Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ A Backup vault policy was modified added +22 −0
analytics/a-backup-vault-policy-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A browser extension was installed or loaded in an uncommon way added +62 −0
analytics/a-browser-extension-was-installed-or-loaded-in-an-uncommon-wayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A browser was opened in private mode added +23 −0
analytics/a-browser-was-opened-in-private-modeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Cloud DB instance was exported to an unknown destination added +22 −0
analytics/a-cloud-db-instance-was-exported-to-an-unknown-destinationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud function was created with an unusual runtime added +63 −0
analytics/a-cloud-function-was-created-with-an-unusual-runtimeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity created or modified a security group added +51 −0
analytics/a-cloud-identity-created-or-modified-a-security-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity executed an API call from an unusual country added +117 −0
analytics/a-cloud-identity-executed-an-api-call-from-an-unusual-countryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity had escalated its permissions added +82 −0
analytics/a-cloud-identity-had-escalated-its-permissionsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity invoked IAM related persistence operations added +56 −0
analytics/a-cloud-identity-invoked-iam-related-persistence-operationsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity performed multiple unusual activities added +38 −0
analytics/a-cloud-identity-performed-multiple-unusual-activitiesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud identity started a Cloud Shell session added +22 −0
analytics/a-cloud-identity-started-a-cloud-shell-sessionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud instance was stopped added +24 −0
analytics/a-cloud-instance-was-stoppedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud snapshot of AWS database or storage was modified or shared added +49 −0
analytics/a-cloud-snapshot-of-aws-database-or-storage-was-modified-or-sharedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud storage configuration was modified added +24 −0
analytics/a-cloud-storage-configuration-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A cloud storage object was copied to a foreign cloud account added +50 −0
analytics/a-cloud-storage-object-was-copied-to-a-foreign-cloud-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Command Line Interface (CLI) command was executed from a GCP serverless compute service added +90 −0
analytics/a-command-line-interface-cli-command-was-executed-from-a-gcp-serverless-compute-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Command Line Interface (CLI) command was executed from an AWS serverless compute service added +64 −0
analytics/a-command-line-interface-cli-command-was-executed-from-an-aws-serverless-compute-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A commonly abused process connected to a rare cloud resource added +64 −0
analytics/a-commonly-abused-process-connected-to-a-rare-cloud-resourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A commonly abused process connected to a rare external host added +62 −0
analytics/a-commonly-abused-process-connected-to-a-rare-external-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A compiled HTML help file wrote a script file to the disk added +22 −0
analytics/a-compiled-html-help-file-wrote-a-script-file-to-the-diskRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A compressed file was exfiltrated over SSH added +36 −0
analytics/a-compressed-file-was-exfiltrated-over-sshRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A compromised process accessed a rare cloud resource added +62 −0
analytics/a-compromised-process-accessed-a-rare-cloud-resourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A compromised process accessed a rare external host added +62 −0
analytics/a-compromised-process-accessed-a-rare-external-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A compute-attached identity executed API calls outside the instance's region added +122 −0
analytics/a-compute-attached-identity-executed-api-calls-outside-the-instance-s-regionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A computer account was promoted to DC added +25 −0
analytics/a-computer-account-was-promoted-to-dcRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A contained executable from a mounted share initiated a suspicious outbound network connection added +36 −0
analytics/a-contained-executable-from-a-mounted-share-initiated-a-suspicious-outbound-network-connectionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A contained executable was executed by an unusual process added +70 −0
analytics/a-contained-executable-was-executed-by-an-unusual-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A contained process attempted to escape using the 'notify on release' feature added +36 −0
analytics/a-contained-process-attempted-to-escape-using-the-notify-on-release-featureRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A container registry was created or deleted added +25 −0
analytics/a-container-registry-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A disabled user attempted to authenticate via SSO added +42 −0
analytics/a-disabled-user-attempted-to-authenticate-via-ssoRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A disabled user attempted to log in to a VPN added +37 −0
analytics/a-disabled-user-attempted-to-log-in-to-a-vpnRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A disabled user attempted to log in added +36 −0
analytics/a-disabled-user-attempted-to-log-inRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A domain was added to the trusted domains list added +52 −0
analytics/a-domain-was-added-to-the-trusted-domains-listRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A GCP Cloud SQL DB instance was exported from a production account added +22 −0
analytics/a-gcp-cloud-sql-db-instance-was-exported-from-a-production-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A GCP service account was delegated domain-wide authority in Google Workspace added +36 −0
analytics/a-gcp-service-account-was-delegated-domain-wide-authority-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace identity created, assigned or modified a role added +62 −0
analytics/a-google-workspace-identity-created-assigned-or-modified-a-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace identity performed an unusual admin console activity added +36 −0
analytics/a-google-workspace-identity-performed-an-unusual-admin-console-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace identity used the security investigation tool added +38 −0
analytics/a-google-workspace-identity-used-the-security-investigation-toolRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace Role privilege was deleted added +22 −0
analytics/a-google-workspace-role-privilege-was-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace service was configured as unrestricted added +62 −0
analytics/a-google-workspace-service-was-configured-as-unrestrictedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace user was added to a group added +22 −0
analytics/a-google-workspace-user-was-added-to-a-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Google Workspace user was removed from a group added +22 −0
analytics/a-google-workspace-user-was-removed-from-a-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes API operation was successfully invoked by an anonymous user added +39 −0
analytics/a-kubernetes-api-operation-was-successfully-invoked-by-an-anonymous-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes cluster role binding was created or deleted added +25 −0
analytics/a-kubernetes-cluster-role-binding-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes cluster role was created added +69 −0
analytics/a-kubernetes-cluster-role-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes cluster was created or deleted added +25 −0
analytics/a-kubernetes-cluster-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes ConfigMap was created or deleted added +25 −0
analytics/a-kubernetes-configmap-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes Cronjob was created added +25 −0
analytics/a-kubernetes-cronjob-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes DaemonSet was created added +25 −0
analytics/a-kubernetes-daemonset-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes dashboard service account was used outside the cluster added +39 −0
analytics/a-kubernetes-dashboard-service-account-was-used-outside-the-clusterRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes deployment was created added +25 −0
analytics/a-kubernetes-deployment-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes ephemeral container was created added +25 −0
analytics/a-kubernetes-ephemeral-container-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes namespace was created or deleted added +25 −0
analytics/a-kubernetes-namespace-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes node service account activity from external IP added +39 −0
analytics/a-kubernetes-node-service-account-activity-from-external-ipRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes Pod was created with a sidecar container added +25 −0
analytics/a-kubernetes-pod-was-created-with-a-sidecar-containerRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes Pod was deleted added +25 −0
analytics/a-kubernetes-pod-was-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes ReplicaSet was created added +25 −0
analytics/a-kubernetes-replicaset-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes role binding was created or deleted added +25 −0
analytics/a-kubernetes-role-binding-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes secret was created or deleted added +25 −0
analytics/a-kubernetes-secret-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes service account executed an unusual API call added +78 −0
analytics/a-kubernetes-service-account-executed-an-unusual-api-callRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes service account has enumerated its permissions added +52 −0
analytics/a-kubernetes-service-account-has-enumerated-its-permissionsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes service account was created or deleted added +39 −0
analytics/a-kubernetes-service-account-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes service was created or deleted added +25 −0
analytics/a-kubernetes-service-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Kubernetes StatefulSet was created added +25 −0
analytics/a-kubernetes-statefulset-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A LOLBIN was copied to a different location added +49 −0
analytics/a-lolbin-was-copied-to-a-different-locationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A machine certificate was issued with a mismatch added +23 −0
analytics/a-machine-certificate-was-issued-with-a-mismatchRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A mail forwarding rule was configured in Google Workspace added +42 −0
analytics/a-mail-forwarding-rule-was-configured-in-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Microsoft Teams application was installed added +36 −0
analytics/a-microsoft-teams-application-was-installedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Microsoft Teams bot was added to a team added +22 −0
analytics/a-microsoft-teams-bot-was-added-to-a-teamRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A new Azure email domain verification was requested added +36 −0
analytics/a-new-azure-email-domain-verification-was-requestedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A new machine attempted Kerberos delegation added +23 −0
analytics/a-new-machine-attempted-kerberos-delegationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A New Server was Added to an Azure Active Directory Hybrid Health ADFS Environment added +22 −0
analytics/a-new-server-was-added-to-an-azure-active-directory-hybrid-health-adfs-environmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A non-browser process accessed a website UI added +62 −0
analytics/a-non-browser-process-accessed-a-website-uiRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Possible crypto miner was detected on a host added +23 −0
analytics/a-possible-crypto-miner-was-detected-on-a-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A possible risky login to Azure added +55 −0
analytics/a-possible-risky-login-to-azureRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process connected to a rare cloud resource added +70 −0
analytics/a-process-connected-to-a-rare-cloud-resourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process connected to a rare external host added +103 −0
analytics/a-process-connected-to-a-rare-external-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process connected to rare external host added +36 −0
analytics/a-process-connected-to-rare-external-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process is masquerading as a common Microsoft product added +88 −0
analytics/a-process-is-masquerading-as-a-common-microsoft-productRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process modified an SSH authorized_keys file added +62 −0
analytics/a-process-modified-an-ssh-authorized_keys-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process queried the ADFS database decryption key via LDAP added +62 −0
analytics/a-process-queried-the-adfs-database-decryption-key-via-ldapRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A process was executed with a command line obfuscated by Unicode character substitution added +22 −0
analytics/a-process-was-executed-with-a-command-line-obfuscated-by-unicode-character-substitutionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A rare DLL, signed by an uncommon vendor, was hijacked into a Microsoft process added +145 −0
analytics/a-rare-dll-signed-by-an-uncommon-vendor-was-hijacked-into-a-microsoft-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A rare file path was added to the AppInit_DLLs registry value added +52 −0
analytics/a-rare-file-path-was-added-to-the-appinit_dlls-registry-valueRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A rare FTP user has been detected on an existing FTP server added +40 −0
analytics/a-rare-ftp-user-has-been-detected-on-an-existing-ftp-serverRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A rare local administrator login added +36 −0
analytics/a-rare-local-administrator-loginRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A remote service was created via RPC over SMB added +40 −0
analytics/a-remote-service-was-created-via-rpc-over-smbRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Service Principal was created in Azure added +23 −0
analytics/a-service-principal-was-created-in-azureRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Service Principal was removed from Azure added +22 −0
analytics/a-service-principal-was-removed-from-azureRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A service was disabled added +62 −0
analytics/a-service-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Successful login from TOR added +24 −0
analytics/a-successful-login-from-torRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A successful SSO sign-in from TOR added +46 −0
analytics/a-successful-sso-sign-in-from-torRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A Successful VPN connection from TOR added +41 −0
analytics/a-successful-vpn-connection-from-torRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A suspicious direct syscall was executed added +49 −0
analytics/a-suspicious-direct-syscall-was-executedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A suspicious executable with multiple file extensions was created added +24 −0
analytics/a-suspicious-executable-with-multiple-file-extensions-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A suspicious process enrolled for a certificate added +38 −0
analytics/a-suspicious-process-enrolled-for-a-certificateRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A suspicious process queried AD CS objects via LDAP added +40 −0
analytics/a-suspicious-process-queried-ad-cs-objects-via-ldapRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A TCP stream was created directly in a shell added +22 −0
analytics/a-tcp-stream-was-created-directly-in-a-shellRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A third-party application's access to the Google Workspace domain's resources was revoked added +22 −0
analytics/a-third-party-application-s-access-to-the-google-workspace-domain-s-resources-was-revokedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ A third-party application was authorized to access the Google Workspace APIs added +23 −0
analytics/a-third-party-application-was-authorized-to-access-the-google-workspace-apisRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.