Release date: 4 August, 2025Change typeChangesAdded a new High Analytics AlertAn unusual process in ingress-nginx has accessed a service-account token fileAdded a new Informational Analytics BIOCUncommon net localgroup command executionImproved logic of 7 Low Analytics BIOCsAURL - At least one sender-related domain in the email is classified as maliciousAn RDS snapshot was exported to an unknown S3 bucketAn S3 replication policy to an unknown bucket was createdEmail was received from an unknown sender using a disposable domainExternal email display name impersonation of internal personnelLDAP AD CS Enumeration via Attack ToolUnusual hostname for the sending mail server in the email headersImproved logic of 4 Low Analytics AlertsLarge Upload (HTTPS)Logs were not collected from a data source for an abnormally long timeRisk indicators detected in emailSuspicious identity downloaded multiple objects from a bucketImproved logic of an Informational BIOCWindows Task Manager being disabled via RegistryImproved logic of 38 Informational Analytics BIOCsA new Azure email domain verification was requestedAURL - Email contains URL(s) classified as inappropriateAURL - Email contains URL(s) classified as maliciousAURL - Email was received from a newly registered domainAURL - Email was sent from a domain classified as inappropriateAURL - Unpopular domain(s) detected in an email's URL(s)AWS SES account sending settings modifiedAWS SSM send command attemptAn AWS SES identity was deletedAn Email address was added to AWS SESCloud email sending was enabledCloud email service activityEmail Punycode characters in URL(s)Email attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail suspicious Moniker link detectedEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedFirst SSO Resource Access in the OrganizationIAM role was createdPossible LDAP Enumeration Tool UsagePossible LDAP Enumeration of Microsoft Configuration ManagerRarely seen URL(s) within a well-known domain detected in your organization's emailSuspicious Unicode character detected in emailUncommon net group command executionUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUsage of homograph characters detected in an emailUsage of homograph characters detected in an email's from headerX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of 7 Informational Analytics AlertsA user executed multiple LDAP enumeration queriesCloud email infrastructure enumeration activityIP Rotation Pattern in SSO SprayIntense SSO failuresPort ScanSSO Brute ForceSSO Password SprayChanged metadata of an Informational Analytics BIOCA process connected to a rare cloud resource