Release date: 17 September, 2025Change typeChangesAdded 4 new Low Analytics BIOCsMshta.exe spawns from a browser processPowerShell runs suspicious base64-encoded commandsRecurring access to rare domainUncommon sensitive registry hive dumpAdded 14 new Informational Analytics BIOCsA cloud identity started a Cloud Shell sessionA third-party utility was copied to a different locationAn EBS snapshot block was downloadedAn unknown account was invited to the AWS organizationCloud compute volume creation attemptCloud instance creation attemptCloud instance deletion attemptEBS volume attachment attemptEBS volume detachment attemptExecution of masqueraded third-party utilityExecution of renamed lolbinPotential creation of persistent cloud credentialsUnusual AWS CLI/SDK activityUnusual Kubernetes secret accessImproved logic of 6 Medium Analytics BIOCsA cloud storage object was copied to a foreign cloud accountCorrelation rule errorError in event forwardingKubernetes vulnerability scanning tool usageParsing Rule ErrorPenetration testing tool activityImproved logic of a Medium Analytics AlertA new machine attempted Kerberos delegationImproved logic of 10 Low Analytics BIOCsAzure account deletion by a non-standard accountEmail attachment with Right-to-Left Override Unicode characterEmail was received from an unknown sender using a disposable domainExternal email display name impersonation of internal personnelLinux system firewall was modifiedPotential SCCM credential harvesting using WMI detectedRare process created an SSH session to an uncommon cloud resourceRare process created an SSH session to an uncommon external hostSuspicious access of the System Management ContainerSuspicious modification of the AdminSDHolder's ACLImproved logic of 6 Low Analytics AlertsA compromised process accessed a rare external hostAn identity dumped multiple secrets from a projectLarge Upload (Generic)Large Upload (HTTPS)Logs were not collected from a data source for an abnormally long timeRisk indicators detected in emailImproved logic of 49 Informational Analytics BIOCsA cloud identity had escalated its permissionsA process connected to a rare cloud resourceA process connected to rare external hostA user was added to a Windows security groupAWS STS temporary credentials were generatedActivity in a dormant region of a cloud projectAn identity started an AWS SSM sessionAuthentication method added to an Azure accountAzure AD account unlock/password reset attemptAzure account creation by a non-standard accountAzure device code authentication flow usedAzure permission delegation grantedCloud impersonation attempt by unusual identity typeEmail Punycode characters in URL(s)Email attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail contains URL delivering high-risk file typeEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail suspicious Moniker link detectedEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedEmail with file-sharing link containing auto-download parameterIdentity assigned an Azure AD Administrator RolePenetration testing tool activity attemptPenetration testing tool attemptPotential DCSync by an unusual userRarely seen URL(s) within a well-known domain detected in your organization's emailSSO with abnormal user agentSending unusual file(s) to an external addressSuspicious SPF ResultSuspicious Unicode character detected in emailUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUnrecognized internal address (AAD mismatch)Unusual AWS systems manager activityUnusual Identity and Access Management (IAM) activityUnusual cloud identity impersonationUnusual hostname for the sending mail server in the email headersUnusual resource modification/creationUsage of homograph characters detected in an emailUsage of homograph characters detected in an email's from headerX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of 10 Informational Analytics AlertsAbnormal SMB scanning activity to multiple hostsCloud email infrastructure enumeration activityCloud infrastructure enumeration activityInternal Login Password SprayMulti region enumeration activityMultiple failed logins from a single IPNumerous emails sent by a single sender to multiple internal recipientsPossible Privilege Escalation using Delegated MSA accountSuspicious theme and sentiment in emailUnusual attachment volume in outbound emailsDecreased the severity to Informational for an Analytics BIOCModification of NTLM restrictions in the RegistryChanged metadata of 2 Low Analytics BIOCsFirst Azure AD PowerShell operation for a userOkta FastPass reported phishing attack suspectedChanged metadata of 3 Informational Analytics BIOCsA possible risky login to AzureCloud compute serial console accessSuspicious cloud compute instance SSH keys modification attemptRemoved 2 old Medium Analytics BIOCsPowerShell runs suspicious base64-encoded commandsVulnerable driver loadedRemoved an old Low BIOCMshta.exe spawns from a browserRemoved an old Low Analytics BIOCExecution of renamed lolbin