Release date: 27 October, 2025Change typeChangesAdded 2 new Medium Analytics BIOCsLogging was impaired via external encryption keySuspicious HTTP parameters detectedAdded 20 new Informational Analytics BIOCsA process is masquerading as a common Microsoft productCommon third-party software name masqueradingEBS snapshots were created from an EC2 instanceExecutable moved to Windows system folderExternal email with a single internal recipient hidden in BCCIAM instance profile associations were describedIAM instance profile was associated with EC2 instanceIAM instance profile was createdIAM instance profile was replaced for EC2 instanceIAM instance profiles were listedIAM policy was attached to roleIAM role-attached managed policies were listedLaunch Agent persistency registered or modifiedOutbound email contains file-sharing service link sent to external recipientOutbound email includes an external BCC recipient observed for the first timePotential spoofing of internal domain spottedSuspicious DKIM ResultSuspicious DMARC resultUncommon access to a sensitive fileUsage of homograph characters detected in an email attachment(s) nameAdded 2 new Informational Analytics AlertsA compromised process accessed a rare cloud resourceAbnormal connections to a dormant host from a newly seen endpointImproved logic of 3 Medium Analytics BIOCsPossible code downloading from a remote host by Regsvr32Uncommon Service Create/ConfigUnsigned process injecting into a Windows system binary with no command lineImproved logic of a Medium Analytics AlertKerberos User EnumerationImproved logic of 7 Low Analytics BIOCsEmail attachment with Right-to-Left Override Unicode characterEmail was received from an unknown sender using a disposable domainLDAP search query from an unpopular and unsigned processNon-browser access to a pastebin-like sitePossible DCSync from a non domain controllerRecurring rare domain access from an unsigned processSuspicious LDAP search query executedImproved logic of 5 Low Analytics AlertsLarge Upload (Generic)Large Upload (HTTPS)Logs were not collected from a data source for an abnormally long timeRare LDAP enumerationRisk indicators detected in emailImproved logic of 51 Informational Analytics BIOCsA new Azure email domain verification was requestedA process connected to a rare cloud resourceAWS CloudTrail has been stoppedAWS CloudTrail modificationAWS SES account sending settings modifiedAWS SSM send command attemptAbnormal Recurring Communications to a Rare DomainAn AWS SES identity was deletedAn Email address was added to AWS SESAn identity started an AWS SSM sessionCloud compute serial console accessCloud email sending was enabledCloud email service activityEmail attachment with a potentially malicious file extensionEmail attachment with multiple extensionsEmail attachment(s) with potentially malicious MIME typeEmail containing a link with an IP address convention was detectedEmail containing a redirected linkEmail contains URL delivering high-risk file typeEmail has a short body or subject and was sent from an external sourceEmail marked as spam and bulk based on Spam Confidence Level and Bulk Complaint Level valuesEmail mimics replies or forwards without an actual ongoing conversationEmail was received from an unknown address using a public provider domainEmail was received from an unknown sender using a recognized domainEmail with URL shortener detectedEmail with file-sharing link containing auto-download parameterExecution of an uncommon process at an early startup stageGCP logging sink modificationIAM role was createdKubernetes nsenter container escapeMoniker link detected in URL(s)Punycode characters detected in URL(s)Rare connection to external IP address or host by an application using RMI-IIOP or LDAP protocolRarely seen URL(s) within a well-known domain detected in your organization's emailSending unusual file(s) to an external addressSuspicious SPF ResultSuspicious SSO authenticationSuspicious Unicode character detected in emailSuspicious cloud compute instance SSH keys modification attemptUncommon Linux shell command executionUncommon SQL like command lineUnpopular URL domain(s) in your organization detected in emailUnpopular URL(s) detected in emailUnpopular domains detected in email URLs for a recipientUnrecognized internal address (AAD mismatch)Unusual AWS systems manager activityUnusual hostname for the sending mail server in the email headersUsage of homograph characters detected in an emailUsage of homograph characters detected in an email's from headerUser attempted to connect from a suspicious countryX-Forefront-Antispam-Report has flagged this email as a potential threatImproved logic of 10 Informational Analytics AlertsAbnormal Allocation of compute resources in multiple regionsCloud email infrastructure enumeration activityIP Rotation Pattern in SSO SprayIntense SSO failuresNumerous emails sent by a single sender to multiple internal recipientsPort ScanPossible LDAP enumeration by unsigned processSSO Password SpraySuspicious reconnaissance using LDAPUnusual attachment volume in outbound emailsDecreased the severity to Informational for 3 Analytics BIOCsCloudTrail logging deletionExternal email display name impersonation of internal personnelGCP logging sink deletionChanged metadata of a High Analytics BIOCSuspicious API call from a Tor exit nodeChanged metadata of a High Analytics AlertSuspicious objects encryption in an AWS bucketChanged metadata of 3 Medium Analytics BIOCsA cloud storage object was copied to a foreign cloud accountCloud snapshot of a database or storage instance was publicly sharedSuspicious usage of EC2 tokenChanged metadata of 8 Low Analytics BIOCsA Backup vault policy was modifiedAWS S3 bucket was exposed to public accessAWS data asset shared publicAn RDS snapshot was exported to an unknown S3 bucketAn S3 replication policy to an unknown bucket was createdDisable encryption operationsGCP data asset shared publicRemote usage of an AWS service tokenChanged metadata of a Low Analytics AlertSuspicious identity downloaded multiple objects from a bucketChanged metadata of 45 Informational Analytics BIOCsA cloud identity had escalated its permissionsA cloud snapshot of AWS database or storage was modified or sharedA cloud storage configuration was modifiedA process modified an SSH authorized_keys fileA third-party utility was copied to a different locationA user logged in to the AWS console for the first timeAWS EC2 instance exported into S3AWS RDS cluster deletionAWS STS temporary credentials were generatedAWS Transfer Family server createdAn AWS EFS File-share mount was deletedAn AWS EFS file-share was deletedAn AWS RDS Global Cluster DeletionAn AWS RDS instance was created from a snapshotAn AWS S3 bucket configuration was modifiedAn AWS database service master user password was changedAn EBS snapshot block was downloadedAn identity disabled bucket loggingAn identity was granted permissions to manage user access to Azure resourcesAn unusual cloud identity was granted permissions to a BigQuery resourceAurora DB cluster stoppedAzure Blob Container Access Level ModificationAzure Storage Account key generatedAzure storage account blob anonymous access is enabledAzure storage account cross-tenant object replication was enabledAzure storage account was publicly sharedBigQuery table or query results exfiltrated to a foreign projectCloud resource logging was disabledCloud snapshot created or modifiedCloud storage automatic backup disabledCloud storage delete protection disabledData encryption was disabledEBS volume attachment attemptEC2 snapshot attribute has been modifiedExecution of masqueraded third-party utilityExecution of renamed lolbinGCP Logging Bucket DeletionGCP Storage Bucket Configuration ModificationGCP Storage Bucket Permissions ModificationGCP Storage Bucket deletionObject versioning was disabledRemote usage of AWS Lambda's roleS3 configuration deletionSoft delete of cloud storage configuration was disabledUnusual Identity and Access Management (IAM) activityChanged metadata of 5 Informational Analytics AlertsAn identity performed a suspicious download of multiple cloud storage objectsDeletion of multiple cloud resourcesMultiple cloud snapshots exportMultiple failed logins from a single IPStorage enumeration activityRemoved an old Low Analytics BIOCPossible Microsoft process masquerading