Release date: 21 April, 2025Change typeChangesAdded 2 new Low Analytics BIOCsCertipy AD CS enumeration via LDAPSuspicious access of the System Management ContainerAdded 3 new Informational Analytics BIOCsCloud resource logging was disabledPKINIT TGT authentication requestUncommon shell command executionImproved logic of 5 High Analytics BIOCsA Successful VPN connection from TORA Successful login from TORA successful SSO sign-in from TORSuspicious API call from a Tor exit nodeSuspicious SaaS API call from a Tor exit nodeImproved logic of a High Analytics AlertSuspicious objects encryption in an AWS bucketImproved logic of 17 Medium Analytics BIOCsA Kubernetes API operation was successfully invoked by an anonymous userA Kubernetes dashboard service account was used outside the clusterA machine certificate was issued with a mismatchA mail forwarding rule was configured in Google WorkspaceAzure AD PIM alert disabledCloud snapshot of a database or storage instance was publicly sharedKubernetes vulnerability scanning tool usageMachine account was added to a domain admins groupPenetration testing tool activityService ticket request with a spoofed sAMAccountNameSuspicious authentication with Azure Password Hash Sync userSuspicious heavy allocation of compute resources - possible mining activitySuspicious hidden user createdSuspicious usage of EC2 tokenTGT request with a spoofed sAMAccountName - Event logTGT request with a spoofed sAMAccountName - NetworkWindows LOLBIN executable connected to a rare external hostImproved logic of 6 Medium Analytics AlertsA new machine attempted Kerberos delegationKerberos User EnumerationNTLM Hash HarvestingPossible AS-REP Roasting AttackPossible Kerberoasting attackRandom-Looking Domain NamesImproved logic of 65 Low Analytics BIOCsA Command Line Interface (CLI) command was executed from a GCP serverless compute serviceA Command Line Interface (CLI) command was executed from an AWS serverless compute serviceA GCP service account was delegated domain-wide authority in Google WorkspaceA cloud function was created with an unusual runtimeA computer account was promoted to DCA disabled user attempted to log in to a VPNA domain was added to the trusted domains listA process queried the ADFS database decryption key via LDAPA user attempted to bypass Okta MFAA user modified the CA audit policyAWS Flow Logs deletionAWS Guard-Duty detector deletionAWS data asset shared publicAWS network ACL rule deletionAWS web ACL deletionAn Azure Firewall policy deletionAzure AD PIM role settings changeAzure Event Hub DeletionAzure Network Watcher DeletionAzure account deletion by a non-standard accountAzure domain federation settings modification attemptBilling admin role was removedCloud Trail logging deletionConditional Access policy removedDisable encryption operationsDiscovery of accounts with pre-authentication disabled via LDAPEMAIL BETA - Email was received from an unknown sender using a disposable domainEMAIL BETA - External email display name impersonation of internal personnelExchange DKIM signing configuration disabledExchange Safe Attachment policy disabled or removedExchange Safe Link policy disabled or removedExchange anti-phish policy disabled or removedExchange audit log disabledExchange mailbox audit bypassExchange malware filter policy removedExchange transport forwarding rule configuredExchange user mailbox forwardingFirst Azure AD PowerShell operation for a userGCP Logging Sink DeletionInteractive login by a service accountKubernetes pod creation from unknown container image registryLogin attempt by a honey userMFA Disabled for Google WorkspaceMFA was disabled for an Azure identityMasquerading as a default local accountOkta Reported Attack SuspectedPossible Pass-the-HashRecurring access to rare IPRecurring rare domain access from an unsigned processRemote usage of an AWS service tokenRemote usage of an Azure Managed Identity tokenRemote usage of an Azure Service Principal tokenSPNs cleared from a machine accountSSO authentication attempt by a honey userSSO authentication by a machine accountSSO authentication by a service accountScripting engine connected to a rare external hostSuspicious Print System Remote Protocol usage by a processSuspicious modification of the AdminSDHolder's ACLSuspicious sAMAccountName changeUnusual Azure AD sync module loadUnusual cross projects activityUser set insecure CA registry setting for global SANsVPN login attempt by a honey userVPN login by a service accountImproved logic of 23 Low Analytics AlertsA user connected a new USB storage device to multiple hostsA user rejected an SSO request from an unusual countryA user sent multiple TGT requests to irregular serviceA user uploaded malware to SharePoint or OneDriveAccount probingAn identity dumped multiple secrets from a projectDNS TunnelingExcessive user account lockoutsFailed DNSImpossible traveler - SSOImpossible traveler - VPNInteractive local account enumerationLogs were not collected from a data source for an abnormally long timeMultiple Azure AD admin role removalsMultiple Rare LOLBIN Process Executions by UserMultiple suspicious user accounts were createdNTLM Brute Force on a Service AccountNTLM Brute Force on an Administrator AccountNew Shared User AccountPossible external RDP Brute-ForceShort-lived user accountSuspicious identity downloaded multiple objects from a bucketUser collected remote shared files in an archiveImproved logic of 334 Informational Analytics BIOCsA Google Workspace Role privilege was deletedA Google Workspace identity created, assigned or modified a roleA Google Workspace identity performed an unusual admin console activityA Google Workspace identity used the security investigation toolA Google Workspace service was configured as unrestrictedA Google Workspace user was added to a groupA Google Workspace user was removed from a groupA Kubernetes ConfigMap was created or deletedA Kubernetes Cronjob was createdA Kubernetes DaemonSet was createdA Kubernetes Pod was created with a sidecar containerA Kubernetes Pod was deletedA Kubernetes ReplicaSet was createdA Kubernetes StatefulSet was createdA Kubernetes cluster role binding was created or deletedA Kubernetes cluster was created or deletedA Kubernetes deployment was createdA Kubernetes ephemeral container was createdA Kubernetes namespace was created or deletedA Kubernetes node service account activity from external IPA Kubernetes role binding was created or deletedA Kubernetes secret was created or deletedA Kubernetes service account executed an unusual API callA Kubernetes service account has enumerated its permissionsA Kubernetes service account was created or deletedA Kubernetes service was created or deletedA New Server was Added to an Azure Active Directory Hybrid Health ADFS EnvironmentA Service Principal was created in AzureA Service Principal was removed from AzureA browser was opened in private modeA cloud identity created or modified a security groupA cloud identity executed an API call from an unusual countryA cloud identity had escalated its permissionsA cloud identity invoked IAM related persistence operationsA cloud instance was stoppedA cloud snapshot was created or modifiedA cloud storage configuration was modifiedA compute-attached identity executed API calls outside the instance's regionA container registry was created or deletedA disabled user attempted to authenticate via SSOA disabled user attempted to log inA possible risky login to AzureA process connected to a rare external hostA rare local administrator loginA suspicious process queried AD CS objects via LDAPA third-party application was authorized to access the Google Workspace APIsA third-party application's access to the Google Workspace domain's resources was revokedA user accessed Okta's admin applicationA user accessed an uncommon AppIDA user account was modified to password never expiresA user added a Windows firewall ruleA user certificate was issued with a mismatchA user changed the Windows system timeA user connected a USB storage device for the first timeA user connected a new USB storage device to a hostA user connected from a new countryA user connected to a VPN from a new countryA user created a pfx file for the first timeA user created an abnormal password-protected archiveA user enabled a default local accountA user logged in at an unusual time via SSOA user logged in at an unusual time via VPNA user logged in from an abnormal country or ASNA user logged in to the AWS console for the first timeA user modified an Okta network zoneA user modified an Okta policy ruleA user queried AD CS objects via LDAPA user was added to a Windows security groupAWS Cloud Trail log trail modificationAWS CloudWatch log group deletionAWS CloudWatch log stream deletionAWS Config Recorder stoppedAWS EC2 instance exported into S3AWS IAM resource group deletionAWS RDS cluster deletionAWS Role Trusted Entity modificationAWS Root account activityAWS SSM send command attemptAWS STS temporary credentials were generatedAWS SecurityHub findings were modifiedAWS Transfer Family server createdAWS config resource deletionAWS network ACL rule creationAWS user creationAbnormal Communication to a Rare DomainAbnormal User Login to Domain ControllerActivity in a dormant region of a cloud projectAdmin privileges were granted to a Google Workspace userAn AWS EFS File-share mount was deletedAn AWS EFS file-share was deletedAn AWS EKS cluster was created or deletedAn AWS ElastiCache security group was createdAn AWS ElastiCache security group was modified or deletedAn AWS GuardDuty IP set was createdAn AWS Lambda Function was createdAn AWS Lambda function was modifiedAn AWS RDS Global Cluster DeletionAn AWS RDS instance was created from a snapshotAn AWS Route 53 domain was transferred to another AWS accountAn AWS S3 bucket configuration was modifiedAn AWS SAML provider was modifiedAn AWS SES Email sending settings were modifiedAn AWS SES identity was deletedAn AWS database service master user password was changedAn Azure Cloud Shell was CreatedAn Azure DNS Zone was modifiedAn Azure Firewall Rule Collection was modifiedAn Azure Firewall was modifiedAn Azure Key Vault key was modifiedAn Azure Key Vault was modifiedAn Azure Kubernetes Cluster was created or deletedAn Azure Kubernetes Role or Cluster-Role was modifiedAn Azure Kubernetes Role-Binding or Cluster-Role-Binding was modified or deletedAn Azure Kubernetes Service Account was modified or deletedAn Azure Network Security Group was modifiedAn Azure Point-to-Site VPN was modifiedAn Azure Suppression Rule was createdAn Azure VPN Connection was modifiedAn Azure application reached a throttling API rateAn Azure firewall rule group was modifiedAn Azure virtual network Device was modifiedAn Azure virtual network was modifiedAn Email address was added to AWS SESAn IAM group was createdAn app was added to Google MarketplaceAn app was added to the Google Workspace trusted OAuth apps listAn app was removed from a blocked list in Google WorkspaceAn identity accessed Azure Kubernetes SecretsAn identity attached an administrative policy to an IAM user/roleAn identity created or updated password for an IAM userAn identity disabled bucket loggingAn identity started an AWS SSM sessionAn identity was granted permissions to manage user access to Azure resourcesAn operation was performed by an identity from a domain that was not seen in the organizationAn unusual archive file creation by a userAttempted Azure application access from unknown tenantAurora DB cluster stoppedAuthentication method added to an Azure accountAuthentication method was added to Azure accountAzure AD PIM elevation requestAzure AD account unlock/password reset attemptAzure Automation Account CreationAzure Automation Runbook Creation/ModificationAzure Automation Runbook DeletionAzure Automation Webhook creationAzure Blob Container Access Level ModificationAzure Event Hub Authorization rule creation/modificationAzure Key Vault Secrets were modifiedAzure Key Vault modificationAzure Kubernetes events were deletedAzure Resource Group DeletionAzure Service principal/Application creationAzure Storage Account key generatedAzure Temporary Access Pass (TAP) registered to an accountAzure account creation by a non-standard accountAzure application URI modificationAzure application consentAzure application credentials addedAzure application removedAzure audit - MFA fraud reportedAzure conditional access policy creation or modificationAzure device code authentication flow usedAzure diagnostic configuration deletionAzure group creation/deletionAzure mailbox rule creationAzure permission delegation grantedAzure service principal assigned app roleAzure storage account blob anonymous access is enabledAzure storage account cross-tenant object replication was enabledAzure storage account was publicly sharedAzure user creation/deletionAzure user password resetAzure virtual machine commands executionBitLocker key retrievalCloud Organizational policy was created or modifiedCloud Trail Logging has been stopped/suspendedCloud Watch alarm deletionCloud compute instance user data script modificationCloud compute serial console accessCloud email service activityCloud identity reached a throttling API rateCloud impersonation attempt by unusual identity typeCloud storage automatic backup disabledCloud storage delete protection disabledCloud unusual access key creationCredentials were added to Azure applicationDLP sensitive data exposed to external usersData Sharing between GCP and Google Workspace was disabledData encryption was disabledDeletion of AD CS certificate database entriesDenied API call by a Kubernetes service accountDevice Registration Policy modificationEC2 snapshot attribute has been modifiedEMAIL BETA - Email attachment with a potentially malicious file extensionEMAIL BETA - Email attachment(s) with potentially malicious MIME typeEMAIL BETA - Email containing a redirected linkEMAIL BETA - Email has a short body or subject and was sent from an external sourceEMAIL BETA - Email was received from an unknown sender using a public provider domainEMAIL BETA - Email was received from an unknown sender using a recognized domainEMAIL BETA - Suspicious Unicode character detected in emailEMAIL BETA - Usage of homograph characters detected in an emailEMAIL BETA - Well-known brand impersonation within an email's from address domainExchange compliance search createdExchange email-hiding inbox ruleExchange email-hiding transport ruleExchange inbox forwarding rule configuredExchange mailbox folder permission modificationExternal Sharing was turned on for Google DriveExternal user invitation to Azure tenantFirst SSO Resource Access in the OrganizationFirst SSO access from ASN for userFirst SSO access from ASN in organizationFirst VPN access attempt from a country in organizationFirst VPN access from ASN for userFirst VPN access from ASN in organizationFirst connection from a country in organizationGCP Firewall Rule ModificationGCP Firewall Rule creationGCP IAM Custom Role CreationGCP IAM Role DeletionGCP IAM Service Account Key DeletionGCP Logging Bucket DeletionGCP Logging Sink ModificationGCP Pub/Sub Subscription DeletionGCP Pub/Sub Topic DeletionGCP Service Account DisableGCP Service Account creationGCP Service Account deletionGCP Service Account key creationGCP Storage Bucket Configuration ModificationGCP Storage Bucket Permissions ModificationGCP Storage Bucket deletionGCP VPC Firewall Rule DeletionGCP Virtual Private Cloud (VPC) Network DeletionGCP Virtual Private Network Route CreationGCP Virtual Private Network Route DeletionGCP set IAM policy activityGmail delegation was turned on for the organizationGmail routing settings changedGoogle Marketplace restrictions were modifiedGoogle Workspace organizational unit was modifiedGoogle Workspace third-party application's security settings were changedGranting Access to an AccountIAM User added to an IAM groupIdentity assigned an Azure AD Administrator RoleInteractive login by a machine accountInteractive login from a shared user accountKubernetes Pod Created With Sensitive VolumeKubernetes Pod Created with host Inter Process Communications (IPC) namespaceKubernetes Pod created with host process ID (PID) namespaceKubernetes Privileged Pod CreationKubernetes admission controller activityKubernetes cluster events deletionKubernetes network policy modificationKubernetes pod creation with host networkKubernetes service account activity outside the clusterLocal user account creationLogin by a dormant userMFA device was removed/deactivated from an IAM userMember added to a Windows local security groupMicrosoft 365 DLP policy disabled or removedModification or Deletion of an Azure Application Gateway DetectedNetwork sniffing detected in Cloud environmentObject versioning was disabledOkta API Token CreatedOkta User Session ImpersonationOkta account unlock by adminOkta admin privilege assignmentOneDrive file downloadOneDrive file uploadOneDrive folder creationOwner added to Azure applicationOwner was added to Azure applicationPIM privilege member removalPenetration testing tool activity attemptPenetration testing tool attemptPossible GPO EnumerationPossible LDAP Enumeration Tool UsagePossible LDAP Enumeration of Microsoft Configuration ManagerPossible SPN enumerationPotential Okta access limit breachPrivileged role used by Azure applicationRare AppID usage to a rare destinationRare DLP rule match by userRare LOLBIN Process Execution by UserRare NTLM Access By User To HostRare NTLM Usage by UserRare machine account creationRare process execution by userRare process execution in organizationRemote usage of AWS Lambda's roleRemote usage of VM Service Account tokenRemote usage of an App engine Service Account tokenRemoval of an Azure Owner from an Application or Service PrincipalS3 configuration deletionSSO with abnormal operating systemSSO with abnormal user agentSSO with new operating systemSaaS suspicious external domain user activitySensitive account password reset attemptSharePoint Site Collection admin group additionSoft delete of cloud storage configuration was disabledSuccessful unusual guest user invitationSuspicious Azure AD interactive sign-in using PowerShellSuspicious External RDP LoginSuspicious NTLM authentication with machine accountSuspicious SSO access from ASNSuspicious SSO authenticationSuspicious cloud compute instance ssh keys modification attemptSuspicious domain user account creationUnusual AWS systems manager activityUnusual Conditional Access operation for an identityUnusual IAM enumeration activity by a non-user IdentityUnusual Identity and Access Management (IAM) activityUnusual certificate management activityUnusual cloud identity impersonationUnusual exec into a Kubernetes PodUnusual key management activityUnusual resource access by Azure applicationUnusual resource modification by newly seen IAM userUnusual resource modification/creationUnusual secret management activityUnusual user account enablementUnusual user account unlockUnusual weak authentication by userUnverified domain added to Azure ADUser accessed SaaS resource via anonymous linkUser account delegation changeUser added SID History to an accountUser added a new device to Okta Verify instanceUser attempted to connect from a suspicious countryVPN access with an abnormal operating systemVPN login by a dormant userVPN login with a machine accountImproved logic of 72 Informational Analytics AlertsA user accessed an abnormal number of files on a remote shared folderA user accessed an abnormal number of remote shared foldersA user accessed multiple time-consuming websitesA user accessed multiple unusual resources via SSOA user authenticated with weak NTLM to multiple hostsA user established an SMB connection to multiple hostsA user executed multiple LDAP enumeration queriesA user logged on to multiple workstations via SchannelA user observed and reported unusual activity in OktaA user performed suspiciously massive file activityA user printed an unusual number of filesA user received multiple weakly encrypted service ticketsA user requested multiple service ticketsA user took numerous screenshotsAbnormal Allocation of compute resources in multiple regionsAllocation of multiple cloud compute resourcesAn Azure identity performed multiple actions that were deniedAn identity performed a suspicious download of multiple cloud storage objectsAzure enumeration activity using Microsoft Graph APIAzure uncommon increase in API request sizesBrute-force attempt on a local accountCloud infrastructure enumeration activityCloud user performed multiple actions that were deniedDeletion of multiple cloud resourcesExchange mailbox delegation permissions addedExternal Login Password SprayExternal SaaS file-sharing activityIAM Enumeration sequenceIncrease in Job-Related Site VisitsIntense SSO failuresInternal Login Password SprayKubernetes enumeration activityMailbox enumeration activity by Azure applicationMassive file activity abnormal to processMassive file compression by userMassive file downloads from SaaS serviceMassive upload to SaaS serviceMassive upload to a rare storage or mail domainMicrosoft OneDrive enumeration activityMicrosoft OneNote enumeration activityMicrosoft SharePoint enumeration activityMicrosoft Teams enumeration activityMulti region enumeration activityMultiple Okta MFA requests sent to a userMultiple Rare Process Executions in OrganizationMultiple TGT requests for users without Kerberos pre-authenticationMultiple cloud snapshots exportMultiple failed logins from a single IPMultiple user accounts were deletedMultiple users authenticated with weak NTLM to a hostNTLM Brute ForceNTLM Password SprayOkta Reported Threat DetectedOkta account reset password attemptOkta account unlockOkta device assignmentPossible Brute-Force attemptPossible TGT reuse from different hosts (pass the ticket)Possible data exfiltration over a USB storage devicePossible internal data exfiltration over a USB storage deviceRemote account enumerationSSH authentication brute force attemptsSSO Brute ForceSSO Password SpraySensitive Exchange mail sent to external usersShort-lived Azure AD user accountStorage enumeration activitySuspicious DNS trafficUser accessed multiple O365 AIP sensitive filesUser added to a group and removedUser moved Exchange sent messages to deleted itemsVPN login Brute-Force attemptChanged metadata of an Informational Analytics BIOCUnusual DB process spawning a shell