Release date: 24 June, 2025Change typeChangesAdded 2 new Low Analytics BIOCsOffice process spawned with suspicious command-line argumentsOkta FastPass reported phishing attack suspectedAdded a new Informational Analytics BIOCUncommon SQL like command lineAdded a new Informational Analytics AlertMicrosoft Configuration Manager device registration and policy requestImproved logic of a High Analytics BIOCCollection errorImproved logic of a Medium Analytics BIOCA cloud storage object was copied to a foreign cloud accountImproved logic of 4 Medium Analytics AlertsA cloud identity performed multiple unusual activitiesPossible AS-REP Roasting AttackPossible Kerberoasting attackSuspicious Azure enumeration activityImproved logic of 7 Low Analytics BIOCsAURL - An email was sent from a malicious domainEmail was received from an unknown sender using a disposable domainExternal email display name impersonation of internal personnelPossible DCSync from a non domain controllerScripting engine connected to a rare external hostUnusual hostname for the sending mail server in the email headersUsage of homograph characters detected in an email's from headerImproved logic of 2 Low Analytics AlertsRisk indicators detected in emailSuspicious identity downloaded multiple objects from a bucketImproved logic of 29 Informational Analytics BIOCsA process connected to a rare cloud resourceAURL - Email contains URL(s) classified as inappropriateAURL - Email contains URL(s) classified as maliciousAURL - Email was received from a newly registered domainAURL - Email was sent from a domain classified as inappropriateAURL - Unpopular domain(s) detected in an email's URL(s)AWS SES account sending settings modifiedEmail Punycode characters in URL(s)Email attachment with a potentially malicious file extensionEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedRare Remote Service (SVCCTL) RPC activityRarely seen URL(s) within a well-known domain detected in your organization's emailSuspicious Unicode character detected in emailUncommon Linux remote shell command executionUncommon Linux shell command executionUncommon macOS shell command executionUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUsage of homograph characters detected in an emailX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of an Informational Analytics AlertSuspicious theme and sentiment in emailChanged metadata of an Informational Analytics BIOCAppleScript executed a shell scriptRemoved an old Informational BIOCLsmod executionRemoved 2 old Informational Analytics BIOCsAn AWS ElastiCache security group was createdAn AWS ElastiCache security group was modified or deleted