Release date: 29 January, 2025Change typeChangesAdded a new Medium Analytics AlertSuspicious Azure enumeration activityAdded a new Low Analytics BIOCDiscovery of accounts with pre-authentication disabled via LDAPAdded 2 new Informational Analytics BIOCsAppleScript executed a shell scriptSuspicious NTLM authentication with machine accountAdded 3 new Informational Analytics AlertsMicrosoft OneNote enumeration activityOkta account reset password attemptUncommon WPAD queriesImproved logic of 2 High Analytics BIOCsSuspicious API call from a Tor exit nodeSuspicious SaaS API call from a Tor exit nodeImproved logic of a High Analytics AlertSuspicious objects encryption in an AWS bucketImproved logic of 10 Medium Analytics BIOCsA Kubernetes API operation was successfully invoked by an anonymous userA Kubernetes dashboard service account was used outside the clusterA mail forwarding rule was configured in Google WorkspaceAzure AD PIM alert disabledCloud snapshot of a database or storage instance was publicly sharedDiscovery of misconfigured certificate templates using LDAPKubernetes vulnerability scanning tool usagePenetration testing tool activitySuspicious heavy allocation of compute resources - possible mining activitySuspicious usage of EC2 tokenImproved logic of 41 Low Analytics BIOCsA Command Line Interface (CLI) command was executed from a GCP serverless compute serviceA Command Line Interface (CLI) command was executed from an AWS serverless compute serviceA GCP service account was delegated domain-wide authority in Google WorkspaceA cloud function was created with an unusual runtimeA domain was added to the trusted domains listA user attempted to bypass Okta MFAAWS Flow Logs deletionAWS Guard-Duty detector deletionAWS network ACL rule deletionAWS web ACL deletionAn Azure Firewall policy deletionAzure AD PIM role settings changeAzure Event Hub DeletionAzure Network Watcher DeletionAzure account deletion by a non-standard accountAzure domain federation settings modification attemptBilling admin role was removedCloud Trail logging deletionConditional Access policy removedDisable encryption operationsExchange DKIM signing configuration disabledExchange Safe Attachment policy disabled or removedExchange Safe Link policy disabled or removedExchange anti-phish policy disabled or removedExchange audit log disabledExchange mailbox audit bypassExchange malware filter policy removedExchange transport forwarding rule configuredExchange user mailbox forwardingFirst Azure AD PowerShell operation for a userGCP Logging Sink DeletionKubernetes pod creation from unknown container image registryMFA Disabled for Google WorkspaceMFA was disabled for an Azure identityOkta Reported Attack SuspectedRemote usage of an AWS service tokenRemote usage of an Azure Managed Identity tokenRemote usage of an Azure Service Principal tokenUncommon SSH session was establishedUncommon remote monitoring and management toolUnusual cross projects activityImproved logic of 4 Low Analytics AlertsA user uploaded malware to SharePoint or OneDriveAn identity dumped multiple secrets from a projectMultiple Azure AD admin role removalsSuspicious identity downloaded multiple objects from a bucketImproved logic of 256 Informational Analytics BIOCsA Google Workspace Role privilege was deletedA Google Workspace identity created, assigned or modified a roleA Google Workspace identity performed an unusual admin console activityA Google Workspace identity used the security investigation toolA Google Workspace service was configured as unrestrictedA Google Workspace user was added to a groupA Google Workspace user was removed from a groupA Kubernetes ConfigMap was created or deletedA Kubernetes Cronjob was createdA Kubernetes DaemonSet was createdA Kubernetes Pod was created with a sidecar containerA Kubernetes Pod was deletedA Kubernetes ReplicaSet was createdA Kubernetes StatefulSet was createdA Kubernetes cluster role binding was created or deletedA Kubernetes cluster was created or deletedA Kubernetes deployment was createdA Kubernetes ephemeral container was createdA Kubernetes namespace was created or deletedA Kubernetes node service account activity from external IPA Kubernetes role binding was created or deletedA Kubernetes secret was created or deletedA Kubernetes service account executed an unusual API callA Kubernetes service account has enumerated its permissionsA Kubernetes service account was created or deletedA Kubernetes service was created or deletedA New Server was Added to an Azure Active Directory Hybrid Health ADFS EnvironmentA Service Principal was created in AzureA Service Principal was removed from AzureA cloud identity created or modified a security groupA cloud identity executed an API call from an unusual countryA cloud identity had escalated its permissionsA cloud identity invoked IAM related persistence operationsA cloud instance was stoppedA cloud snapshot was created or modifiedA cloud storage configuration was modifiedA compute-attached identity executed API calls outside the instance's regionA container registry was created or deletedA process connected to a rare external hostA third-party application was authorized to access the Google Workspace APIsA third-party application's access to the Google Workspace domain's resources was revokedA user accessed Okta's admin applicationA user logged in to the AWS console for the first timeA user modified an Okta network zoneA user modified an Okta policy ruleAWS Cloud Trail log trail modificationAWS CloudWatch log group deletionAWS CloudWatch log stream deletionAWS Config Recorder stoppedAWS EC2 instance exported into S3AWS IAM resource group deletionAWS RDS cluster deletionAWS Role Trusted Entity modificationAWS Root account activityAWS SSM send command attemptAWS STS temporary credentials were generatedAWS SecurityHub findings were modifiedAWS config resource deletionAWS network ACL rule creationAWS user creationAbnormal Communication to a Rare DomainAbnormal Communication to a Rare IPAbnormal Recurring Communications to a Rare DomainActivity in a dormant region of a cloud projectAdmin privileges were granted to a Google Workspace userAn AWS EFS File-share mount was deletedAn AWS EFS file-share was deletedAn AWS EKS cluster was created or deletedAn AWS ElastiCache security group was createdAn AWS ElastiCache security group was modified or deletedAn AWS GuardDuty IP set was createdAn AWS Lambda Function was createdAn AWS Lambda function was modifiedAn AWS RDS Global Cluster DeletionAn AWS RDS instance was created from a snapshotAn AWS Route 53 domain was transferred to another AWS accountAn AWS S3 bucket configuration was modifiedAn AWS SAML provider was modifiedAn AWS SES Email sending settings were modifiedAn AWS SES identity was deletedAn AWS database service master user password was changedAn Azure Cloud Shell was CreatedAn Azure DNS Zone was modifiedAn Azure Firewall Rule Collection was modifiedAn Azure Firewall was modifiedAn Azure Key Vault key was modifiedAn Azure Key Vault was modifiedAn Azure Kubernetes Cluster was created or deletedAn Azure Kubernetes Role or Cluster-Role was modifiedAn Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deletedAn Azure Kubernetes Service Account was modified or deletedAn Azure Network Security Group was modifiedAn Azure Point-to-Site VPN was modifiedAn Azure Suppression Rule was createdAn Azure VPN Connection was modifiedAn Azure application reached a throttling API rateAn Azure firewall rule group was modifiedAn Azure virtual network Device was modifiedAn Azure virtual network was modifiedAn Email address was added to AWS SESAn IAM group was createdAn app was added to Google MarketplaceAn app was added to the Google Workspace trusted OAuth apps listAn app was removed from a blocked list in Google WorkspaceAn identity accessed Azure Kubernetes SecretsAn identity attached an administrative policy to an IAM user/roleAn identity created or updated password for an IAM userAn identity disabled bucket loggingAn identity started an AWS SSM sessionAn identity was granted permissions to manage user access to Azure resourcesAn operation was performed by an identity from a domain that was not seen in the organizationAttempted Azure application access from unknown tenantAurora DB cluster stoppedAuthentication method added to an Azure accountAuthentication method was added to Azure accountAzure AD PIM elevation requestAzure AD account unlock/password reset attemptAzure Automation Account CreationAzure Automation Runbook Creation/ModificationAzure Automation Runbook DeletionAzure Automation Webhook creationAzure Blob Container Access Level ModificationAzure Event Hub Authorization rule creation/modificationAzure Key Vault Secrets were modifiedAzure Key Vault modificationAzure Kubernetes events were deletedAzure Resource Group DeletionAzure Service principal/Application creationAzure Storage Account key generatedAzure Temporary Access Pass (TAP) registered to an accountAzure account creation by a non-standard accountAzure application URI modificationAzure application consentAzure application credentials addedAzure application removedAzure conditional access policy creation or modificationAzure device code authentication flow usedAzure diagnostic configuration deletionAzure group creation/deletionAzure mailbox rule creationAzure permission delegation grantedAzure service principal assigned app roleAzure user creation/deletionAzure user password resetAzure virtual machine commands executionBitLocker key retrievalCloud Organizational policy was created or modifiedCloud Trail Logging has been stopped/suspendedCloud Watch alarm deletionCloud compute instance user data script modificationCloud compute serial console accessCloud email service activityCloud identity reached a throttling API rateCloud impersonation attempt by unusual identity typeCloud storage automatic backup disabledCloud storage delete protection disabledCloud unusual access key creationCredentials were added to Azure applicationDLP sensitive data exposed to external usersData Sharing between GCP and Google Workspace was disabledData encryption was disabledDenied API call by a Kubernetes service accountDevice Registration Policy modificationEC2 snapshot attribute has been modifiedExchange compliance search createdExchange email-hiding inbox ruleExchange email-hiding transport ruleExchange inbox forwarding rule configuredExchange mailbox folder permission modificationExternal Sharing was turned on for Google DriveExternal user invitation to Azure tenantGCP Firewall Rule ModificationGCP Firewall Rule creationGCP IAM Custom Role CreationGCP IAM Role DeletionGCP IAM Service Account Key DeletionGCP Logging Bucket DeletionGCP Logging Sink ModificationGCP Pub/Sub Subscription DeletionGCP Pub/Sub Topic DeletionGCP Service Account DisableGCP Service Account creationGCP Service Account deletionGCP Service Account key creationGCP Storage Bucket Configuration ModificationGCP Storage Bucket Permissions ModificationGCP Storage Bucket deletionGCP VPC Firewall Rule DeletionGCP Virtual Private Cloud (VPC) Network DeletionGCP Virtual Private Network Route CreationGCP Virtual Private Network Route DeletionGCP set IAM policy activityGmail delegation was turned on for the organizationGmail routing settings changedGoogle Marketplace restrictions were modifiedGoogle Workspace organizational unit was modifiedGoogle Workspace third-party application's security settings were changedGranting Access to an AccountIAM User added to an IAM groupIdentity assigned an Azure AD Administrator RoleKubernetes Pod Created With Sensitive VolumeKubernetes Pod Created with host Inter Process Communications (IPC) namespaceKubernetes Pod created with host process ID (PID) namespaceKubernetes Privileged Pod CreationKubernetes admission controller activityKubernetes cluster events deletionKubernetes network policy modificationKubernetes pod creation with host networkKubernetes service account activity outside the clusterMFA device was removed/deactivated from an IAM userMember added to a Windows local security groupMicrosoft 365 DLP policy disabled or removedModification or Deletion of an Azure Application Gateway DetectedNetwork sniffing detected in Cloud environmentObject versioning was disabledOkta API Token CreatedOkta User Session ImpersonationOkta account unlock by adminOkta admin privilege assignmentOneDrive file downloadOneDrive file uploadOneDrive folder creationOwner added to Azure applicationOwner was added to Azure applicationPIM privilege member removalPenetration testing tool activity attemptPenetration testing tool attemptPossible LDAP Enumeration Tool UsagePotential Okta access limit breachPrivileged role used by Azure applicationRare DLP rule match by userRemote usage of AWS Lambda's roleRemote usage of VM Service Account tokenRemote usage of an App engine Service Account tokenRemoval of an Azure Owner from an Application or Service PrincipalS3 configuration deletionSaaS suspicious external domain user activitySharePoint Site Collection admin group additionSoft delete of cloud storage configuration was disabledSuccessful unusual guest user invitationSuspicious cloud compute instance ssh keys modification attemptUnusual AWS systems manager activityUnusual Conditional Access operation for an identityUnusual IAM enumeration activity by a non-user IdentityUnusual Identity and Access Management (IAM) activityUnusual certificate management activityUnusual cloud identity impersonationUnusual exec into a Kubernetes PodUnusual key management activityUnusual resource access by Azure applicationUnusual resource modification by newly seen IAM userUnusual resource modification/creationUnusual secret management activityUnverified domain added to Azure ADUser accessed SaaS resource via anonymous linkUser added a new device to Okta Verify instanceImproved logic of 32 Informational Analytics AlertsA user executed multiple LDAP enumeration queriesA user observed and reported unusual activity in OktaAbnormal Allocation of compute resources in multiple regionsAllocation of multiple cloud compute resourcesAn Azure identity performed multiple actions that were deniedAn identity performed a suspicious download of multiple cloud storage objectsAzure enumeration activity using Microsoft Graph APIAzure high-volume data transferCloud infrastructure enumeration activityCloud user performed multiple actions that were deniedDeletion of multiple cloud resourcesExchange mailbox delegation permissions addedExternal SaaS file-sharing activityIAM Enumeration sequenceKubernetes enumeration activityMailbox enumeration activity by Azure applicationMassive file downloads from SaaS serviceMassive upload to SaaS serviceMicrosoft OneDrive enumeration activityMicrosoft SharePoint enumeration activityMicrosoft Teams enumeration activityMulti region enumeration activityMultiple cloud snapshots exportMultiple failed logins from a single IPOkta Reported Threat DetectedOkta account unlockOkta device assignmentSensitive Exchange mail sent to external usersShort-lived Azure AD user accountStorage enumeration activityUser accessed multiple O365 AIP sensitive filesUser moved Exchange sent messages to deleted itemsChanged metadata of 2 Low Analytics BIOCsAn uncommon executable was remotely written over SMB to an uncommon destinationNTDS.dit file written by an uncommon executableChanged metadata of an Informational Analytics BIOCFirst SSO access from ASN in organizationChanged metadata of an Informational Analytics AlertMultiple SSO MFA attempts were rejected by a userTemporarily removed a Informational Analytics BIOC for improvementAbnormal Recurring Communications to a Rare IP