Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ Cloud snapshot of a database or storage instance was publicly shared added +22 −0
analytics/cloud-snapshot-of-a-database-or-storage-instance-was-publicly-sharedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud storage automatic backup disabled added +38 −0
analytics/cloud-storage-automatic-backup-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud storage delete protection disabled added +38 −0
analytics/cloud-storage-delete-protection-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud user performed multiple actions that were denied added +40 −0
analytics/cloud-user-performed-multiple-actions-that-were-deniedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Cloud Watch alarm deletion added +22 −0
analytics/cloud-watch-alarm-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ CloudTrail logging deletion added +52 −0
analytics/cloudtrail-logging-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Collection error added +23 −0
analytics/collection-errorRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Command execution in a Kubernetes pod added +49 −0
analytics/command-execution-in-a-kubernetes-podRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Command execution via AWS SSM added +24 −0
analytics/command-execution-via-aws-ssmRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Command execution via wmiexec added +22 −0
analytics/command-execution-via-wmiexecRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Command running with COMSPEC in the command line argument added +22 −0
analytics/command-running-with-comspec-in-the-command-line-argumentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Common third-party software name masquerading added +49 −0
analytics/common-third-party-software-name-masqueradingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Commonly abused AutoIT script connects to an external domain added +24 −0
analytics/commonly-abused-autoit-script-connects-to-an-external-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Commonly abused AutoIT script drops an executable file to disk added +23 −0
analytics/commonly-abused-autoit-script-drops-an-executable-file-to-diskRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Commonly abused process launched as a system service added +22 −0
analytics/commonly-abused-process-launched-as-a-system-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Compressing data using python added +22 −0
analytics/compressing-data-using-pythonRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Compute activity in dormant cloud region added +64 −0
analytics/compute-activity-in-dormant-cloud-regionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Conditional Access policy removed added +22 −0
analytics/conditional-access-policy-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Conhost.exe spawned a suspicious cmd process added +62 −0
analytics/conhost-exe-spawned-a-suspicious-cmd-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Contained process execution with a rare GitHub URL added +22 −0
analytics/contained-process-execution-with-a-rare-github-urlRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Copy a process memory file added +36 −0
analytics/copy-a-process-memory-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Copy a user's GnuPG directory with rsync added +22 −0
analytics/copy-a-user-s-gnupg-directory-with-rsyncRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Correlation rule error added +23 −0
analytics/correlation-rule-errorRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Creation or modification of the default command executed when opening an application added +75 −0
analytics/creation-or-modification-of-the-default-command-executed-when-opening-an-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Credentials were added to Azure application added +24 −0
analytics/credentials-were-added-to-azure-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Data encryption was disabled added +23 −0
analytics/data-encryption-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Data exfiltration from cloud database added +56 −0
analytics/data-exfiltration-from-cloud-databaseRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Data Sharing between GCP and Google Workspace was disabled added +78 −0
analytics/data-sharing-between-gcp-and-google-workspace-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Delayed Deletion of Files added +22 −0
analytics/delayed-deletion-of-filesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Deletion of AD CS certificate database entries added +37 −0
analytics/deletion-of-ad-cs-certificate-database-entriesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Deletion of multiple cloud resources added +51 −0
analytics/deletion-of-multiple-cloud-resourcesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Denied API call by a Kubernetes service account added +52 −0
analytics/denied-api-call-by-a-kubernetes-service-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Device Registration Policy modification added +36 −0
analytics/device-registration-policy-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Disable AWS audit logs through Event Selectors added +22 −0
analytics/disable-aws-audit-logs-through-event-selectorsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Disable encryption operations added +22 −0
analytics/disable-encryption-operationsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Disable Microsoft Defender Antivirus via registry added +22 −0
analytics/disable-microsoft-defender-antivirus-via-registryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Discovery of accounts with pre-authentication disabled via LDAP added +40 −0
analytics/discovery-of-accounts-with-pre-authentication-disabled-via-ldapRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Discovery of host users via WMIC added +22 −0
analytics/discovery-of-host-users-via-wmicRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Discovery of misconfigured certificate templates using LDAP added +36 −0
analytics/discovery-of-misconfigured-certificate-templates-using-ldapRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Display text URL differs from actual URL added +22 −0
analytics/display-text-url-differs-from-actual-urlRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ DLP sensitive data exposed to external users added +38 −0
analytics/dlp-sensitive-data-exposed-to-external-usersRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ DNS Tunneling added +41 −0
analytics/dns-tunnelingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Download a script using the python requests module added +22 −0
analytics/download-a-script-using-the-python-requests-moduleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Download pattern that resembles Peer to Peer traffic added +27 −0
analytics/download-pattern-that-resembles-peer-to-peer-trafficRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ DSC (Desired State Configuration) lateral movement using PowerShell added +70 −0
analytics/dsc-desired-state-configuration-lateral-movement-using-powershellRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ EBS snapshots were created from an EC2 instance added +49 −0
analytics/ebs-snapshots-were-created-from-an-ec2-instanceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ EBS volume attachment attempt added +49 −0
analytics/ebs-volume-attachment-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ EBS volume detachment attempt added +36 −0
analytics/ebs-volume-detachment-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ EC2 backdoor created with newly added external SSH or RDP access added +36 −0
analytics/ec2-backdoor-created-with-newly-added-external-ssh-or-rdp-accessRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ EC2 instance Amazon machine image was created added +22 −0
analytics/ec2-instance-amazon-machine-image-was-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Elevation to SYSTEM via services added +55 −0
analytics/elevation-to-system-via-servicesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email attachment(s) with potentially malicious MIME type added +55 −0
analytics/email-attachment-s-with-potentially-malicious-mime-typeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email attachment with a potentially malicious file extension added +55 −0
analytics/email-attachment-with-a-potentially-malicious-file-extensionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email attachment with multiple extensions added +55 −0
analytics/email-attachment-with-multiple-extensionsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email attachment with Right-to-Left Override Unicode character added +24 −0
analytics/email-attachment-with-right-to-left-override-unicode-characterRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email containing a link with an IP address convention was detected added +24 −0
analytics/email-containing-a-link-with-an-ip-address-convention-was-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email containing a redirected link added +40 −0
analytics/email-containing-a-redirected-linkRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email contains URL delivering high-risk file type added +40 −0
analytics/email-contains-url-delivering-high-risk-file-typeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level values added +85 −0
analytics/email-marked-as-spam-and-bulk-based-on-spam-confidence-level-and-bulk-complaint-level-valuesRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email mimics replies or forwards without an actual ongoing conversation added +23 −0
analytics/email-mimics-replies-or-forwards-without-an-actual-ongoing-conversationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email sent using an automated system or script detected added +36 −0
analytics/email-sent-using-an-automated-system-or-script-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email was received from an unknown address using a public provider domain added +24 −0
analytics/email-was-received-from-an-unknown-address-using-a-public-provider-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email was received from an unknown sender using a disposable domain added +24 −0
analytics/email-was-received-from-an-unknown-sender-using-a-disposable-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email with file-sharing link containing auto-download parameter added +40 −0
analytics/email-with-file-sharing-link-containing-auto-download-parameterRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Email with URL shortener detected added +22 −0
analytics/email-with-url-shortener-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Encoded information using Windows certificate management tool added +23 −0
analytics/encoded-information-using-windows-certificate-management-toolRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Error in event forwarding added +23 −0
analytics/error-in-event-forwardingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Excessive user account lockouts added +53 −0
analytics/excessive-user-account-lockoutsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange anti-phish policy disabled or removed added +40 −0
analytics/exchange-anti-phish-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange audit log disabled added +23 −0
analytics/exchange-audit-log-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange compliance search created added +49 −0
analytics/exchange-compliance-search-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange DKIM signing configuration disabled added +40 −0
analytics/exchange-dkim-signing-configuration-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange email-hiding inbox rule added +62 −0
analytics/exchange-email-hiding-inbox-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange email-hiding transport rule added +49 −0
analytics/exchange-email-hiding-transport-ruleRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange inbox forwarding rule configured added +74 −0
analytics/exchange-inbox-forwarding-rule-configuredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange mailbox audit bypass added +23 −0
analytics/exchange-mailbox-audit-bypassRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange mailbox delegation permissions added added +36 −0
analytics/exchange-mailbox-delegation-permissions-addedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange mailbox folder permission modification added +36 −0
analytics/exchange-mailbox-folder-permission-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange malware filter policy removed added +23 −0
analytics/exchange-malware-filter-policy-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange Safe Attachment policy disabled or removed added +24 −0
analytics/exchange-safe-attachment-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange Safe Link policy disabled or removed added +24 −0
analytics/exchange-safe-link-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange transport forwarding rule configured added +58 −0
analytics/exchange-transport-forwarding-rule-configuredRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Exchange user mailbox forwarding added +58 −0
analytics/exchange-user-mailbox-forwardingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Executable created to disk by lsass.exe added +22 −0
analytics/executable-created-to-disk-by-lsass-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Executable moved to Windows system folder added +75 −0
analytics/executable-moved-to-windows-system-folderRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Executable or Script file written by a web server process added +70 −0
analytics/executable-or-script-file-written-by-a-web-server-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of an uncommon process at an early startup stage by Windows system binary added +49 −0
analytics/execution-of-an-uncommon-process-at-an-early-startup-stage-by-windows-system-binaryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of an uncommon process at an early startup stage added +49 −0
analytics/execution-of-an-uncommon-process-at-an-early-startup-stageRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of an uncommon process with a local/domain user SID at an early startup stage by Windows system binary added +62 −0
analytics/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stage-by-windows-system-binaryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of an uncommon process with a local/domain user SID at an early startup stage added +49 −0
analytics/execution-of-an-uncommon-process-with-a-local-domain-user-sid-at-an-early-startup-stageRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of command from within a Kubernetes pod using kubelet credentials added +36 −0
analytics/execution-of-command-from-within-a-kubernetes-pod-using-kubelet-credentialsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of dllhost.exe with an empty command line added +49 −0
analytics/execution-of-dllhost-exe-with-an-empty-command-lineRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of masqueraded third-party utility added +52 −0
analytics/execution-of-masqueraded-third-party-utilityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Execution of renamed lolbin added +38 −0
analytics/execution-of-renamed-lolbinRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External email display name impersonation of internal personnel added +36 −0
analytics/external-email-display-name-impersonation-of-internal-personnelRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External email with a single internal recipient hidden in BCC added +40 −0
analytics/external-email-with-a-single-internal-recipient-hidden-in-bccRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External Login Password Spray added +101 −0
analytics/external-login-password-sprayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External SaaS file-sharing activity added +39 −0
analytics/external-saas-file-sharing-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External Sharing was turned on for Google Drive added +62 −0
analytics/external-sharing-was-turned-on-for-google-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ External user added a link to a Microsoft Teams chat added +36 −0
analytics/external-user-added-a-link-to-a-microsoft-teams-chatRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.