Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ Rare SSH Session added +22 −0
analytics/rare-ssh-sessionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rare Unix process divided files by size added +22 −0
analytics/rare-unix-process-divided-files-by-sizeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rare unsigned process execution by scheduled task added +62 −0
analytics/rare-unsigned-process-execution-by-scheduled-taskRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rare Unsigned Process Spawned by Office Process Under Suspicious Directory added +22 −0
analytics/rare-unsigned-process-spawned-by-office-process-under-suspicious-directoryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rare Windows Remote Management (WinRM) HTTP Activity added +23 −0
analytics/rare-windows-remote-management-winrm-http-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rare WinRM Session added +22 −0
analytics/rare-winrm-sessionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rarely seen sender address in the organization added +24 −0
analytics/rarely-seen-sender-address-in-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rarely seen sender domain in the organization added +24 −0
analytics/rarely-seen-sender-domain-in-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rarely seen URL(s) within a well-known domain detected in your organization's email added +22 −0
analytics/rarely-seen-url-s-within-a-well-known-domain-detected-in-your-organization-s-emailRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ RDP Connection to localhost added +22 −0
analytics/rdp-connection-to-localhostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ RDP connections enabled remotely via Registry added +50 −0
analytics/rdp-connections-enabled-remotely-via-registryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ RDP from an unmanaged endpoint in a typically managed subnet added +37 −0
analytics/rdp-from-an-unmanaged-endpoint-in-a-typically-managed-subnetRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Reading bash command history file added +22 −0
analytics/reading-bash-command-history-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Recurring access to rare domain added +38 −0
analytics/recurring-access-to-rare-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Recurring access to rare IP added +24 −0
analytics/recurring-access-to-rare-ipRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Recurring rare domain access from an unsigned process added +49 −0
analytics/recurring-rare-domain-access-from-an-unsigned-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Recurring rare domain access to dynamic DNS domain added +24 −0
analytics/recurring-rare-domain-access-to-dynamic-dns-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Registration of Uncommon .NET Services and/or Assemblies added +22 −0
analytics/registration-of-uncommon-net-services-and-or-assembliesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote account enumeration added +55 −0
analytics/remote-account-enumerationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote code execution into Kubernetes Pod added +49 −0
analytics/remote-code-execution-into-kubernetes-podRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote command execution via wmic.exe added +36 −0
analytics/remote-command-execution-via-wmic-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote DCOM command execution added +75 −0
analytics/remote-dcom-command-executionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote PsExec-like command execution added +106 −0
analytics/remote-psexec-like-command-executionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote service command execution from an uncommon source added +24 −0
analytics/remote-service-command-execution-from-an-uncommon-sourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote service start from an uncommon source added +24 −0
analytics/remote-service-start-from-an-uncommon-sourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of an App engine Service Account token added +38 −0
analytics/remote-usage-of-an-app-engine-service-account-tokenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of an AWS service token added +46 −0
analytics/remote-usage-of-an-aws-service-tokenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of an Azure Managed Identity token added +80 −0
analytics/remote-usage-of-an-azure-managed-identity-tokenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of an Azure Service Principal token added +52 −0
analytics/remote-usage-of-an-azure-service-principal-tokenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of AWS Lambda's role added +106 −0
analytics/remote-usage-of-aws-lambda-s-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote usage of VM Service Account token added +38 −0
analytics/remote-usage-of-vm-service-account-tokenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Remote WMI process execution added +38 −0
analytics/remote-wmi-process-executionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Removal of an Azure Owner from an Application or Service Principal added +36 −0
analytics/removal-of-an-azure-owner-from-an-application-or-service-principalRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Retrieval of cloud compute EC2 instance user data added +36 −0
analytics/retrieval-of-cloud-compute-ec2-instance-user-dataRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Retrieval of kubelet credentials added +36 −0
analytics/retrieval-of-kubelet-credentialsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Run downloaded script using pipe added +36 −0
analytics/run-downloaded-script-using-pipeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rundll32.exe executes a rare unsigned module added +49 −0
analytics/rundll32-exe-executes-a-rare-unsigned-moduleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rundll32.exe running with no command-line arguments added +22 −0
analytics/rundll32-exe-running-with-no-command-line-argumentsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Rundll32.exe spawns conhost.exe added +22 −0
analytics/rundll32-exe-spawns-conhost-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ S3 configuration deletion added +22 −0
analytics/s3-configuration-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SAAS - Email was reported by the user or administrator as a phishing attempt added +49 −0
analytics/saas-email-was-reported-by-the-user-or-administrator-as-a-phishing-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SaaS suspicious external domain user activity added +37 −0
analytics/saas-suspicious-external-domain-user-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SCCM log files enumeration added +36 −0
analytics/sccm-log-files-enumerationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Scheduled Task hidden by registry modification added +23 −0
analytics/scheduled-task-hidden-by-registry-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Scrcons.exe Rare Child Process added +40 −0
analytics/scrcons-exe-rare-child-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Screensaver process executed from Users or temporary folder added +36 −0
analytics/screensaver-process-executed-from-users-or-temporary-folderRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Script file added to startup-related Registry keys added +22 −0
analytics/script-file-added-to-startup-related-registry-keysRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Scripting engine connected to a rare external host added +72 −0
analytics/scripting-engine-connected-to-a-rare-external-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SecureBoot was disabled added +22 −0
analytics/secureboot-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Security object deletion in Google Workspace Admin Console added +36 −0
analytics/security-object-deletion-in-google-workspace-admin-consoleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Security tools detection attempt added +24 −0
analytics/security-tools-detection-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sending unusual file(s) to an external address added +24 −0
analytics/sending-unusual-file-s-to-an-external-addressRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sensitive account password reset attempt added +37 −0
analytics/sensitive-account-password-reset-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sensitive browser credential files accessed by a rare non browser process added +36 −0
analytics/sensitive-browser-credential-files-accessed-by-a-rare-non-browser-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sensitive Exchange mail sent to external users added +55 −0
analytics/sensitive-exchange-mail-sent-to-external-usersRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Serial console access was enabled in AWS account added +23 −0
analytics/serial-console-access-was-enabled-in-aws-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Service execution via sc.exe added +22 −0
analytics/service-execution-via-sc-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Service ticket request with a spoofed sAMAccountName added +25 −0
analytics/service-ticket-request-with-a-spoofed-samaccountnameRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SES Production Access Requested added +36 −0
analytics/ses-production-access-requestedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Setting Windows Auto Logon by uncommon process added +22 −0
analytics/setting-windows-auto-logon-by-uncommon-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Setuid and Setgid file bit manipulation added +38 −0
analytics/setuid-and-setgid-file-bit-manipulationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SharePoint Site Collection admin group addition added +49 −0
analytics/sharepoint-site-collection-admin-group-additionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Short-lived Azure AD user account added +36 −0
analytics/short-lived-azure-ad-user-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Short-lived user account added +50 −0
analytics/short-lived-user-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Signed process creates a scheduled task via file access added +38 −0
analytics/signed-process-creates-a-scheduled-task-via-file-accessRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Signed process performed an unpopular DLL injection added +75 −0
analytics/signed-process-performed-an-unpopular-dll-injectionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Signed process performed an unpopular injection added +101 −0
analytics/signed-process-performed-an-unpopular-injectionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Single account excessively locked out added +39 −0
analytics/single-account-excessively-locked-outRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Slack Connect direct message invite was accepted added +47 −0
analytics/slack-connect-direct-message-invite-was-acceptedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SMB Traffic from Non-Standard Process added +36 −0
analytics/smb-traffic-from-non-standard-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Soft delete of cloud storage configuration was disabled added +22 −0
analytics/soft-delete-of-cloud-storage-configuration-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Space after filename added +22 −0
analytics/space-after-filenameRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Spam Bot Traffic added +51 −0
analytics/spam-bot-trafficRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SPNs cleared from a machine account added +41 −0
analytics/spns-cleared-from-a-machine-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSH authentication brute force attempts added +49 −0
analytics/ssh-authentication-brute-force-attemptsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO authentication attempt by a honey user added +39 −0
analytics/sso-authentication-attempt-by-a-honey-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO authentication by a machine account added +42 −0
analytics/sso-authentication-by-a-machine-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO authentication by a service account added +68 −0
analytics/sso-authentication-by-a-service-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO Brute Force added +80 −0
analytics/sso-brute-forceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO Password Spray added +80 −0
analytics/sso-password-sprayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO with abnormal operating system added +23 −0
analytics/sso-with-abnormal-operating-systemRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO with abnormal user agent added +40 −0
analytics/sso-with-abnormal-user-agentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SSO with new operating system added +25 −0
analytics/sso-with-new-operating-systemRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Storage enumeration activity added +25 −0
analytics/storage-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Stored credentials exported using credwiz.exe added +64 −0
analytics/stored-credentials-exported-using-credwiz-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Subdomain Fuzzing added +37 −0
analytics/subdomain-fuzzingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Successful unusual guest user invitation added +36 −0
analytics/successful-unusual-guest-user-invitationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sudden spike in outbound email volume added +55 −0
analytics/sudden-spike-in-outbound-email-volumeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Sudoedit Brute force attempt added +22 −0
analytics/sudoedit-brute-force-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ SUID/GUID permission discovery added +22 −0
analytics/suid-guid-permission-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious access of the System Management Container added +23 −0
analytics/suspicious-access-of-the-system-management-containerRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious access to cloud credential files added +101 −0
analytics/suspicious-access-to-cloud-credential-filesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious access to Kubernetes API with kubelet credentials added +40 −0
analytics/suspicious-access-to-kubernetes-api-with-kubelet-credentialsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious access to shadow file added +75 −0
analytics/suspicious-access-to-shadow-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious account attribute modification that matches that of another account added +41 −0
analytics/suspicious-account-attribute-modification-that-matches-that-of-another-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious active setup registered added +22 −0
analytics/suspicious-active-setup-registeredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious activity indicating a potential abuse of a cloud-native email service added +50 −0
analytics/suspicious-activity-indicating-a-potential-abuse-of-a-cloud-native-email-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious activity on logging bucket added +52 −0
analytics/suspicious-activity-on-logging-bucketRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious AI Dataset Download added +38 −0
analytics/suspicious-ai-dataset-downloadRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Suspicious AI Dataset Label Modification added +24 −0
analytics/suspicious-ai-dataset-label-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.