Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ An Azure DNS Zone was modified added +22 −0
analytics/an-azure-dns-zone-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Firewall policy deletion added +22 −0
analytics/an-azure-firewall-policy-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Firewall rule collection group was modified or deleted added +22 −0
analytics/an-azure-firewall-rule-collection-group-was-modified-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure firewall rule group was modified added +22 −0
analytics/an-azure-firewall-rule-group-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Firewall was modified added +22 −0
analytics/an-azure-firewall-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure identity performed multiple actions that were denied added +67 −0
analytics/an-azure-identity-performed-multiple-actions-that-were-deniedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Key Vault key was modified added +22 −0
analytics/an-azure-key-vault-key-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Key Vault was modified added +22 −0
analytics/an-azure-key-vault-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Kubernetes Cluster was created or deleted added +22 −0
analytics/an-azure-kubernetes-cluster-was-created-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deleted added +22 −0
analytics/an-azure-kubernetes-role-binding-or-cluster-role-binding-was-modified-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Kubernetes Role or Cluster-Role was modified added +22 −0
analytics/an-azure-kubernetes-role-or-cluster-role-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Kubernetes Service Account was modified or deleted added +22 −0
analytics/an-azure-kubernetes-service-account-was-modified-or-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Network Security Group was modified added +22 −0
analytics/an-azure-network-security-group-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Point-to-Site VPN was modified added +22 −0
analytics/an-azure-point-to-site-vpn-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure SQL database was exported from a production subscription added +22 −0
analytics/an-azure-sql-database-was-exported-from-a-production-subscriptionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure Suppression Rule was created added +22 −0
analytics/an-azure-suppression-rule-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure virtual network Device was modified added +22 −0
analytics/an-azure-virtual-network-device-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure virtual network was modified added +22 −0
analytics/an-azure-virtual-network-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure VM snapshot SAS URL was generated for export from a production subscription added +22 −0
analytics/an-azure-vm-snapshot-sas-url-was-generated-for-export-from-a-production-subscriptionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure VM snapshot SAS URL was generated added +36 −0
analytics/an-azure-vm-snapshot-sas-url-was-generatedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Azure VPN Connection was modified added +22 −0
analytics/an-azure-vpn-connection-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An EBS snapshot block was downloaded added +55 −0
analytics/an-ebs-snapshot-block-was-downloadedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An Email address was added to AWS SES added +22 −0
analytics/an-email-address-was-added-to-aws-sesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An executable was written and executed by a web server added +22 −0
analytics/an-executable-was-written-and-executed-by-a-web-serverRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An IAM group was created added +22 −0
analytics/an-iam-group-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity accessed a backup cloud storage added +42 −0
analytics/an-identity-accessed-a-backup-cloud-storageRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity accessed a cloud storage for the first time added +26 −0
analytics/an-identity-accessed-a-cloud-storage-for-the-first-timeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity accessed Azure Kubernetes Secrets added +22 −0
analytics/an-identity-accessed-azure-kubernetes-secretsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity attached an administrative policy to an IAM user or role added +70 −0
analytics/an-identity-attached-an-administrative-policy-to-an-iam-user-or-roleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity created or updated password for an IAM user added +40 −0
analytics/an-identity-created-or-updated-password-for-an-iam-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity disabled bucket logging added +22 −0
analytics/an-identity-disabled-bucket-loggingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity initiated a download of multiple cloud objects added +57 −0
analytics/an-identity-initiated-a-download-of-multiple-cloud-objectsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity performed a suspicious download of multiple cloud storage objects added +87 −0
analytics/an-identity-performed-a-suspicious-download-of-multiple-cloud-storage-objectsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity started an AWS SSM session added +52 −0
analytics/an-identity-started-an-aws-ssm-sessionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity successfully extracted multiple secrets within the organization added +49 −0
analytics/an-identity-successfully-extracted-multiple-secrets-within-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An identity was granted permissions to manage user access to Azure resources added +23 −0
analytics/an-identity-was-granted-permissions-to-manage-user-access-to-azure-resourcesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An internal Cloud resource performed port scan on external networks added +25 −0
analytics/an-internal-cloud-resource-performed-port-scan-on-external-networksRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An operation was performed by an identity from a domain that was not seen in the organization added +38 −0
analytics/an-operation-was-performed-by-an-identity-from-a-domain-that-was-not-seen-in-the-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An RDS snapshot containing sensitive data was exported added +22 −0
analytics/an-rds-snapshot-containing-sensitive-data-was-exportedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An RDS snapshot was exported from a production account added +22 −0
analytics/an-rds-snapshot-was-exported-from-a-production-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An RDS snapshot was exported to an unknown bucket added +36 −0
analytics/an-rds-snapshot-was-exported-to-an-unknown-bucketRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An RDS snapshot was exported to an unknown S3 bucket added +62 −0
analytics/an-rds-snapshot-was-exported-to-an-unknown-s3-bucketRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An S3 replication policy to an unknown bucket was created added +62 −0
analytics/an-s3-replication-policy-to-an-unknown-bucket-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon executable was remotely written over SMB to an uncommon destination added +62 −0
analytics/an-uncommon-executable-was-remotely-written-over-smb-to-an-uncommon-destinationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon file added to startup-related Registry keys added +88 −0
analytics/an-uncommon-file-added-to-startup-related-registry-keysRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon file was created in the startup folder added +76 −0
analytics/an-uncommon-file-was-created-in-the-startup-folderRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon lolbin execution by scheduled task added +49 −0
analytics/an-uncommon-lolbin-execution-by-scheduled-taskRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon RDP session from a managed host added +88 −0
analytics/an-uncommon-rdp-session-from-a-managed-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon RDP session was established added +88 −0
analytics/an-uncommon-rdp-session-was-establishedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An uncommon service was started added +38 −0
analytics/an-uncommon-service-was-startedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unknown account was invited to the AWS organization added +22 −0
analytics/an-unknown-account-was-invited-to-the-aws-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unpopular process accessed the microphone on the host added +38 −0
analytics/an-unpopular-process-accessed-the-microphone-on-the-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unsigned process created scheduled task and performed an injection added +40 −0
analytics/an-unsigned-process-created-scheduled-task-and-performed-an-injectionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unusual archive file creation by a user added +38 −0
analytics/an-unusual-archive-file-creation-by-a-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unusual cloud identity was granted permissions to a BigQuery resource added +40 −0
analytics/an-unusual-cloud-identity-was-granted-permissions-to-a-bigquery-resourceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unusual process in ingress-nginx has accessed a service-account token file added +24 −0
analytics/an-unusual-process-in-ingress-nginx-has-accessed-a-service-account-token-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ An unusual read activity of cloud object added +26 −0
analytics/an-unusual-read-activity-of-cloud-objectRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AppleScript executed a shell script added +52 −0
analytics/applescript-executed-a-shell-scriptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AppleScript interpreter dynamic library loaded into a process added +49 −0
analytics/applescript-interpreter-dynamic-library-loaded-into-a-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AppleScript process executed with a rare command line added +101 −0
analytics/applescript-process-executed-with-a-rare-command-lineRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Attempt to execute a command on a remote host using PsExec.exe added +40 −0
analytics/attempt-to-execute-a-command-on-a-remote-host-using-psexec-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Attempted Azure application access from unknown tenant added +50 −0
analytics/attempted-azure-application-access-from-unknown-tenantRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Aurora DB cluster stopped added +22 −0
analytics/aurora-db-cluster-stoppedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Authentication attempt by a honey user added +39 −0
analytics/authentication-attempt-by-a-honey-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Authentication Attempt From a Dormant Account added +37 −0
analytics/authentication-attempt-from-a-dormant-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Authentication method added to an Azure account added +49 −0
analytics/authentication-method-added-to-an-azure-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Authentication method was added to Azure account added +23 −0
analytics/authentication-method-was-added-to-azure-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Autorun.inf created in root C drive added +24 −0
analytics/autorun-inf-created-in-root-c-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Backup recovery point deletion added +22 −0
analytics/aws-backup-recovery-point-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Backup vault was deleted added +49 −0
analytics/aws-backup-vault-was-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Bedrock AI infrastructure enumeration activity added +36 −0
analytics/aws-bedrock-ai-infrastructure-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Bedrock model invocation logging deletion added +49 −0
analytics/aws-bedrock-model-invocation-logging-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS CloudTrail has been stopped added +52 −0
analytics/aws-cloudtrail-has-been-stoppedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS CloudTrail modification added +54 −0
analytics/aws-cloudtrail-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS CloudWatch log group deletion added +24 −0
analytics/aws-cloudwatch-log-group-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS CloudWatch log stream deletion added +24 −0
analytics/aws-cloudwatch-log-stream-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Config Recorder stopped added +22 −0
analytics/aws-config-recorder-stoppedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS config resource deletion added +22 −0
analytics/aws-config-resource-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS console login without MFA added +26 −0
analytics/aws-console-login-without-mfaRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS data asset shared public added +22 −0
analytics/aws-data-asset-shared-publicRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS EBS enumeration activity added +23 −0
analytics/aws-ebs-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS EBS snapshot deletion added +22 −0
analytics/aws-ebs-snapshot-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS EC2 infrastructure enumeration activity added +22 −0
analytics/aws-ec2-infrastructure-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS EC2 instance exported into S3 added +22 −0
analytics/aws-ec2-instance-exported-into-s3Read it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Flow Logs deletion added +22 −0
analytics/aws-flow-logs-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Guard-Duty detector deletion added +22 −0
analytics/aws-guard-duty-detector-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS IAM resource group deletion added +22 −0
analytics/aws-iam-resource-group-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS IAM Role Created with Cross-Account Access added +38 −0
analytics/aws-iam-role-created-with-cross-account-accessRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS IAM Role's Trusted Policy Modification Allows Cross-Account Access added +23 −0
analytics/aws-iam-role-s-trusted-policy-modification-allows-cross-account-accessRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Lambda Cross-Account sensitive permissions configured added +66 −0
analytics/aws-lambda-cross-account-sensitive-permissions-configuredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Lambda infrastructure enumeration activity added +22 −0
analytics/aws-lambda-infrastructure-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS network ACL rule creation added +24 −0
analytics/aws-network-acl-rule-creationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS network ACL rule deletion added +22 −0
analytics/aws-network-acl-rule-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS Password Policy Discovery added +22 −0
analytics/aws-password-policy-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS principals discovery added +22 −0
analytics/aws-principals-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS RDS cluster deletion added +22 −0
analytics/aws-rds-cluster-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS resource discovery added +22 −0
analytics/aws-resource-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS root account activity added +22 −0
analytics/aws-root-account-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS S3 bucket data retention policy change through S3 Lifecycle rule added +22 −0
analytics/aws-s3-bucket-data-retention-policy-change-through-s3-lifecycle-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ AWS S3 bucket was exposed to public access added +49 −0
analytics/aws-s3-bucket-was-exposed-to-public-accessRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.