Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ Indicator blocking added +36 −0
analytics/indicator-blockingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Indirect command execution using the Program Compatibility Assistant added +22 −0
analytics/indirect-command-execution-using-the-program-compatibility-assistantRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Initial person-to-person email contact added +24 −0
analytics/initial-person-to-person-email-contactRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Injection into rundll32.exe added +36 −0
analytics/injection-into-rundll32-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Installation of a new System-V service added +38 −0
analytics/installation-of-a-new-system-v-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Intense SSO failures added +48 −0
analytics/intense-sso-failuresRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Interactive at.exe privilege escalation method added +24 −0
analytics/interactive-at-exe-privilege-escalation-methodRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Interactive local account enumeration added +24 −0
analytics/interactive-local-account-enumerationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Interactive login by a machine account added +36 −0
analytics/interactive-login-by-a-machine-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Interactive login by a service account added +49 −0
analytics/interactive-login-by-a-service-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Interactive login from a shared user account added +22 −0
analytics/interactive-login-from-a-shared-user-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Internal Login Password Spray added +88 −0
analytics/internal-login-password-sprayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Invalid SAML Detected added +36 −0
analytics/invalid-saml-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ IP Rotation Pattern in SSO Spray added +64 −0
analytics/ip-rotation-pattern-in-sso-sprayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Iptables configuration command was executed added +114 −0
analytics/iptables-configuration-command-was-executedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kerberos Pre-Auth Failures by Host added +23 −0
analytics/kerberos-pre-auth-failures-by-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kerberos Pre-Auth Failures by User and Host added +23 −0
analytics/kerberos-pre-auth-failures-by-user-and-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kerberos Traffic from Non-Standard Process added +36 −0
analytics/kerberos-traffic-from-non-standard-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kerberos User Enumeration added +23 −0
analytics/kerberos-user-enumerationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Key credential attribute modification added +50 −0
analytics/key-credential-attribute-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Keylogging using system commands added +38 −0
analytics/keylogging-using-system-commandsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Known service display name with uncommon image-path added +70 −0
analytics/known-service-display-name-with-uncommon-image-pathRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Known service name with an uncommon image-path added +55 −0
analytics/known-service-name-with-an-uncommon-image-pathRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubelet server communication from a pod added +40 −0
analytics/kubelet-server-communication-from-a-podRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes admission controller activity added +88 −0
analytics/kubernetes-admission-controller-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes API server communication from within a pod added +49 −0
analytics/kubernetes-api-server-communication-from-within-a-podRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes cluster events deletion added +25 −0
analytics/kubernetes-cluster-events-deletionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes enumeration activity added +41 −0
analytics/kubernetes-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes environment enumeration activity added +49 −0
analytics/kubernetes-environment-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes network policy modification added +25 −0
analytics/kubernetes-network-policy-modificationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes nsenter container escape added +49 −0
analytics/kubernetes-nsenter-container-escapeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes Pod Created with host Inter Process Communications (IPC) namespace added +73 −0
analytics/kubernetes-pod-created-with-host-inter-process-communications-ipc-namespaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes Pod created with host process ID (PID) namespace added +73 −0
analytics/kubernetes-pod-created-with-host-process-id-pid-namespaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes Pod Created With Sensitive Volume added +73 −0
analytics/kubernetes-pod-created-with-sensitive-volumeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes pod creation from unknown container image registry added +39 −0
analytics/kubernetes-pod-creation-from-unknown-container-image-registryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes pod creation with host network added +73 −0
analytics/kubernetes-pod-creation-with-host-networkRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes Privileged Pod Creation added +73 −0
analytics/kubernetes-privileged-pod-creationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes secret enumeration activity added +88 −0
analytics/kubernetes-secret-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes secrets enumeration for the first time added +39 −0
analytics/kubernetes-secrets-enumeration-for-the-first-timeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes service account activity outside the cluster added +52 −0
analytics/kubernetes-service-account-activity-outside-the-clusterRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes version disclosure added +22 −0
analytics/kubernetes-version-disclosureRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes vulnerability scanner activity added +40 −0
analytics/kubernetes-vulnerability-scanner-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Kubernetes vulnerability scanning tool usage added +58 −0
analytics/kubernetes-vulnerability-scanning-tool-usageRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Large Upload (FTP) added +37 −0
analytics/large-upload-ftpRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Large Upload (Generic) added +63 −0
analytics/large-upload-genericRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Large Upload (HTTPS) added +51 −0
analytics/large-upload-httpsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Large Upload (SMTP) added +38 −0
analytics/large-upload-smtpRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Large volume of files potentially containing credentials accessed in Google Drive added +40 −0
analytics/large-volume-of-files-potentially-containing-credentials-accessed-in-google-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LDAP AD CS Enumeration via Attack Tool added +40 −0
analytics/ldap-ad-cs-enumeration-via-attack-toolRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LDAP search query from an unpopular and unsigned process added +22 −0
analytics/ldap-search-query-from-an-unpopular-and-unsigned-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LDAP traffic from non-standard process added +75 −0
analytics/ldap-traffic-from-non-standard-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Linux local user account creation added +38 −0
analytics/linux-local-user-account-creationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Linux network share discovery added +22 −0
analytics/linux-network-share-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Linux process execution with a rare GitHub URL added +22 −0
analytics/linux-process-execution-with-a-rare-github-urlRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Linux system firewall was modified added +22 −0
analytics/linux-system-firewall-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local account discovery added +22 −0
analytics/local-account-discoveryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local group enumeration via RPC added +38 −0
analytics/local-group-enumeration-via-rpcRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local group enumeration added +53 −0
analytics/local-group-enumerationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local user account creation by a machine account added +23 −0
analytics/local-user-account-creation-by-a-machine-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local user account creation added +37 −0
analytics/local-user-account-creationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Local user enumeration via SAMR added +36 −0
analytics/local-user-enumeration-via-samrRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Log enumeration via cloud native logging service added +36 −0
analytics/log-enumeration-via-cloud-native-logging-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Logging was impaired via external encryption key added +25 −0
analytics/logging-was-impaired-via-external-encryption-keyRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Login attempt by a honey user added +36 −0
analytics/login-attempt-by-a-honey-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Login by a dormant user added +36 −0
analytics/login-by-a-dormant-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Logs were not collected from a data source for an abnormally long time added +80 −0
analytics/logs-were-not-collected-from-a-data-source-for-an-abnormally-long-timeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LOLBAS executable injects into another process added +36 −0
analytics/lolbas-executable-injects-into-another-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LOLBIN created a PSScriptPolicyTest PowerShell script file added +36 −0
analytics/lolbin-created-a-psscriptpolicytest-powershell-script-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LOLBIN process executed with a high integrity level added +40 −0
analytics/lolbin-process-executed-with-a-high-integrity-levelRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ LSASS dump file written to disk added +22 −0
analytics/lsass-dump-file-written-to-diskRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Machine Account NTLM Relay added +25 −0
analytics/machine-account-ntlm-relayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Machine account was added to a domain admins group added +23 −0
analytics/machine-account-was-added-to-a-domain-admins-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mailbox Client Access Setting (CAS) changed added +23 −0
analytics/mailbox-client-access-setting-cas-changedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mailbox enumeration activity by Azure application added +37 −0
analytics/mailbox-enumeration-activity-by-azure-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Manipulation of netsh helper DLLs Registry keys added +22 −0
analytics/manipulation-of-netsh-helper-dlls-registry-keysRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Masquerading as a default local account added +75 −0
analytics/masquerading-as-a-default-local-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Masquerading as the Linux crond process added +36 −0
analytics/masquerading-as-the-linux-crond-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive file activity abnormal to process added +38 −0
analytics/massive-file-activity-abnormal-to-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive file compression by user added +23 −0
analytics/massive-file-compression-by-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive file downloads from SaaS service added +65 −0
analytics/massive-file-downloads-from-saas-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive files deletion in Box added +36 −0
analytics/massive-files-deletion-in-boxRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive files deletion in Dropbox added +36 −0
analytics/massive-files-deletion-in-dropboxRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive files deletion in Google Drive added +36 −0
analytics/massive-files-deletion-in-google-driveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive files deletion in Microsoft SharePoint or OneDrive added +36 −0
analytics/massive-files-deletion-in-microsoft-sharepoint-or-onedriveRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive upload to a rare storage or mail domain added +39 −0
analytics/massive-upload-to-a-rare-storage-or-mail-domainRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Massive upload to SaaS service added +45 −0
analytics/massive-upload-to-saas-serviceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Member added to a Windows local security group added +56 −0
analytics/member-added-to-a-windows-local-security-groupRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Memory dumping with comsvcs.dll added +23 −0
analytics/memory-dumping-with-comsvcs-dllRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MFA device was removed/deactivated from an IAM user added +22 −0
analytics/mfa-device-was-removed-deactivated-from-an-iam-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MFA Disabled for Google Workspace added +38 −0
analytics/mfa-disabled-for-google-workspaceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MFA was disabled for a Google Workspace user added +49 −0
analytics/mfa-was-disabled-for-a-google-workspace-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MFA was disabled for an Azure identity added +55 −0
analytics/mfa-was-disabled-for-an-azure-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft 365 DLP policy disabled or removed added +38 −0
analytics/microsoft-365-dlp-policy-disabled-or-removedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft 365 storage services exfiltration activity added +23 −0
analytics/microsoft-365-storage-services-exfiltration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Configuration Manager device registration and policy request added +40 −0
analytics/microsoft-configuration-manager-device-registration-and-policy-requestRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Office adds a value to autostart Registry key added +22 −0
analytics/microsoft-office-adds-a-value-to-autostart-registry-keyRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Office injects code into a process added +101 −0
analytics/microsoft-office-injects-code-into-a-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Office Process Spawning a Suspicious One-Liner added +24 −0
analytics/microsoft-office-process-spawning-a-suspicious-one-linerRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Office process spawns a commonly abused process added +24 −0
analytics/microsoft-office-process-spawns-a-commonly-abused-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Office process spawns conhost.exe added +24 −0
analytics/microsoft-office-process-spawns-conhost-exeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.