DeviceTvmCertificateInfoDeviceInfoDeviceTvmSoftwareVulnerabilities
MDE Digi Cert Global Root G2
Alex Verboon|Dec 19, 2025
SigninLogs
Correlation Id Equals Tenant Id In Peculiar Password Spray
Jose Sebastián Canós|Dec 18, 2025
DeviceEventsDeviceNetworkEventsDeviceProcessEvents
Suspicious MS Build Remote Thread
Bert-Jan Pals|Dec 15, 2025
DeviceProcessEvents
Pod Containerexec
DeviceFileEvents
Executable Files Program Data Folder
Bert-Jan Pals|Dec 10, 2025
DeviceInfo
MDE Device Groups
DeviceInfo
MDE Device Active Inactive
EmailEventsEmailUrlInfo
KQL Techniques For Email URL Redirect Hunting
IdentityAccountInfoIdentityInfo
MDI Identity Password Security Posture Assessment
OfficeActivityCloudAppEvents
MDO Auto Forwarding Mode
resources
Azure Resource Graph APIM With Basic Auth Enabled
AuditLogs
Entra Account Disabled
AuditLogs
Entra Group Changes
AuditLogs
Entra Password Resets
AuditLogs
User Deleted From Entra
AuditLogs
Device Deleted From Entra
resources
Audit Logic Apps With Office365 Connections Using Resource Query
DeviceProcessEvents
Executables In App Data Local Roaming
resourcechanges
Azure Resource VM Sku Sizes Changes
IdentityInfo
UEBA Find Onpremise Users With Password Not Required
resourcechanges
Azure Resource VM Sku Sizes
DeviceEvents
MDI Automatic Windows Auditing Configuration
Alex Verboon|Nov 22, 2025
TorExitNodesHistoricDeviceNetworkEvents
IC Tor Exit Browser Hunting Based On Device Events
Sergio Albea|Nov 18, 2025
DeviceProcessEventsDeviceImageLoadEvents
Rustdeskexecution
ExposureGraphNodesExposureGraphEdges
Hunt Critical Credentials On Non Cred Guard Devices
Robbe Van den Daele|Nov 11, 2025
DeviceFileEventsDeviceNetworkEvents
Data Staging File Zilla Ps FTP Winscp
DeviceProcessEvents
Veeam PSQL Dump
DeviceEvents
DNS Zone Export
DeviceProcessEvents
Sshtunneltoexternalhost
DeviceProcessEvents
NTD Sdumpwbadmin
DeviceProcessEvents
Bumblee Bee Initiailaccess
DeviceProcessEvents
TH Obfuscated Or Encoded Commandline
DeviceInfoDeviceNetworkInfoDeviceNetworkEvents
LM Internal Threat Hunting Over Routers Devices
DeviceNetworkEvents
Detecting Abuse Of Sync Thing Tool To Steal Data
DeviceImageLoadEventsDeviceEventsDeviceNetworkEvents
Sliver C2beacon Loaded
Bert-Jan Pals|Nov 6, 2025
AlertEvidence
NRT Auto IR High Impact Alert
Bert-Jan Pals|Nov 4, 2025
SigninLogs
Entra Identify And Map Authentication Context Usage
AuditLogs
Access Review On Role Assignable Group Auto Deleted
AlertEvidenceAlertInfo
XDR Upn Alerts
Bert-Jan Pals|Nov 1, 2025
DeviceRegistryEvents
Detecting Modification Of Windows Security Audit Policy Auditpolexe
Sergio Albea|Oct 29, 2025
DeviceProcessEvents
Detecting Execution Of Windows Security Audit Policy Auditpolexe
Sergio Albea|Oct 29, 2025
IdentityLogonEventsDeviceNetworkInfoDeviceInfo
Detect Suspicious Spn Logon From Workstation
Robbe Van den Daele|Oct 24, 2025
DeviceNetworkEvents
Detect Dump Guard Ntlm Challenge
Robbe Van den Daele|Oct 24, 2025
OfficeActivity
Third Party Phishing Report Malfunction
Jose Sebastián Canós|Oct 21, 2025
AuditLogs
Audit When PIM Fails To Remove An Eligible Member From Role
EmailAttachmentInfoDeviceFileEventsDeviceEvents
Detect Last Pass Hack Emails Attempts To Trick Users Into Installing Malware
Sergio Albea|Oct 16, 2025
DeviceFileEvents
Identifying File Exfiltration Via RDP Sessions
Sergio Albea|Oct 15, 2025
DeviceProcessEvents
Cache Smuggle
DeviceFileEvents
NTDS File Create Modify
IdentityLogonEvents
Identities Bad Reputation ASN Activities
Sergio Albea|Oct 10, 2025