Analytics rules — August 09, 2026
1293 files changed, 53061 insertions, 0 deletions — view the commit on the mirror.
Analytics rule catalog exported for the first time: 1,293 detectors
This is the analytics mirror’s first export, not a day of change to an existing catalog. All 1,293 files under analytics/ are additions — nothing was modified or removed, so there is no prior baseline to diff against.
Each file is one exported detection rule. Given the size and all-additions shape of this commit, individual rules were not read; see the mirror for the full list.
Bulk change — 1,293 files. Per-file diffs are not stored for a change this size; view it on the mirror.
Changes
1293 files listed.
-
▸ ▾ Microsoft OneDrive enumeration activity added +23 −0
analytics/microsoft-onedrive-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft OneNote enumeration activity added +23 −0
analytics/microsoft-onenote-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft SharePoint enumeration activity added +23 −0
analytics/microsoft-sharepoint-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Teams application setup policy was modified added +40 −0
analytics/microsoft-teams-application-setup-policy-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Teams enumeration activity added +23 −0
analytics/microsoft-teams-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Teams external communication policy was modified added +40 −0
analytics/microsoft-teams-external-communication-policy-was-modifiedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Microsoft Teams messages were exported from conversation added +36 −0
analytics/microsoft-teams-messages-were-exported-from-conversationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mimikatz command-line arguments added +22 −0
analytics/mimikatz-command-line-argumentsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ ML artifacts destruction added +37 −0
analytics/ml-artifacts-destructionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Modification of NTLM restrictions in the Registry added +22 −0
analytics/modification-of-ntlm-restrictions-in-the-registryRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Modification of PAM added +40 −0
analytics/modification-of-pamRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Modification of the AD FS IdentityServer configuration file added +38 −0
analytics/modification-of-the-ad-fs-identityserver-configuration-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Modification or Deletion of an Azure Application Gateway Detected added +22 −0
analytics/modification-or-deletion-of-an-azure-application-gateway-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Moniker link detected in URL(s) added +55 −0
analytics/moniker-link-detected-in-url-sRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mount command was executed from within a Kubernetes pod to list all the attached filesystems added +36 −0
analytics/mount-command-was-executed-from-within-a-kubernetes-pod-to-list-all-the-attached-filesystemsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MpCmdRun.exe was used to download files into the system added +22 −0
analytics/mpcmdrun-exe-was-used-to-download-files-into-the-systemRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mshta.exe launched with suspicious arguments added +22 −0
analytics/mshta-exe-launched-with-suspicious-argumentsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Mshta.exe spawns from a browser process added +36 −0
analytics/mshta-exe-spawns-from-a-browser-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ MSI accessed a web page running a server-side script added +36 −0
analytics/msi-accessed-a-web-page-running-a-server-side-scriptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Msiexec execution of an executable from an uncommon remote location added +49 −0
analytics/msiexec-execution-of-an-executable-from-an-uncommon-remote-locationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multi region enumeration activity added +27 −0
analytics/multi-region-enumeration-activityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple alerts associated with a single RDP connection added +23 −0
analytics/multiple-alerts-associated-with-a-single-rdp-connectionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple alerts of different MITRE tactics were seen added +24 −0
analytics/multiple-alerts-of-different-mitre-tactics-were-seenRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Azure AD admin role removals added +22 −0
analytics/multiple-azure-ad-admin-role-removalsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple cloud snapshots export added +77 −0
analytics/multiple-cloud-snapshots-exportRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple discovery commands on a Linux host by the same process added +58 −0
analytics/multiple-discovery-commands-on-a-linux-host-by-the-same-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple discovery commands on a Windows host by the same process added +114 −0
analytics/multiple-discovery-commands-on-a-windows-host-by-the-same-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple discovery commands added +94 −0
analytics/multiple-discovery-commandsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple discovery-like commands added +74 −0
analytics/multiple-discovery-like-commandsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple failed AWS assume role attempts added +42 −0
analytics/multiple-failed-aws-assume-role-attemptsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple failed logins from a single IP added +54 −0
analytics/multiple-failed-logins-from-a-single-ipRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple network-related alerts of different MITRE tactics on the same host added +23 −0
analytics/multiple-network-related-alerts-of-different-mitre-tactics-on-the-same-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple network-related alerts produced by different detectors on the same host added +23 −0
analytics/multiple-network-related-alerts-produced-by-different-detectors-on-the-same-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Okta MFA requests sent to a user added +40 −0
analytics/multiple-okta-mfa-requests-sent-to-a-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Rare LOLBIN Process Executions by User added +36 −0
analytics/multiple-rare-lolbin-process-executions-by-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Rare Process Executions in Organization added +22 −0
analytics/multiple-rare-process-executions-in-organizationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple risk indicators for a cloud identity added +25 −0
analytics/multiple-risk-indicators-for-a-cloud-identityRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Suspicious FTP Login Attempts added +24 −0
analytics/multiple-suspicious-ftp-login-attemptsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple suspicious user accounts were created added +23 −0
analytics/multiple-suspicious-user-accounts-were-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple TGT requests for users without Kerberos pre-authentication added +50 −0
analytics/multiple-tgt-requests-for-users-without-kerberos-pre-authenticationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple uncommon SSH Servers with the same Server host key added +22 −0
analytics/multiple-uncommon-ssh-servers-with-the-same-server-host-keyRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple user accounts failed login due to account lockouts added +38 −0
analytics/multiple-user-accounts-failed-login-due-to-account-lockoutsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple user accounts were deleted added +41 −0
analytics/multiple-user-accounts-were-deletedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple users authenticated with weak NTLM to a host added +22 −0
analytics/multiple-users-authenticated-with-weak-ntlm-to-a-hostRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Multiple Weakly-Encrypted Kerberos Tickets Received added +23 −0
analytics/multiple-weakly-encrypted-kerberos-tickets-receivedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Near-empty email from an external sender added +62 −0
analytics/near-empty-email-from-an-external-senderRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Netcat makes or gets connections added +22 −0
analytics/netcat-makes-or-gets-connectionsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Network sniffing detected in Cloud environment added +54 −0
analytics/network-sniffing-detected-in-cloud-environmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New addition to Windows Defender exclusion list added +38 −0
analytics/new-addition-to-windows-defender-exclusion-listRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New Administrative Behavior added +38 −0
analytics/new-administrative-behaviorRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New cloud identity created with administrative policy added +41 −0
analytics/new-cloud-identity-created-with-administrative-policyRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New FTP Server added +57 −0
analytics/new-ftp-serverRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New Shared User Account added +22 −0
analytics/new-shared-user-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ New Teams application published to the organization catalog added +36 −0
analytics/new-teams-application-published-to-the-organization-catalogRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Non-browser access to a pastebin-like site added +75 −0
analytics/non-browser-access-to-a-pastebin-like-siteRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTDS.dit file written by an uncommon executable added +66 −0
analytics/ntds-dit-file-written-by-an-uncommon-executableRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Brute Force on a Service Account added +22 −0
analytics/ntlm-brute-force-on-a-service-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Brute Force on an Administrator Account added +22 −0
analytics/ntlm-brute-force-on-an-administrator-accountRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Brute Force added +49 −0
analytics/ntlm-brute-forceRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Hash Harvesting added +23 −0
analytics/ntlm-hash-harvestingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Password Spray added +37 −0
analytics/ntlm-password-sprayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ NTLM Relay added +25 −0
analytics/ntlm-relayRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Numerous emails sent by a single sender to multiple internal recipients added +22 −0
analytics/numerous-emails-sent-by-a-single-sender-to-multiple-internal-recipientsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Object versioning was disabled added +37 −0
analytics/object-versioning-was-disabledRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Office process accessed an unusual .LNK file added +24 −0
analytics/office-process-accessed-an-unusual-lnk-fileRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Office process spawned with suspicious command-line arguments added +50 −0
analytics/office-process-spawned-with-suspicious-command-line-argumentsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta account reset password attempt added +36 −0
analytics/okta-account-reset-password-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta account unlock by admin added +36 −0
analytics/okta-account-unlock-by-adminRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta account unlock added +36 −0
analytics/okta-account-unlockRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta admin privilege assignment added +36 −0
analytics/okta-admin-privilege-assignmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta API Token Created added +44 −0
analytics/okta-api-token-createdRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta device assignment added +38 −0
analytics/okta-device-assignmentRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta FastPass reported phishing attack suspected added +37 −0
analytics/okta-fastpass-reported-phishing-attack-suspectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta Reported Attack Suspected added +22 −0
analytics/okta-reported-attack-suspectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta Reported Threat Detected added +36 −0
analytics/okta-reported-threat-detectedRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Okta User Session Impersonation added +36 −0
analytics/okta-user-session-impersonationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ OneDrive file download added +23 −0
analytics/onedrive-file-downloadRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ OneDrive file upload added +24 −0
analytics/onedrive-file-uploadRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ OneDrive folder creation added +23 −0
analytics/onedrive-folder-creationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Outbound email contains file-sharing service link sent to external recipient added +55 −0
analytics/outbound-email-contains-file-sharing-service-link-sent-to-external-recipientRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Outbound email includes an external BCC recipient observed for the first time added +40 −0
analytics/outbound-email-includes-an-external-bcc-recipient-observed-for-the-first-timeRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Outbound email to an address hosted by a public email service provider added +40 −0
analytics/outbound-email-to-an-address-hosted-by-a-public-email-service-providerRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Outlook files accessed by an unsigned process added +23 −0
analytics/outlook-files-accessed-by-an-unsigned-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Owner added to Azure application added +22 −0
analytics/owner-added-to-azure-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Owner was added to Azure application added +25 −0
analytics/owner-was-added-to-azure-applicationRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Parsing Rule Error added +23 −0
analytics/parsing-rule-errorRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Penetration testing tool activity attempt added +36 −0
analytics/penetration-testing-tool-activity-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Permission Groups discovery commands added +36 −0
analytics/permission-groups-discovery-commandsRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Phantom DLL Loading added +49 −0
analytics/phantom-dll-loadingRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ PIM privilege member removal added +22 −0
analytics/pim-privilege-member-removalRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Ping to localhost from an uncommon, unsigned parent process added +22 −0
analytics/ping-to-localhost-from-an-uncommon-unsigned-parent-processRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ PKINIT TGT authentication request added +56 −0
analytics/pkinit-tgt-authentication-requestRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Port Scan added +63 −0
analytics/port-scanRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Port Sweep added +38 −0
analytics/port-sweepRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible AS-REP Roasting Attack added +36 −0
analytics/possible-as-rep-roasting-attackRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible authentication coercion added +52 −0
analytics/possible-authentication-coercionRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible binary padding using dd added +22 −0
analytics/possible-binary-padding-using-ddRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible Brute-Force attempt added +55 −0
analytics/possible-brute-force-attemptRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible brute force on sudo user added +36 −0
analytics/possible-brute-force-on-sudo-userRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.
-
▸ ▾ Possible brute force or configuration change attempt on cytool added +22 −0
analytics/possible-brute-force-or-configuration-change-attempt-on-cytoolRead it here → This file's diff on GitHub ↗
Generated by the mirror — not a documentation page, so no diff is kept. The counts above still say how much moved.
Diffs are not stored for a change this size — view it on the mirror.