Release date: 21 July, 2025Change typeChangesAdded a new Medium Analytics BIOCSuspicious dNSHostName attribute change to DC nameAdded 5 new Low Analytics BIOCsA commonly abused process connected to a rare cloud resourceA commonly abused process connected to a rare external cloud resourceRare binary connected to a rare cloud resourceRare binary connected to a rare external hostUnusual Process Spawned by Nginx in Ingress-Nginx podAdded 2 new Low Analytics AlertsMicrosoft 365 storage services exfiltration activityMultiple user accounts failed login due to account lockoutsAdded 2 new Informational Analytics BIOCsAppleScript interpreter dynamic library loaded into a processUncommon sensitive filesystem registry hive accessAdded 5 new Informational Analytics AlertsIP Rotation Pattern in SSO SprayPossible Impossible Travel Pattern - SSOPossible Privilege Escalation using Delegated MSA accountSCCM log files enumerationSingle account excessively locked outImproved logic of 2 High Analytics BIOCsA Successful VPN connection from TORA successful SSO sign-in from TORImproved logic of 4 Medium Analytics BIOCsA cloud storage object was copied to a foreign cloud accountAzure AD PIM alert disabledCloud snapshot of a database or storage instance was publicly sharedSuspicious authentication with Azure Password Hash Sync userImproved logic of 39 Low Analytics BIOCsA Backup vault policy was modifiedA Command Line Interface (CLI) command was executed from an AWS serverless compute serviceA disabled user attempted to log in to a VPNA user attempted to bypass Okta MFAAURL - An email was sent from a malicious domainAWS S3 bucket was exposed to public accessAWS data asset shared publicAbnormal communication with a rare combination of TLS and HTTP User AgentAn RDS snapshot was exported to an unknown S3 bucketAzure AD PIM role settings changeAzure account deletion by a non-standard accountAzure domain federation settings modification attemptCloud Trail logging deletionEmail was received from an unknown sender using a disposable domainExecutable or Script file written by a web server processExternal email display name impersonation of internal personnelFirst Azure AD PowerShell operation for a userGCP data asset shared publicLOLBIN process executed with a high integrity levelMFA was disabled for an Azure identityPossible webshell file written by a web server processPotential SCCM credential harvesting using WMI detectedRare process created an SSH session to an uncommon cloud resourceRare process executed by an AppleScriptRecurring rare domain access from an unsigned processSSO authentication attempt by a honey userSSO authentication by a machine accountSSO authentication by a service accountSuspicious LDAP search query executedSuspicious Print System Remote Protocol usage by a processSuspicious access of the System Management ContainerSuspicious process accessed certificate filesUnusual CIM repository file accessUnusual hostname for the sending mail server in the email headersUnusual process accessed a crypto wallet's filesUnusual process accessed a messaging app's filesUnusual process accessed a web browser history fileVPN login attempt by a honey userVPN login by a service accountImproved logic of 10 Low Analytics AlertsA user rejected an SSO request from an unusual countryImpossible traveler - SSOImpossible traveler - VPNLarge Upload (HTTPS)Logs were not collected from a data source for an abnormally long timeMultiple Azure AD admin role removalsMultiple discovery commandsRisk indicators detected in emailSuspicious identity downloaded multiple objects from a bucketUser added to the SMS Admins local groupImproved logic of 136 Informational Analytics BIOCsA Kubernetes ConfigMap was created or deletedA Kubernetes Cronjob was createdA Kubernetes cluster role binding was created or deletedA Kubernetes cluster was created or deletedA Kubernetes ephemeral container was createdA Kubernetes namespace was created or deletedA Kubernetes role binding was created or deletedA Kubernetes secret was created or deletedA Kubernetes service account was created or deletedA Kubernetes service was created or deletedA cloud identity created or modified a security groupA cloud identity executed an API call from an unusual countryA cloud identity invoked IAM related persistence operationsA cloud instance was stoppedA cloud snapshot of AWS database or storage was modified or sharedA compute-attached identity executed API calls outside the instance's regionA container registry was created or deletedA disabled user attempted to authenticate via SSOA new Azure email domain verification was requestedA possible risky login to AzureA user accessed Okta's admin applicationA user connected from a new countryA user connected to a VPN from a new countryA user created a pfx file for the first timeA user logged in at an unusual time via SSOA user logged in at an unusual time via VPNA user modified an Okta network zoneA user modified an Okta policy ruleAURL - Email contains URL(s) classified as inappropriateAURL - Email contains URL(s) classified as maliciousAURL - Email was received from a newly registered domainAURL - Email was sent from a domain classified as inappropriateAURL - Unpopular domain(s) detected in an email's URL(s)AWS Flow Logs deletionAWS SES account sending settings modifiedAWS Transfer Family server createdAn AWS SES identity was deletedAn Email address was added to AWS SESAn identity attached an administrative policy to an IAM user/roleAn identity was granted permissions to manage user access to Azure resourcesAn unusual archive file creation by a userAppleScript executed a shell scriptAuthentication method added to an Azure accountAzure AD PIM elevation requestAzure AD account unlock/password reset attemptAzure Temporary Access Pass (TAP) registered to an accountAzure account creation by a non-standard accountAzure application consentAzure application credentials addedAzure device code authentication flow usedAzure permission delegation grantedAzure service principal assigned app roleAzure storage account blob anonymous access is enabledAzure storage account was publicly sharedAzure user password resetBitLocker key retrievalCloud Unusual Instance Metadata Service (IMDS) accessCloud compute instance user data script modificationCloud compute serial console accessCloud email sending was enabledCloud email service activityCloud resource logging was disabledCloud snapshot created or modifiedData encryption was disabledDevice Registration Policy modificationEmail Punycode characters in URL(s)Email attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail suspicious Moniker link detectedEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedFirst SSO Resource Access in the OrganizationFirst SSO access from ASN for userFirst SSO access from ASN in organizationFirst VPN access attempt from a country in organizationFirst VPN access from ASN for userFirst VPN access from ASN in organizationFirst connection from a country in organizationGlobally uncommon high entropy process was executedGlobally uncommon process execution from a signed processIdentity assigned an Azure AD Administrator RoleKubernetes cluster events deletionKubernetes network policy modificationLocal user account creationMember added to a Windows local security groupNetwork sniffing detected in Cloud environmentOkta API Token CreatedOkta User Session ImpersonationOkta account unlock by adminOkta admin privilege assignmentOwner added to Azure applicationPIM privilege member removalPossible DLL Side-LoadingPossible LDAP Enumeration of Microsoft Configuration ManagerPotential Okta access limit breachRare AppID usage to a rare destinationRarely seen URL(s) within a well-known domain detected in your organization's emailRemoval of an Azure Owner from an Application or Service PrincipalSSO with abnormal operating systemSSO with abnormal user agentSSO with new operating systemSuccessful unusual guest user invitationSuspicious Azure AD interactive sign-in using PowerShellSuspicious NTLM authentication with machine accountSuspicious SSO access from ASNSuspicious SSO authenticationSuspicious Unicode character detected in emailSuspicious domain user account creationUncommon cloud CLI tool usageUncommon net group or localgroup executionUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUnusual ADConnect database file accessUnusual Conditional Access operation for an identityUnusual Identity and Access Management (IAM) activityUnusual access to the AD Sync credential filesUnusual process accessed a macOS notes DB fileUnusual process accessed web browser cookiesUnusual process accessed web browser credentialsUnusual resource modification by newly seen IAM userUsage of homograph characters detected in an emailUser added a new device to Okta Verify instanceUser attempted to connect from a suspicious countryVPN access with an abnormal operating systemVPN login by a dormant userVPN login with a machine accountWeb server CGO executed an uncommon processX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of 34 Informational Analytics AlertsA user accessed an abnormal number of files on a remote shared folderA user accessed an abnormal number of remote shared foldersA user accessed multiple time-consuming websitesA user accessed multiple unusual resources via SSOA user performed suspiciously massive file activityA user printed an unusual number of filesA user took numerous screenshotsAbnormal File Activity in SCCMContentLib Shared Folder by userAn identity performed a suspicious download of multiple cloud storage objectsCloud email infrastructure enumeration activityCloud infrastructure enumeration activityDeletion of multiple cloud resourcesExternal SaaS file-sharing activityIAM Enumeration sequenceIncrease in Job-Related Site VisitsIntense SSO failuresKubernetes enumeration activityMassive file compression by userMassive file downloads from SaaS serviceMassive upload to SaaS serviceMassive upload to a rare storage or mail domainMicrosoft Configuration Manager device registration and policy requestMultiple Okta MFA requests sent to a userNTLM RelayOkta account reset password attemptOkta account unlockPossible data exfiltration over a USB storage devicePossible internal data exfiltration over a USB storage devicePotential NTLM Relay AttackSSO Brute ForceSSO Password SprayShort-lived Azure AD user accountStorage enumeration activityVPN login Brute-Force attemptDecreased the severity to Low for an Analytics BIOCUnprivileged process opened a registry hiveDecreased the severity to Informational for an Analytics BIOCUsage of homograph characters detected in an email's from headerChanged metadata of 2 Medium Analytics BIOCsPhantom DLL LoadingWindows LOLBIN executable connected to a rare external hostChanged metadata of 7 Low Analytics BIOCsAn S3 replication policy to an unknown bucket was createdPossible DLL Hijack into a Microsoft processPossible DLL Search Order HijackingRare communication over email ports to external email server by unsigned processRare process created an SSH session to an uncommon external hostScripting engine connected to a rare external hostUncommon VNC server communicationChanged metadata of 8 Informational Analytics BIOCsA process connected to a rare cloud resourceA process connected to rare external hostGlobally uncommon image load from a signed processPossible authentication coercionPrivileged certificate request via certificate templateSuspicious MFA request reported by user in Entra IDUncommon service stop operationUnusual Kubernetes service account file read