Release date: 17 March, 2025Change typeChangesAdded 6 new Medium Analytics AlertsEMAIL BETA - Multiple risk indicators detected in emailEMAIL BETA - Potential brand impersonation in emailEMAIL BETA - Potential evasion techniques detected in emailEMAIL BETA - Potentially dangerous URL(s) in emailEMAIL BETA - Potentially dangerous senderEMAIL BETA - Potentially malicious attachment(s) spotted in an emailAdded 11 new Low Analytics BIOCsAWS data asset shared publicEMAIL BETA - An email was sent from a malicious domainEMAIL BETA - Email containing a link with an IP address convention was detectedEMAIL BETA - Email contains URL(s) classified as inappropriateEMAIL BETA - Email mimics replies or forwards without an actual ongoing conversationEMAIL BETA - Email received from an unknown sender using a disposable email addressEMAIL BETA - Email was sent from a domain classified as inappropriateEMAIL BETA - External email display name impersonation of internal personnelEMAIL BETA - Unpopular domains detected in email URLs for a recipientEMAIL BETA - Unusual hostname for the sending mail server in the email headersEMAIL BETA - Usage of homograph characters detected in an email's from headerAdded a new Low Analytics AlertEMAIL BETA - Potential employee impersonation in email with financial or urgent contextAdded 30 new Informational Analytics BIOCsAzure audit - MFA fraud reportedEMAIL BETA - An email was received from a domain classified as riskyEMAIL BETA - Email Punycode characters in URLEMAIL BETA - Email attachment with a potentially malicious file extensionEMAIL BETA - Email attachment with multiple extensionsEMAIL BETA - Email attachment(s) with potentially malicious MIME typeEMAIL BETA - Email containing a redirected linkEMAIL BETA - Email containing financial content was received from an external domainEMAIL BETA - Email containing urgency terms was received from an external domainEMAIL BETA - Email contains URL(s) classified as maliciousEMAIL BETA - Email contains potentially malicious attachments that are not blocked by defaultEMAIL BETA - Email has a short body or subject and was sent from an external sourceEMAIL BETA - Email marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEMAIL BETA - Email message contains text hiding attributesEMAIL BETA - Email received from an unknown sender using a public provider email addressEMAIL BETA - Email suspicious Moniker link detectedEMAIL BETA - Email was received from a newly registered domainEMAIL BETA - Email was received from an unknown sender addressEMAIL BETA - Email with URL shortener detectedEMAIL BETA - Rarely seen URL(s) within a well-known domain detected in your organization's emailEMAIL BETA - Suspicious Unicode character detected in emailEMAIL BETA - URL(s) classified as risky have been detected within EmailEMAIL BETA - Unpopular URL domain(s) in your organization detected in emailEMAIL BETA - Unpopular URL(s) detected in emailEMAIL BETA - Unpopular domain(s) detected in an email's URL(s)EMAIL BETA - Usage of homograph characters detected in an emailEMAIL BETA - Well-known brand impersonation within an email's from address domainEMAIL BETA - X-Forefront-Antispam-Report has flagged this email as a potential threatUncommon driver loadedUnusual user account enablementAdded 4 new Informational Analytics AlertsEMAIL BETA - Elevated alert triggered by combined alerts and severityEMAIL BETA - Email identified as potential fraud attemptEMAIL BETA - Suspicious theme and sentiment in emailKubernetes environment enumeration activityImproved logic of a High Analytics BIOCCollection errorImproved logic of a Medium Analytics BIOCCloud snapshot of a database or storage instance was publicly sharedImproved logic of 11 Low Analytics BIOCsAWS Flow Logs deletionAzure Event Hub DeletionCloud Trail logging deletionPossible DCSync from a non domain controllerUncommon local scheduled task creation via schtasks.exeUnusual Encrypting File System Remote call (EFSRPC) to domain controllerUnusual cross projects activityUnusual process accessed FTP Client credentialsUnusual process accessed a crypto wallet's filesUnusual process accessed a messaging app's filesUnusual process accessed a web browser history fileImproved logic of 2 Low Analytics AlertsAn identity dumped multiple secrets from a projectLogs were not collected from a data source for an abnormally long timeImproved logic of 54 Informational Analytics BIOCsA Kubernetes ConfigMap was created or deletedA Kubernetes Cronjob was createdA Kubernetes cluster role binding was created or deletedA Kubernetes cluster was created or deletedA Kubernetes ephemeral container was createdA Kubernetes namespace was created or deletedA Kubernetes role binding was created or deletedA Kubernetes secret was created or deletedA Kubernetes service account executed an unusual API callA Kubernetes service account was created or deletedA Kubernetes service was created or deletedA cloud identity created or modified a security groupA cloud identity executed an API call from an unusual countryA cloud identity had escalated its permissionsA cloud identity invoked IAM related persistence operationsA cloud instance was stoppedA cloud snapshot was created or modifiedA container registry was created or deletedA user created an abnormal password-protected archiveA user modified an Okta network zoneActivity in a dormant region of a cloud projectAn Azure application reached a throttling API rateAn identity attached an administrative policy to an IAM user/roleAzure Temporary Access Pass (TAP) registered to an accountAzure application credentials addedAzure storage account blob anonymous access is enabledAzure storage account was publicly sharedCloud compute instance user data script modificationCloud compute serial console accessCloud identity reached a throttling API rateCloud impersonation attempt by unusual identity typeData encryption was disabledExchange email-hiding inbox ruleGlobally uncommon high entropy module was loadedGlobally uncommon high entropy process was executedKubernetes admission controller activityKubernetes cluster events deletionKubernetes network policy modificationNetwork sniffing detected in Cloud environmentPossible LDAP Enumeration Tool UsagePotential Okta access limit breachRare Remote Service (SVCCTL) RPC activityRare Scheduled Task RPC activityRare process accessed a Keychain fileUnusual AWS systems manager activityUnusual Identity and Access Management (IAM) activityUnusual cloud identity impersonationUnusual process accessed a macOS notes DB fileUnusual process accessed web browser cookiesUnusual process accessed web browser credentialsUnusual resource modification by newly seen IAM userUnusual resource modification/creationUnusual user account unlockUser attempted to connect from a suspicious countryImproved logic of 15 Informational Analytics AlertsA user executed multiple LDAP enumeration queriesAn identity performed a suspicious download of multiple cloud storage objectsAzure uncommon increase in API request sizesCloud infrastructure enumeration activityDeletion of multiple cloud resourcesExternal SaaS file-sharing activityIAM Enumeration sequenceInternal Login Password SprayKubernetes enumeration activityMassive file downloads from SaaS serviceMassive upload to SaaS serviceMulti region enumeration activityMultiple failed logins from a single IPSSH brute force attemptStorage enumeration activityIncreased the severity to Low for 2 Analytics BIOCsExecutable or Script file written by a web server processPossible webshell file written by a web server processDecreased the severity to Low for an Analytics BIOCPossible Microsoft process masqueradingChanged metadata of a Medium Analytics BIOCSuspicious heavy allocation of compute resources - possible mining activityChanged metadata of a Low Analytics BIOCCopy a user's GnuPG directory with rsyncChanged metadata of a Low Analytics AlertExcessive user account lockoutsChanged metadata of an Informational Analytics BIOCAzure diagnostic configuration deletionChanged metadata of 3 Informational Analytics AlertsAbnormal Allocation of compute resources in multiple regionsAllocation of multiple cloud compute resourcesRare access to known advertising domains