicious cmd process](broken://spaces/5O67gr80iLneA56jiuO2/pages/Utmn7ETCfYW63yPajb1c)
* \[Low] [DLL sideloading attack using Xwizard](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/dll-sideloading-attack-using-xwizard)
* \[Low] [Delayed Deletion of Files](broken://spaces/5O67gr80iLneA56jiuO2/pages/dFR3R8hfkfZ5pYUPxl8Z)
* \[Low] [Disable Microsoft Defender Antivirus via registry](broken://spaces/5O67gr80iLneA56jiuO2/pages/X49ycs4j2NKm07WkcVoc)
* \[Low] [Exchange DKIM signing configuration disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/i3YHwQe59sp3oclVc3c5)
* \[Low] [Exchange Safe Attachment policy disabled or removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/AgUP2d8XIx1X85dflMpX)
* \[Low] [Exchange Safe Link policy disabled or removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/khVlS6W3vb3I21afnlTJ)
* \[Low] [Exchange anti-phish policy disabled or removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/s48ViMgWekKAGWJ2xie7)
* \[Low] [Exchange audit log disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/GYbO26RzTKbWkWRzYiww)
* \[Low] [Exchange mailbox audit bypass](broken://spaces/5O67gr80iLneA56jiuO2/pages/MtcjV5AwDto2f2F7Y6vL)
* \[Low] [Exchange malware filter policy removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/UxR9R6hWpahIkQekid5t)
* \[Low] [Execution of an uncommon process with a local/domain user SID at early startup by a system binary](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-early-startup-by-a-system-binary)
  * \[Low] Execution of an uncommon process with a local/domain user SID at early startup with suspicious characteristics - Modified Metadata
  * \[Low] Execution of an uncommon process with a local/domain user SID at early startup with uncommon characteristics - Modified Metadata
  * \[Informational] Execution of an uncommon process with a local/domain user SID at early startup by a system binary - Explorer CGO - Modified Metadata
* \[Low] [Execution of dllhost.exe with an empty command line](broken://spaces/5O67gr80iLneA56jiuO2/pages/EHDKrDUJ3MGf76iR8C3n)
* \[Low] [GCP data asset shared public](broken://spaces/5O67gr80iLneA56jiuO2/pages/Uk9NYxnmsCByzVxGsyWE)
* \[Informational] [Globally uncommon high entropy process was executed](broken://spaces/5O67gr80iLneA56jiuO2/pages/YRchX2PWM6WDOLwu3LwK)
  * \[Low] Globally uncommon high entropy process was executed by a web server process or CGO - Modified Metadata
* \[Informational] [Globally uncommon process execution from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/4oU1ceYnH9aVfQHYC4pc)
  * \[Low] Globally uncommon process execution from an injected thread in a signed process - Modified Metadata
* \[Low] [Globally uncommon root domain from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/nukhYEgBeR05MciaKndi)
* \[Low] [Globally uncommon root-domain port combination from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/1C5w8lzpUow2Y6B8NDBF)
* \[Low] [Linux system firewall was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/wzcaJciQsjnaigdJKPrC)
* \[Low] [MFA was disabled for an Azure identity](broken://spaces/5O67gr80iLneA56jiuO2/pages/Ltv58u52P9oreUZgxJKG)
* \[Low] [Machine Account NTLM Relay](broken://spaces/5O67gr80iLneA56jiuO2/pages/fShKrb9423OrHEUpUX52)
* \[Low] [Masquerading as a default local account](broken://spaces/5O67gr80iLneA56jiuO2/pages/ipA84Gupwpdvr45JluEH)
* \[Low] [Masquerading as the Linux crond process](broken://spaces/5O67gr80iLneA56jiuO2/pages/MnOel1OdWz1YeeZjD6u5)
* \[Low] [Microsoft Connection Manager Profile Installer loads a file from the users to temporary folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-connection-manager-profile-installer-loads-a-file-from-the-users-to-temporary-folder)
* \[Low] [Microsoft Connection Manager Profile Installer makes connections to the network](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-connection-manager-profile-installer-makes-connections-to-the-network)
* \[Low] [Microsoft Connection Manager Profile Installer runs command line or PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-connection-manager-profile-installer-runs-command-line-or-powershell)
* \[Low] [Microsoft Office injects code into a process](broken://spaces/5O67gr80iLneA56jiuO2/pages/E5uaGX8SRgclgFvR51ZB)
* \[Low] [Mshta.exe launched with suspicious arguments](broken://spaces/5O67gr80iLneA56jiuO2/pages/4PHdAayQ9JjLOaJos8za)
* \[Low] [Mshta.exe spawns from a browser process](broken://spaces/5O67gr80iLneA56jiuO2/pages/bD9Dlm6rFVFNNVLQXlgJ)
* \[Low] [New addition to Windows Defender exclusion list](broken://spaces/5O67gr80iLneA56jiuO2/pages/m1sBGbmtoZfB3IcrKtKQ)
* \[Low] [Notepad process makes a network connection](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/notepad-process-makes-a-network-connection)
* \[Low] [Office process spawned with suspicious command-line arguments](broken://spaces/5O67gr80iLneA56jiuO2/pages/Z6LPRRCG3amln7FNBs1D)
* \[Low] [Possible DCSync from a non domain controller](broken://spaces/5O67gr80iLneA56jiuO2/pages/lrAEPQwsRmDztPIaR8xd)
* \[Low] [Possible DLL Search Order Hijacking](broken://spaces/5O67gr80iLneA56jiuO2/pages/r6mntLZu5HqDtQtAepO0)
* \[Low] [Potential extraction of NAA Account Credentials in Microsoft Configuration Manager](broken://spaces/5O67gr80iLneA56jiuO2/pages/8H9HFvSpqcJysDL4cMLT)
* \[Low] [Process runs from the recycle bin](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/process-runs-from-the-recycle-bin)
* \[Low] [Rare security product signed executable executed in the network](broken://spaces/5O67gr80iLneA56jiuO2/pages/rqUvjRNmfKlRtw9aoI5o)
* \[Low] [Rare service DLL was added to the registry](broken://spaces/5O67gr80iLneA56jiuO2/pages/3gioHInb6nkE0WMKOOhc)
* \[Low] [Rundll32.exe executes a rare unsigned module](broken://spaces/5O67gr80iLneA56jiuO2/pages/2b01ZHf54Vs8XB2Vo17o)
* \[Low] [Scheduled Task hidden by registry modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/FQH0tf8N1Tkg7IeRrSCs)
* \[Low] [Scripting engine connected to a rare external host](broken://spaces/5O67gr80iLneA56jiuO2/pages/JqxxlP5K1nPJ3mE9qHdW)
  * \[Low] Scripting engine with a modified image name connected to a rare external host - Modified Metadata
* \[Low] [Setuid and Setgid file bit manipulation](broken://spaces/5O67gr80iLneA56jiuO2/pages/7V1soEueoForJXnuKsB2)
* \[Low] [Short-lived user account](broken://spaces/5O67gr80iLneA56jiuO2/pages/pJR8XJVpJIE5g9MbFeSa)
* \[Low] [Suspicious .NET process spawns csc.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-net-process-spawns-csc-exe)
* \[Low] [Suspicious AMSI DLL load location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-amsi-dll-load-location)
* \[Low] [Suspicious DotNet log file created](broken://spaces/5O67gr80iLneA56jiuO2/pages/9rHCaqwHsXg42XuLBOWG)
* \[Low] [Suspicious SSH Downgrade](broken://spaces/5O67gr80iLneA56jiuO2/pages/0KJXcBE06hKCYbZOB7Pb)
* \[Low] [Suspicious data encryption](broken://spaces/5O67gr80iLneA56jiuO2/pages/PrfALVOB0N5wqybYfGPk)
* \[Low] [Suspicious disablement of the Windows Firewall](broken://spaces/5O67gr80iLneA56jiuO2/pages/jPEjHoisurpEjdi2xkcQ)
* \[Low] [Svchost.exe loads a rare unsigned module](broken://spaces/5O67gr80iLneA56jiuO2/pages/rGn0Hg6RBfU42jsOVacI)
* \[Low] [Tampering with the Windows System Restore configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-the-windows-system-restore-configuration)
* \[Low] [The Linux system firewall was disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/SlFEQ1tmWAuEkyWGCgt5)
* \[Low] [Uncommon AppleScript containing a potential obfuscation technique was executed](broken://spaces/5O67gr80iLneA56jiuO2/pages/Qaf96BnjzkubElZBGroD)
* \[Informational] [Uncommon Launch Agent persistency was registered or modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/26DB4X1b3TsCzkguvnBL)
  * \[Low] Uncommon Launch Agent persistency was registered or modified by a non validly signed process - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified by an unsigned process - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified with an uncommon path containing a known vendor name - Modified Metadata
  * \[Low] Uncommon Launch Agent persistency was registered or modified with an unusual persistency executable path - Modified Metadata
* \[Informational] [Uncommon Launch Daemon persistency was registered or modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/t1d7nQeolFJi6V3iOPdn)
  * \[Low] Uncommon Launch Daemon persistency was registered or modified by a non validly signed process - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified by an unsigned process - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified with an uncommon path containing a known vendor name - Modified Metadata
  * \[Low] Uncommon Launch Daemon persistency was registered or modified with an unusual persistency executable path - Modified Metadata
* \[Informational] [Uncommon Linux remote shell command execution](broken://spaces/5O67gr80iLneA56jiuO2/pages/iaQxmJMCosumpMYa8Qgw)
  * \[Low] Uncommon Linux remote shell command execution disabling firewall - Modified Metadata
  * \[Informational] Uncommon Linux remote shell command execution, possibly granting file execution permissions - Modified Metadata
* \[Low] [Uncommon NtWriteVirtualMemoryRemote API invocation with a PE header buffer](broken://spaces/5O67gr80iLneA56jiuO2/pages/NiSB22FW6IsT4LD3URXH)
* \[Low] [Uncommon attempt to clear shell history](broken://spaces/5O67gr80iLneA56jiuO2/pages/OBzxmVGNaaLhZttWfnNF)
* \[Low] [Uncommon driver loaded](broken://spaces/5O67gr80iLneA56jiuO2/pages/tGXhgGJ1Mts6abnl92EM)
* \[Low] [Uncommon execution of ODBCConf](broken://spaces/5O67gr80iLneA56jiuO2/pages/on2irDawCVDsaxjY6jPo)
* \[Informational] [Uncommon login item persistency was registered or modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/aae1FMFiiwvgYPuOVnS7)
  * \[Low] Uncommon login item persistency was registered or modified by an invalidly signed actor process - Modified Metadata
  * \[Low] Uncommon login item persistency was registered or modified by an invalidly signed causality process - Modified Metadata
* \[Informational] [Uncommon macOS shell command execution](broken://spaces/5O67gr80iLneA56jiuO2/pages/rB71QeyrN9Dwq7vADdGB)
  * \[Low] Uncommon macOS shell command execution from an unsigned process - Modified Metadata
  * \[Low] Uncommon macOS shell command execution, possibly granting file execution permissions - Modified Metadata
* \[Low] [Uncommon msiexec execution of an arbitrary file from a remote location](broken://spaces/5O67gr80iLneA56jiuO2/pages/sfAe7vzxKSi3BNYOuQUS)
* \[Low] [Unsigned and unpopular process performed a DLL injection](broken://spaces/5O67gr80iLneA56jiuO2/pages/xMJSMMWcR0tjiEGcBtx5)
* \[Low] [Unusual Encrypting File System Remote call (EFSRPC) to domain controller](broken://spaces/5O67gr80iLneA56jiuO2/pages/qY49yC3FUArpCy2qBjQL)
* \[Low] [Unusual Lolbins Process Spawned by InstallUtil.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/oBjHb1J15nQ9hKjVS5Ua)
* \[Low] [Unusual Netsh PortProxy rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/deCBw1C1Qlf280j2jRYh)
* \[Low] [User set insecure CA registry setting for global SANs](broken://spaces/5O67gr80iLneA56jiuO2/pages/CMZp3hWfPm1SkCIPE8Pe)
* \[Low] [Wscript/Cscript loads .NET DLLs](broken://spaces/5O67gr80iLneA56jiuO2/pages/BdtXWo1Niq7WPzyecyZO)
* \[Informational] [A LOLBIN was copied to a different location](broken://spaces/5O67gr80iLneA56jiuO2/pages/kIECYjiUDkTFNm1SQF25)
* \[Informational] [A Service Principal was removed from Azure](broken://spaces/5O67gr80iLneA56jiuO2/pages/I5RQBMjp4uMlv086GC4l)
* \[Informational] [A browser was opened in private mode](broken://spaces/5O67gr80iLneA56jiuO2/pages/xlaHNAQH6e1W3u2BpXyA)
* \[Informational] [A cloud identity created or modified a security group](broken://spaces/5O67gr80iLneA56jiuO2/pages/BcRXNYsA3FRaZILyI5ej)
* \[Informational] [A cloud storage configuration was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/uj1dy1QZYgIMPofHOD18)
* \[Informational] [A process is masquerading as a common Microsoft product](broken://spaces/5O67gr80iLneA56jiuO2/pages/KdhDC7yOSTS9tvr2Geex)
* \[Informational] [A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process](broken://spaces/5O67gr80iLneA56jiuO2/pages/rUYnaWDDSdUk8h1pmDAe)
* \[Informational] [A third-party utility was copied to a different location](broken://spaces/5O67gr80iLneA56jiuO2/pages/fA2aH0qnpgmNZShKfeqM)
* \[Informational] [A user added a Windows firewall rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/4Ltv7COQLe9GY4TsG6WZ)
* \[Informational] [A user logged in at an unusual time via VPN](broken://spaces/5O67gr80iLneA56jiuO2/pages/30uV9aLupDnjzPiw1GCo)
* \[Informational] [A user modified an Okta network zone](broken://spaces/5O67gr80iLneA56jiuO2/pages/tBJn3OOW7gzKmzkkC8qd)
* \[Informational] [A user modified an Okta policy rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/3x1C2mdGQP1nhAZmRK9b)
* \[Informational] [AI safeguards deletion attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/Ftxdp67QtU4t48M5vTzT)
* \[Informational] [AI safeguards were modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/piwashgLj7FNYAfL8avz)
* \[Informational] [AWS CloudTrail has been stopped](broken://spaces/5O67gr80iLneA56jiuO2/pages/JQaQ7AqEBoyX42FEflPJ)
* \[Informational] [AWS CloudWatch log group deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/I9LpPk7UhrlzTpJEWfno)
* \[Informational] [AWS CloudWatch log stream deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/iuzVvxYX2t9p7S7QIiul)
* \[Informational] [AWS Config Recorder stopped](broken://spaces/5O67gr80iLneA56jiuO2/pages/iv9wjQTvf5WAIgcVlYKp)
* \[Informational] [AWS Flow Logs deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/GmRWVcgajM2m9duSszf5)
* \[Informational] [AWS S3 bucket data retention policy change through S3 Lifecycle rule](broken://spaces/5O67gr80iLneA56jiuO2/pages/39GCbdNqMICpsax9ZdUu)
* \[Informational] [AWS SecurityHub findings were modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/rvX6IfH01aKqQ6XuAiRU)
* \[Informational] [AWS config resource deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/dYxsaqjVZ8oep0JeNnVF)
* \[Informational] [AWS network ACL rule deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/7L9HA5CRgC7nS0E461VN)
* \[Informational] [AWS web ACL deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/BTY3O2xeyClzjiuEpe64)
* \[Informational] [Administrator obtains access rights to a file using icacls.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/administrator-obtains-access-rights-to-a-file-using-icacls-exe)
* \[Informational] [An AWS GuardDuty IP set was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/TJ7YtiZA8GqPeEHFdpIe)
* \[Informational] [An AWS SAML provider was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/8utSA0Yydvt4Sc1tjCE1)
* \[Informational] [An Azure Firewall rule collection group was modified or deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/bQAL9PFK2yGGpnKLHNZB)
* \[Informational] [An Azure Firewall was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/pr54VnlW8hqPx2CjGKIz)
* \[Informational] [An Azure Network Security Group was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/sTTLaZse6YOOKt6NRtpQ)
* \[Informational] [An Azure Point-to-Site VPN was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/OLNelFs8S6hkHSJNJcLA)
* \[Informational] [An Azure Suppression Rule was created](broken://spaces/5O67gr80iLneA56jiuO2/pages/A6ePHFL8Excb8MTtUhzn)
* \[Informational] [An Azure VPN Connection was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/DSbkWtRZWIYQuNWRrHSA)
* \[Informational] [An Azure firewall rule group was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/OwAsyuF8bUnaQXPZWCdx)
* \[Informational] [An app was added to the Google Workspace trusted OAuth apps list](broken://spaces/5O67gr80iLneA56jiuO2/pages/MtiWPkAzNiSFsJKIi3to)
* \[Informational] [An app was removed from a blocked list in Google Workspace](broken://spaces/5O67gr80iLneA56jiuO2/pages/7THaDsB7XNHjPHQa48gj)
* \[Informational] [An unusual cloud identity was granted permissions to a BigQuery resource](broken://spaces/5O67gr80iLneA56jiuO2/pages/nRkUxP37b1FDHgxmgYFq)
* \[Informational] [Authentication Attempt From a Dormant Account](broken://spaces/5O67gr80iLneA56jiuO2/pages/jWDLsBdqEipeqN5rn1Pm)
* \[Informational] [Azure Automation Runbook Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/ljLTtGeh60XAnIYpY5Ze)
* \[Informational] [Azure Kubernetes events were deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/tYonJCkwkT9ehst78TQB)
* \[Informational] [Azure Monitor alert rule deleted](broken://spaces/5O67gr80iLneA56jiuO2/pages/Egfb2WRbq8npsy8UzxTo)
* \[Informational] [Azure Resource Group Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/5ks8RpMvCIfcIVnim4nE)
* \[Informational] [Azure Temporary Access Pass (TAP) registered to an account](broken://spaces/5O67gr80iLneA56jiuO2/pages/ufoGLIvcmREXrvYk8ZPI)
* \[Informational] [Azure VM extension abuse attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/KIUIvMKNLgHzsRHTXMCN)
* \[Informational] [Azure application URI modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/YinCw1D8UvKECfEoqYnz)
* \[Informational] [Azure application credentials added](broken://spaces/5O67gr80iLneA56jiuO2/pages/hdyTFopBdHQ0po3XclZW)
* \[Informational] [Azure application removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/85He78vpEAWyvxJMwO3O)
* \[Informational] [Azure conditional access policy creation or modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/aTuW2fAFiV1DKah7yeVA)
* \[Informational] [Azure device code authentication flow used](broken://spaces/5O67gr80iLneA56jiuO2/pages/WJLuwR7QJqUQct8mPrx0)
* \[Informational] [Azure diagnostic configuration deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/MBdecy2MXGoz3AVxos8Y)
* \[Informational] [Azure mailbox rule creation](broken://spaces/5O67gr80iLneA56jiuO2/pages/OlT1TQ6BOLrBBZSOJ5wr)
* \[Informational] [Azure route table creation or modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/m6spGrxr0BFAjoxcHU1q)
* \[Informational] [Azure storage account blob anonymous access is enabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/BDwEV4YwvON7MQ6gR0gB)
* \[Informational] [Azure storage account was publicly shared](broken://spaces/5O67gr80iLneA56jiuO2/pages/p3FZdRA8EfzZTh0qSfuU)
* \[Informational] [Base64 decoding using the base64 utility](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/base64-decoding-using-the-base64-utility)
* \[Informational] [BitLocker key retrieval](broken://spaces/5O67gr80iLneA56jiuO2/pages/iUfRR5ujWkf0c1PNxcT6)
* \[Informational] [Browser downloads an .hta or .application file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/browser-downloads-an-hta-or-application-file)
* \[Informational] [Changing permissions or ownership of a file or folder](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/changing-permissions-or-ownership-of-a-file-or-folder)
* \[Informational] [Chrome OS Remote Access policy was modified in Google Workspace](broken://spaces/5O67gr80iLneA56jiuO2/pages/aHSCKkIL65Qx7b7jUZYP)
* \[Informational] [Chrome launched in Incognito mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/chrome-launched-in-incognito-mode)
* \[Informational] [Clear event logging policy using auditpol.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clear-event-logging-policy-using-auditpol-exe)
* \[Informational] [Clearing logs by copying /dev/null to a log file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clearing-logs-by-copying-dev-null-to-a-log-file)
* \[Informational] [Clearing logs by executing cat /dev/null](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/clearing-logs-by-executing-cat-dev-null)
* \[Informational] [Cloud AI agent was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/iZ252coIwDiFLkRMtjQM)
* \[Informational] [Cloud Organizational policy was created or modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/GRVAvt9NsGwWEUVLlaQK)
* \[Informational] [Cloud Watch alarm deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/kRKuqOevlP3bI6PWhSdw)
* \[Informational] [Cloud compute volume creation attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/ytprJxAI2CYEOVnb0Rve)
* \[Informational] [Cloud instance creation attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/1GA62FTAJOgDpyQ4z3D3)
* \[Informational] [Cloud instance deletion attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/CPu2SvzQUgyOGAqLgnsA)
* \[Informational] [Cloud resource logging was disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/3eFwuP49gE5NuIhflBDn)
* \[Informational] [Cloud snapshot created or modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/M0nkstxTNo9GngI5ZAXE)
* \[Informational] [CloudTrail logging deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/LBsrjQpAGfkaqBl4c0v4)
* \[Informational] [Common Apple process name missing Apple digital signature](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-apple-process-name-missing-apple-digital-signature)
* \[Informational] [Common Mozilla process name missing Mozilla digital certificate](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/common-mozilla-process-name-missing-mozilla-digital-certificate)
* \[Informational] [Common third-party software name masquerading](broken://spaces/5O67gr80iLneA56jiuO2/pages/2WSikzdMrp0XxCTQzkAe)
* \[Informational] [Commonly abused process executed with obfuscated characters](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-process-executed-with-obfuscated-characters)
* \[Informational] [Commonly abused process spawns out of rundll32.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/commonly-abused-process-spawns-out-of-rundll32-exe)
* \[Informational] [Compiled HTML (help file) makes network connections](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compiled-html-help-file-makes-network-connections)
* \[Informational] [Compiler process started by an Office process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/compiler-process-started-by-an-office-process)
* \[Informational] [Compute activity in dormant cloud region](broken://spaces/5O67gr80iLneA56jiuO2/pages/IYHXMGroDMLsCdAX3Hfq)
* \[Informational] [Data Sharing between GCP and Google Workspace was disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/26sxT9cFNaqPG0ddqRn1)
* \[Informational] [Data destruction using sdelete.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/data-destruction-using-sdelete-exe)
* \[Informational] [Data encryption was disabled](broken://spaces/5O67gr80iLneA56jiuO2/pages/EcKydPJPAnmVlzbiDndN)
* \[Informational] [Deletion of AD CS certificate database entries](broken://spaces/5O67gr80iLneA56jiuO2/pages/Ntfa2bNDwAVbGZDjNaxf)
* \[Informational] [Device Registration Policy modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/IyTnpBeCpS18W2X3fK7D)
* \[Informational] [Disable AWS audit logs through Event Selectors](broken://spaces/5O67gr80iLneA56jiuO2/pages/Nwq9WcH3AT2vDBSuugC9)
* \[Informational] [Disable outlook security via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/disable-outlook-security-via-registry)
* \[Informational] [Disabling Windows Defender via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/disabling-windows-defender-via-registry)
* \[Informational] [Driver written to a temporary directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/driver-written-to-a-temporary-directory)
* \[Informational] [EBS volume attachment attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/7oqAHndgweOAzA8bZ5wn)
* \[Informational] [EBS volume detachment attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/fl1ZI7lt1Yb1zceKZYES)
* \[Informational] [Evasion using time-based properties](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/evasion-using-time-based-properties)
* \[Informational] [Executable moved to Windows system folder](broken://spaces/5O67gr80iLneA56jiuO2/pages/alXbrCHIlfaJe9LeOCm9)
* \[Informational] [Execution of WSL Distro](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-wsl-distro)
* \[Informational] [Execution of commonly abused AutoIT script](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-commonly-abused-autoit-script)
* \[Informational] [Execution of masqueraded third-party utility](broken://spaces/5O67gr80iLneA56jiuO2/pages/m91j6rja1Vrk66aRR3IJ)
* \[Informational] [Execution of regsvcs/regasm with uncommon paths](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/execution-of-regsvcs-regasm-with-uncommon-paths)
* \[Informational] [Execution of renamed lolbin](broken://spaces/5O67gr80iLneA56jiuO2/pages/8NqBBwm3APNGKS6oaeC7)
* \[Informational] [Failed Login For Locked-Out Account](broken://spaces/5O67gr80iLneA56jiuO2/pages/20nELZCffvkqm6w7LCa6)
* \[Informational] [File renamed to have a script extension](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/file-renamed-to-have-a-script-extension)
* \[Informational] [File timestamp tampering](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/file-timestamp-tampering)
* \[Informational] [Fltmc.exe used to unload filter driver](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/fltmc-exe-used-to-unload-filter-driver)
* \[Informational] [GCP Firewall Rule Modification](broken://spaces/5O67gr80iLneA56jiuO2/pages/wuWZgfK4mXmAC8HTOlfs)
* \[Informational] [GCP Firewall Rule creation](broken://spaces/5O67gr80iLneA56jiuO2/pages/9psglCgEh9Jl8a9IqdnT)
* \[Informational] [GCP Logging Bucket Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/U3J3w2oevlZy1ZuBSqRq)
* \[Informational] [GCP VPC Firewall Rule Deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/uBxDXYCTreJL2xIC1g7D)
* \[Informational] [GCP logging sink deletion](broken://spaces/5O67gr80iLneA56jiuO2/pages/pMg7tMS99ramleaEp5qk)
* \[Informational] [Globally uncommon IP address connection from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/g2Sv46bOTn4pVmDD3qjf)
* \[Informational] [Globally uncommon high entropy module was loaded](broken://spaces/5O67gr80iLneA56jiuO2/pages/Da4t7OjfXNUNUncbRW65)
* \[Informational] [Globally uncommon injection from a signed process](broken://spaces/5O67gr80iLneA56jiuO2/pages/UYBrgRaAoNas5ot2lldQ)
* \[Informational] [Hidden Attribute was added to a file using attrib.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/MJGSY0Pr6keV6NOgRwHQ)
* \[Informational] [Hidden directory creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hidden-directory-creation)
* \[Informational] [Hidden file and directory creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/hidden-file-and-directory-creation)
* \[Informational] [ISO mounted manually](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/iso-mounted-manually)
* \[Informational] [Indicator blocking](broken://spaces/5O67gr80iLneA56jiuO2/pages/oxbc0QMrtluZfw9X55Cg)
* \[Informational] [Injection into ping.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/injection-into-ping-exe)
* \[Informational] [Injection into rundll32.exe](broken://spaces/5O67gr80iLneA56jiuO2/pages/iv3rDw1oWmuUicnyMOPo)
* \[Informational] [Internet Explorer security settings modification](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/internet-explorer-security-settings-modification)
* \[Informational] [Iptables configuration command was executed](broken://spaces/5O67gr80iLneA56jiuO2/pages/KWwXz601nX89SUz2zmjG)
* \[Informational] [LOLBAS executable injects into another process](broken://spaces/5O67gr80iLneA56jiuO2/pages/2PCzplov6byg9u8u3AUf)
* \[Informational] [Log deletion in known log file directories](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/log-deletion-in-known-log-file-directories)
* \[Informational] [Log deletion using the truncate command](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/log-deletion-using-the-truncate-command)
* \[Informational] [Log deletion via command-line tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/log-deletion-via-command-line-tool)
* \[Informational] [Login by a dormant user](broken://spaces/5O67gr80iLneA56jiuO2/pages/wnRViyyHYvsH9wMz8Q36)
* \[Informational] [MFA was disabled for a Google Workspace user](broken://spaces/5O67gr80iLneA56jiuO2/pages/l1loJb0y7kOUFNmVeb1h)
* \[Informational] [MSBuild execution](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/msbuild-execution)
* \[Informational] [MSI accessed a web page running a server-side script](broken://spaces/5O67gr80iLneA56jiuO2/pages/MsFR2RMKHuhrKbghFEUr)
* \[Informational] [MacOS firewall manipulation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/macos-firewall-manipulation)
* \[Informational] [Manipulation of Crypto Subject Interface Package (SIP) Provider](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-crypto-subject-interface-package-sip-provider)
* \[Informational] [Manipulation of Windows Defender configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-windows-defender-configuration)
* \[Informational] [Manipulation of Windows Event Log auto-backup via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-windows-event-log-auto-backup-via-registry)
* \[Informational] [Manipulation of service imagepath configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/manipulation-of-service-imagepath-configuration)
* \[Informational] [Microsoft 365 DLP policy disabled or removed](broken://spaces/5O67gr80iLneA56jiuO2/pages/aeFa6YlzsXjVUGohUGPt)
* \[Informational] [Microsoft HTML Application Host spawns from CMD or PowerShell](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-html-application-host-spawns-from-cmd-or-powershell)
* \[Informational] [Microsoft HTML Application Host spawns from Explorer.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/microsoft-html-application-host-spawns-from-explorer-exe)
* \[Informational] [Microsoft Teams application setup policy was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/xPXuYWFg0sIp42ulHcmM)
* \[Informational] [Microsoft Teams external communication policy was modified](broken://spaces/5O67gr80iLneA56jiuO2/pages/ucv4SCC8YfKowUqtBbMJ)
* \[Informational] [Modification of PAM](broken://spaces/5O67gr80iLneA56jiuO2/pages/6RwdDdaNGb8KggMFNRGX)
* \[Informational] [Modification of Windows boot configuration using bcdedit.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/modification-of-windows-boot-configuration-using-bcdedit-exe)
* \[Informational] [Modification of the AD FS IdentityServer configuration file](broken://spaces/5O67gr80iLneA56jiuO2/pages/GhBCn8uewMXvrQVGXGNC)
* \[Informational] [Multi region enumeration activity](broken://spaces/5O67gr80iLneA56jiuO2/pages/k8SNhl4X4lQpG2kdqEYF)
* \[Informational] [NTLM Relay](broken://spaces/5O67gr80iLneA56jiuO2/pages/W7nHjf6X2asxsMFqC3aN)
* \[Informational] [Netsh.exe modifies allowed firewall port/program lists](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/netsh-exe-modifies-allowed-firewall-port-program-lists)
* \[Informational] [New certificate added to the trusted root store](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/new-certificate-added-to-the-trusted-root-store)
* \[Informational] [Permissive file privileges were granted](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/permissive-file-privileges-were-granted)
* \[Informational] [Ping executed with loopback address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ping-executed-with-loopback-address)
* \[Informational] [Ping to a known external IP address](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/ping-to-a-known-external-ip-address)
* \[Informational] [Ping to localhost from an uncommon, unsigned parent process](broken://spaces/5O67gr80iLneA56jiuO2/pages/6VFeCP7EaDu0CMvd4ZCG)
* \[Informational] [Possible DLL Hijack into a Microsoft process](broken://spaces/5O67gr80iLneA56jiuO2/pages/2Ipb5aDktOMGeU9x1eaK)
* \[Informational] [Possible authentication coercion](broken://spaces/5O67gr80iLneA56jiuO2/pages/jzhP6zwYRM6RvZP0FPhW)
* \[Informational] [Possible binary padding using dd](broken://spaces/5O67gr80iLneA56jiuO2/pages/Vhqr2De4I4NodOOFW2Yc)
* \[Informational] [Possible data obfuscation](broken://spaces/5O67gr80iLneA56jiuO2/pages/79dIpsMpmNE33oyj13qi)
* \[Informational] [Possible log destruction using the dd command](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/possible-log-destruction-using-the-dd-command)
* \[Informational] [Potential DCSync by an unusual user](broken://spaces/5O67gr80iLneA56jiuO2/pages/vg4q844DjRrurDQ2czEA)
* \[Informational] [Potential NTLM Relay Attack](broken://spaces/5O67gr80iLneA56jiuO2/pages/J7mMoHF0XEbH8H9J6PoP)
* \[Informational] [Potential NTLM Relay Attack against a Microsoft Configuration Manager Site Server](broken://spaces/5O67gr80iLneA56jiuO2/pages/9mOtnC9T7S1ooYl9WWuN)
* \[Informational] [PowerShell is used to execute a CPL file](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-is-used-to-execute-a-cpl-file)
* \[Informational] [PowerShell is used to modify a timestamp](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/powershell-is-used-to-modify-a-timestamp)
* \[Informational] [Punycode characters detected in URL(s)](broken://spaces/5O67gr80iLneA56jiuO2/pages/7g9TaqisTcbSv2DcVigT)
* \[Informational] [Rare signature signed executable executed in the network](broken://spaces/5O67gr80iLneA56jiuO2/pages/8mbVUs0PqzuwQx2CVGMe)
* \[Informational] [Registration of Uncommon .NET Services and/or Assemblies](broken://spaces/5O67gr80iLneA56jiuO2/pages/kz1tTp6XTTN0fKyltCrL)
* \[Informational] [Removal of an Azure Owner from an Application or Service Principal](broken://spaces/5O67gr80iLneA56jiuO2/pages/GuU4OJrD4sClOzauIBKL)
* \[Informational] [Root certificate installed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/root-certificate-installed)
* \[Informational] [Root certificate installed](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/root-certificate-installed)
* \[Informational] [Rundll32 loads a known abused DLL](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/rundll32-loads-a-known-abused-dll)
* \[Informational] [SELinux was set to permissive mode](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/selinux-was-set-to-permissive-mode)
* \[Informational] [Scripting engine creates an Alternate Data Stream (ADS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/scripting-engine-creates-an-alternate-data-stream-ads)
* \[Informational] [Security object deletion in Google Workspace Admin Console](broken://spaces/5O67gr80iLneA56jiuO2/pages/hJ9c8j8qbWM51dVP5Q5k)
* \[Informational] [Security services stopped](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/security-services-stopped)
* \[Informational] [Security tools detection attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/QfEvoavKsCDiUBRsd3YY)
* \[Informational] [Shell binary copied to another location](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/shell-binary-copied-to-another-location)
* \[Informational] [Short-lived Azure AD user account](broken://spaces/5O67gr80iLneA56jiuO2/pages/qsuI4njg8NoNdxQte41r)
* \[Informational] [Signed process performed an unpopular DLL injection](broken://spaces/5O67gr80iLneA56jiuO2/pages/Pl3CmVG7fXThKkezGDnV)
* \[Informational] [Signed process performed an unpopular injection](broken://spaces/5O67gr80iLneA56jiuO2/pages/G0QBxRxQN7DCjdjT8YeJ)
* \[Informational] [SmartScreen disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/smartscreen-disabled-via-registry)
* \[Informational] [Space after filename](broken://spaces/5O67gr80iLneA56jiuO2/pages/Mbwg3Hb9CHxS0jvbiHjv)
* \[Informational] [Space after filename creation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/space-after-filename-creation)
* \[Informational] [Suspicious AMSI decode attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/Sf561vqBi9KrWyUY62py)
* \[Informational] [Suspicious activity on logging bucket](broken://spaces/5O67gr80iLneA56jiuO2/pages/PI0YBjguCLPAfsZJCuDy)
* \[Informational] [Suspicious process accessed a site masquerading as Google](broken://spaces/5O67gr80iLneA56jiuO2/pages/cMHO5geRGNz0pEr2YiHJ)
* \[Informational] [Suspicious process execution from tmp folder](broken://spaces/5O67gr80iLneA56jiuO2/pages/QU4utpk3xQoknNXwb3Z5)
* \[Informational] [Suspicious usage of cytool.exe](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/suspicious-usage-of-cytool-exe)
* \[Informational] [SyncAppvPublishingServer used to run PowerShell code](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/syncappvpublishingserver-used-to-run-powershell-code)
* \[Informational] [Tampering with Internet Explorer Protected Mode configuration](broken://spaces/5O67gr80iLneA56jiuO2/pages/uRv3jBm0dE6f24rGyxqF)
* \[Informational] [Tampering with Windows Control Panel configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-windows-control-panel-configuration)
* \[Informational] [Tampering with Windows certificate blocking configuration](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/tampering-with-windows-certificate-blocking-configuration)
* \[Informational] [Tampering with the Windows User Account Controls (UAC) configuration](broken://spaces/5O67gr80iLneA56jiuO2/pages/WBeUyc2nli78J4zlti4x)
* \[Informational] [The scripting engine executed code from an Alternate Data Stream (ADS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/the-scripting-engine-executed-code-from-an-alternate-data-stream-ads)
* \[Informational] [Uncommon DotNet module load relationship](broken://spaces/5O67gr80iLneA56jiuO2/pages/l1mZYJdnlgVNYLMGy19P)
* \[Informational] [Uncommon kernel module load](broken://spaces/5O67gr80iLneA56jiuO2/pages/li2SEj4WgT0VzXmkw4aB)
* \[Informational] [Unknown DLL was added to the AD FS Global Assembly Cache path](broken://spaces/5O67gr80iLneA56jiuO2/pages/oaEKDYPirGHTX48TPplk)
* \[Informational] [Unpopular rsync process execution](broken://spaces/5O67gr80iLneA56jiuO2/pages/KiJYXoeN8XeRlsmA8xAx)
* \[Informational] [Unsigned DLL Hijack into a Microsoft process](broken://spaces/5O67gr80iLneA56jiuO2/pages/TkoEwvociP3kUS1kQjLn)
* \[Informational] [Unsigned DLL Side-Loading](broken://spaces/5O67gr80iLneA56jiuO2/pages/DjN4kfA5jIUehrUe4GGt)
* \[Informational] [Unsigned process creates an Alternate Data Stream (ADS)](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-creates-an-alternate-data-stream-ads)
* \[Informational] [Unsigned process injects code into a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-injects-code-into-a-process)
* \[Informational] [Unsigned process running from a temporary directory](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/unsigned-process-running-from-a-temporary-directory)
* \[Informational] [Unusual Conditional Access operation for an identity](broken://spaces/5O67gr80iLneA56jiuO2/pages/xPDUQJihHpHmg94ic6zx)
* \[Informational] [Unusual cloud identity impersonation](broken://spaces/5O67gr80iLneA56jiuO2/pages/fc6D60BWt10V6wFOQhqo)
* \[Informational] [Unusual use of a 'SysInternals' tool](broken://spaces/5O67gr80iLneA56jiuO2/pages/UGnD0eTumhh2iu2ZrVPC)
* \[Informational] [Unusual user-agent for a cloud identity](broken://spaces/5O67gr80iLneA56jiuO2/pages/kGYJaHA9ytKAfyASx5Wt)
* \[Informational] [Usage of tracing tool](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/usage-of-tracing-tool)
* \[Informational] [User account flagged as hidden](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/user-account-flagged-as-hidden)
* \[Informational] [User added SID History to an account](broken://spaces/5O67gr80iLneA56jiuO2/pages/WAq6bnqlwGCDxgCpSLWi)
* \[Informational] [User moved Exchange sent messages to deleted items](broken://spaces/5O67gr80iLneA56jiuO2/pages/mvVnAoQAiBx68ZofHese)
* \[Informational] [VM Detection attempt](broken://spaces/5O67gr80iLneA56jiuO2/pages/1qD0fDa7n7jiyHa5dPLk)
* \[Informational] [VPN login by a dormant user](broken://spaces/5O67gr80iLneA56jiuO2/pages/NdgeeROk4TVSvqVbxK0N)
* \[Informational] [WMI terminated a process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wmi-terminated-a-process)
* \[Informational] [WSL Feature Installation](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/wsl-feature-installation)
* \[Informational] [Weakly-Encrypted Kerberos TGT Response](broken://spaces/5O67gr80iLneA56jiuO2/pages/WiZYV2ff68ZdqSPfjQYd)
* \[Informational] [Windows 10 Developer Mode enabled](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-10-developer-mode-enabled)
* \[Informational] [Windows Firewall disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-firewall-disabled-via-registry)
* \[Informational] [Windows Firewall notifications disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-firewall-notifications-disabled-via-registry)
* \[Informational] [Windows PowerShell Logging being disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-powershell-logging-being-disabled-via-registry)
* \[Informational] [Windows Registry Editor being disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-registry-editor-being-disabled-via-registry)
* \[Informational] [Windows Security audit log was cleared](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-security-audit-log-was-cleared)
* \[Informational] [Windows Task Manager being disabled via Registry](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-task-manager-being-disabled-via-registry)
* \[Informational] [Windows event logs were cleared with PowerShell](broken://spaces/5O67gr80iLneA56jiuO2/pages/qn3kjdzij4sgXA4tr4wo)
* \[Informational] [Windows process masquerading by an unsigned process](https://app.gitbook.com/o/r4DIGbR5VLvkZy3gAYsu/s/5O67gr80iLneA56jiuO2/alerts-by-name/windows-process-masquerading-by-an-unsigned-process)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/cortex-analytics-content-releases/cortex-analytics-content-release-notes/2026-08-26.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
