Cloud Detections

Name Data Source Technique Type Analytic Story Date
O365 ZAP Activity Detection Office 365 Universal Audit Log T1566.001 T1566.002 Anomaly Spearphishing Attachments, Suspicious Emails 2026-05-13
AWS Defense Evasion Impair Security Services AWS CloudTrail DeleteIPSet, AWS CloudTrail DeleteRuleGroup, AWS CloudTrail DeleteAlarms, AWS CloudTrail DeleteWebACL, AWS CloudTrail DeleteLogStream, AWS CloudTrail DeleteDetector, AWS CloudTrail DeleteLoggingConfiguration, AWS CloudTrail DeleteRule T1685.002 TTP AWS Defense Evasion 2026-05-13
O365 Excessive SSO logon errors O365 UserLoginFailed T1556 Anomaly Office 365 Account Takeover, Cloud Federated Credential Abuse 2026-05-13
GCP Successful Single-Factor Authentication Google Workspace T1078.004 T1586.003 TTP Scattered Lapsus$ Hunters, GCP Account Takeover 2026-05-13
Kubernetes Scanner Image Pulling T1526 TTP Dev Sec Ops 2026-05-13
O365 Email Transport Rule Changed Office 365 Universal Audit Log T1114.003 T1564.008 Anomaly Office 365 Account Takeover, Data Exfiltration 2026-05-13
O365 Advanced Audit Disabled O365 Change user license. T1685.002 TTP Office 365 Persistence Mechanisms 2026-05-13
ASL AWS IAM Successful Group Deletion ASL AWS CloudTrail T1069.003 T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
AWS SAML Update identity provider AWS CloudTrail UpdateSAMLProvider T1078 TTP Cloud Federated Credential Abuse 2026-05-13
ASL AWS IAM AccessDenied Discovery Events ASL AWS CloudTrail T1580 Anomaly Suspicious Cloud User Activities 2026-05-13
ASL AWS Disable Bucket Versioning ASL AWS CloudTrail T1490 Anomaly Data Exfiltration, Suspicious AWS S3 Activities 2026-05-13
ASL AWS ECR Container Upload Unknown User ASL AWS CloudTrail T1204.003 Anomaly Dev Sec Ops 2026-05-13
AWS Multiple Failed MFA Requests For User AWS CloudTrail ConsoleLogin T1586.003 T1621 Anomaly AWS Identity and Access Management Account Takeover 2026-05-13
AWS Network Access Control List Created with All Open Ports AWS CloudTrail CreateNetworkAclEntry, AWS CloudTrail ReplaceNetworkAclEntry T1686.001 TTP AWS Network ACL Activity 2026-05-13
O365 Cross-Tenant Access Change Office 365 Universal Audit Log T1484.002 TTP Azure Active Directory Persistence 2026-05-13
Kubernetes newly seen UDP edge T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
GCP Detect gcploit framework T1078 TTP GCP Cross Account Activity 2026-05-13
Kubernetes Cron Job Creation Kubernetes Audit T1053.007 Anomaly Kubernetes Security 2026-05-13
Cloud Provisioning Activity From Previously Unseen IP Address AWS CloudTrail T1078 Anomaly Suspicious Cloud Provisioning Activities 2026-05-13
O365 Service Principal Privilege Escalation O365 Add app role assignment grant to user. T1098.003 TTP Office 365 Account Takeover, Azure Active Directory Privilege Escalation 2026-05-13
Microsoft Intune Device Health Scripts Azure Monitor Activity T1021.007 T1072 T1105 T1202 Hunting Azure Active Directory Account Takeover 2026-05-13
Azure AD Multiple Denied MFA Requests For User Azure Active Directory Sign-in activity T1621 TTP Azure Active Directory Account Takeover 2026-05-13
Detect AWS Console Login by New User AWS CloudTrail T1552 T1586.003 Hunting Suspicious Cloud Authentication Activities, AWS Identity and Access Management Account Takeover 2026-05-13
O365 SharePoint Suspicious Search Behavior Office 365 Universal Audit Log T1213.002 T1552 Anomaly Office 365 Account Takeover, Compromised User Account, CISA AA22-320A, Office 365 Collection Techniques 2026-05-13
O365 File Permissioned Application Consent Granted by User O365 Consent to application. T1528 TTP Office 365 Account Takeover 2026-05-13
O365 Email Reported By User Found Malicious Office 365 Universal Audit Log T1566.001 T1566.002 TTP Spearphishing Attachments, Suspicious Emails 2026-05-13
ASL AWS New MFA Method Registered For User ASL AWS CloudTrail T1556.006 TTP AWS Identity and Access Management Account Takeover 2026-05-13
Kubernetes Nginx Ingress LFI T1212 TTP Dev Sec Ops 2026-05-13
O365 Email Security Feature Changed Office 365 Universal Audit Log T1685.002 TTP Office 365 Account Takeover, Office 365 Persistence Mechanisms 2026-05-13
AWS Excessive Security Scanning AWS CloudTrail T1526 TTP AWS User Monitoring 2026-05-13
GitHub Organizations Disable Dependabot GitHub Organizations Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
Azure AD Successful PowerShell Authentication Azure Active Directory T1078.004 T1586.003 TTP Azure Active Directory Account Takeover 2026-05-13
Azure AD New Federated Domain Added Azure Active Directory Set domain authentication T1484.002 TTP Hellcat Ransomware, Azure Active Directory Persistence, Storm-0501 Ransomware, Scattered Lapsus$ Hunters 2026-05-13
Gsuite Drive Share In External Email G Suite Drive T1567.002 Anomaly Insider Threat, Scattered Lapsus$ Hunters, Dev Sec Ops 2026-05-13
AWS ECR Container Upload Outside Business Hours AWS CloudTrail PutImage T1204.003 Anomaly Dev Sec Ops 2026-05-13
ASL AWS ECR Container Upload Outside Business Hours ASL AWS CloudTrail T1204.003 Anomaly Dev Sec Ops 2026-05-13
AWS Exfiltration via Bucket Replication AWS CloudTrail PutBucketReplication T1537 TTP Data Exfiltration, Suspicious AWS S3 Activities 2026-05-13
Kubernetes Shell Running on Worker Node with CPU Activity T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
O365 Multiple Service Principals Created by User O365 Add service principal. T1136.003 Anomaly NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Cloud Provisioning Activity From Previously Unseen City AWS CloudTrail T1078 Anomaly Suspicious Cloud Provisioning Activities 2026-05-13
Gsuite Suspicious Shared File Name G Suite Drive T1566.001 Anomaly Dev Sec Ops 2026-05-13
Detect Spike in AWS Security Hub Alerts for User AWS Security Hub N/A Anomaly AWS Security Hub Alerts, Critical Alerts 2026-05-13
ASL AWS Defense Evasion Delete CloudWatch Log Group ASL AWS CloudTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
Kubernetes Nginx Ingress RFI T1212 TTP Dev Sec Ops 2026-05-13
ASL AWS UpdateLoginProfile ASL AWS CloudTrail T1136.003 TTP AWS IAM Privilege Escalation 2026-05-13
O365 Mailbox Email Forwarding Enabled T1114.003 TTP Office 365 Collection Techniques 2026-05-13
AWS Console Login Failed During MFA Challenge AWS CloudTrail ConsoleLogin T1586.003 T1621 TTP Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
AWS Lambda UpdateFunctionCode AWS CloudTrail T1204 Hunting Suspicious Cloud User Activities 2026-05-13
ASL AWS Detect Users creating keys with encrypt policy without MFA ASL AWS CloudTrail T1486 TTP Ransomware Cloud 2026-05-13
O365 Multi-Source Failed Authentications Spike O365 UserLoginFailed T1110.003 T1110.004 T1586.003 Hunting Office 365 Account Takeover, NOBELIUM Group 2026-05-13
O365 Privileged Role Assigned Office 365 Universal Audit Log T1098.003 TTP Azure Active Directory Persistence, Scattered Lapsus$ Hunters 2026-05-13
Detect Spike in AWS Security Hub Alerts for EC2 Instance AWS Security Hub N/A Anomaly AWS Security Hub Alerts, Critical Alerts 2026-05-13
Azure AD AzureHound UserAgent Detected Azure Active Directory MicrosoftGraphActivityLogs, Azure Active Directory NonInteractiveUserSignInLogs T1087.004 T1526 TTP Compromised User Account, Azure Active Directory Privilege Escalation 2026-05-13
AWS Concurrent Sessions From Different Ips AWS CloudTrail DescribeEventAggregates T1185 TTP Scattered Lapsus$ Hunters, Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
O365 Bypass MFA via Trusted IP O365 Set Company Information. T1686.001 TTP Office 365 Persistence Mechanisms 2026-05-13
Azure AD External Guest User Invited Azure Active Directory Invite external user T1136.003 TTP Azure Active Directory Persistence 2026-05-13
Microsoft Intune Mobile Apps Azure Monitor Activity T1021.007 T1072 T1105 T1202 Hunting Azure Active Directory Account Takeover 2026-05-13
Kubernetes Scanning by Unauthenticated IP Address Kubernetes Audit T1046 Anomaly Kubernetes Security 2026-05-13
AWS ECR Container Scanning Findings Low Informational Unknown AWS CloudTrail DescribeImageScanFindings T1204.003 Anomaly Dev Sec Ops 2026-05-13
AWS Credential Access Failed Login AWS CloudTrail ConsoleLogin T1110.001 T1586.003 TTP AWS Identity and Access Management Account Takeover 2026-05-13
O365 Privileged Graph API Permission Assigned O365 Update application. T1003.002 TTP NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Kubernetes Falco Shell Spawned Kubernetes Falco T1204 Anomaly Kubernetes Security 2026-05-13
AWS Exfiltration via EC2 Snapshot AWS CloudTrail DescribeSnapshotAttribute, AWS CloudTrail DeleteSnapshot, AWS CloudTrail ModifySnapshotAttribute, AWS CloudTrail CreateSnapshot T1537 TTP Data Exfiltration, Suspicious Cloud Instance Activities 2026-05-13
Azure AD OAuth Application Consent Granted By User Azure Active Directory Consent to application T1528 TTP Azure Active Directory Account Takeover 2026-05-13
AWS IAM AccessDenied Discovery Events AWS CloudTrail T1580 Anomaly Suspicious Cloud User Activities 2026-05-13
Amazon EKS Kubernetes cluster scan detection T1526 Hunting Kubernetes Scanning Activity 2026-05-13
Kubernetes Abuse of Secret by Unusual Location Kubernetes Audit T1552.007 Anomaly Kubernetes Security 2026-05-13
Detect Spike in blocked Outbound Traffic from your AWS N/A Anomaly Command And Control, Suspicious AWS Traffic, AWS Network ACL Activity 2026-05-13
O365 PST export alert O365 T1114 TTP Office 365 Collection Techniques, Data Exfiltration 2026-05-13
GCP Multiple Users Failing To Authenticate From Ip Google Workspace T1110.003 T1110.004 T1586.003 Anomaly GCP Account Takeover 2026-05-13
AWS Bedrock Delete Model Invocation Logging Configuration AWS CloudTrail DeleteModelInvocationLoggingConfiguration T1685.002 TTP AWS Bedrock Security 2026-05-13
Cloud Compute Instance Created By Previously Unseen User AWS CloudTrail T1078.004 Anomaly Cloud Cryptomining 2026-05-13
O365 High Number Of Failed Authentications for User O365 UserLoginFailed T1110.001 TTP Office 365 Account Takeover 2026-05-13
Kubernetes Abuse of Secret by Unusual User Name Kubernetes Audit T1552.007 Anomaly Kubernetes Security 2026-05-13
ASL AWS Multi-Factor Authentication Disabled ASL AWS CloudTrail T1556.006 T1586.003 T1621 TTP AWS Identity and Access Management Account Takeover 2026-05-13
GitHub Enterprise Disable IP Allow List GitHub Enterprise Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
O365 Add App Role Assignment Grant User O365 Add app role assignment grant to user. T1136.003 TTP Cloud Federated Credential Abuse, Office 365 Persistence Mechanisms 2026-05-13
Azure AD Privileged Authentication Administrator Role Assigned Azure Active Directory Add member to role T1003.002 TTP Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation 2026-05-13
AWS Defense Evasion Update Cloudtrail AWS CloudTrail UpdateTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
GitHub Organizations Repository Archived GitHub Organizations Audit Logs T1195 T1485 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
Azure AD Service Principal Authentication Azure Active Directory Sign-in activity T1078.004 TTP NOBELIUM Group, Azure Active Directory Account Takeover 2026-05-13
Kubernetes Anomalous Outbound Network Activity from Process T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Azure AD Global Administrator Role Assigned Azure Active Directory Add member to role T1098.003 TTP Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
AWS IAM Assume Role Policy Brute Force AWS CloudTrail T1110 T1580 TTP AWS IAM Privilege Escalation 2026-05-13
AWS Network Access Control List Deleted AWS CloudTrail DeleteNetworkAclEntry T1686.001 Anomaly AWS Network ACL Activity 2026-05-13
O365 New Forwarding Mailflow Rule Created T1114 TTP Office 365 Collection Techniques 2026-05-13
O365 FullAccessAsApp Permission Assigned O365 Update application. T1098.002 T1098.003 TTP NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
ASL AWS Create Access Key ASL AWS CloudTrail T1136.003 Hunting AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
Azure AD High Number Of Failed Authentications From Ip Azure Active Directory T1110.001 T1110.003 TTP NOBELIUM Group, Azure Active Directory Account Takeover, Compromised User Account 2026-05-13
Azure AD Concurrent Sessions From Different Ips Azure Active Directory T1185 TTP Azure Active Directory Account Takeover, Compromised User Account, Scattered Lapsus$ Hunters 2026-05-13
Azure AD PIM Role Assigned Azure Active Directory T1098.003 TTP Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
Azure AD Tenant Wide Admin Consent Granted Azure Active Directory Consent to application T1098.003 TTP NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
Kubernetes Abuse of Secret by Unusual User Agent Kubernetes Audit T1552.007 Anomaly Kubernetes Security 2026-05-13
O365 DLP Rule Triggered Office 365 Universal Audit Log T1048 T1567 Anomaly Data Exfiltration 2026-05-13
AWS ECR Container Scanning Findings Medium AWS CloudTrail DescribeImageScanFindings T1204.003 Anomaly Dev Sec Ops 2026-05-13
AWS Successful Single-Factor Authentication AWS CloudTrail ConsoleLogin T1078.004 T1586.003 TTP AWS Identity and Access Management Account Takeover 2026-05-13
AWS CreateLoginProfile AWS CloudTrail ConsoleLogin, AWS CloudTrail CreateLoginProfile T1136.003 TTP AWS IAM Privilege Escalation 2026-05-13
AWS Bedrock Delete Knowledge Base AWS CloudTrail DeleteKnowledgeBase T1485 TTP AWS Bedrock Security 2026-05-13
AWS Exfiltration via Anomalous GetObject API Activity AWS CloudTrail GetObject T1119 Anomaly Data Exfiltration 2026-05-13
GitHub Organizations Delete Branch Ruleset GitHub Organizations Audit Logs T1195 T1685 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
AWS Credential Access RDS Password reset AWS CloudTrail ModifyDBInstance T1110 T1586.003 TTP Scattered Lapsus$ Hunters, AWS Identity and Access Management Account Takeover 2026-05-13
ASL AWS Network Access Control List Created with All Open Ports ASL AWS CloudTrail T1686.001 TTP AWS Network ACL Activity 2026-05-13
GitHub Enterprise Register Self Hosted Runner GitHub Enterprise Audit Logs T1195 T1685 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
AWS Detect Users with KMS keys performing encryption S3 AWS CloudTrail T1486 Anomaly Ransomware Cloud 2026-05-13
ASL AWS Defense Evasion Update Cloudtrail ASL AWS CloudTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
O365 Email Send Attachments Excessive Volume Office 365 Universal Audit Log T1070.008 T1485 Anomaly Office 365 Account Takeover, Suspicious Emails 2026-05-13
Azure AD Device Code Authentication Azure Active Directory T1528 T1566.002 TTP Azure Active Directory Account Takeover 2026-05-13
AWS EC2 Snapshot Shared Externally AWS CloudTrail ModifySnapshotAttribute T1537 TTP Data Exfiltration, Suspicious Cloud Instance Activities 2026-05-13
GitHub Enterprise Repository Deleted GitHub Enterprise Audit Logs T1195 T1485 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
O365 Privileged Role Assigned To Service Principal Office 365 Universal Audit Log T1098.003 TTP Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation 2026-05-13
O365 SharePoint Malware Detection Office 365 Universal Audit Log T1204.002 TTP Office 365 Account Takeover, Azure Active Directory Persistence, Ransomware Cloud 2026-05-13
O365 Multiple Mailboxes Accessed via API O365 MailItemsAccessed T1114.002 TTP Office 365 Collection Techniques, NOBELIUM Group 2026-05-13
AWS Disable Bucket Versioning AWS CloudTrail PutBucketVersioning T1490 Anomaly Data Exfiltration, Suspicious AWS S3 Activities 2026-05-13
O365 Safe Links Detection Office 365 Universal Audit Log T1566.001 TTP Office 365 Account Takeover, Spearphishing Attachments 2026-05-13
AWS Defense Evasion Delete CloudWatch Log Group AWS CloudTrail DeleteLogGroup T1685.002 TTP AWS Defense Evasion 2026-05-13
GCP Multi-Factor Authentication Disabled Google Workspace T1556.006 T1586.003 TTP Scattered Lapsus$ Hunters, GCP Account Takeover 2026-05-13
GCP Unusual Number of Failed Authentications From Ip Google Workspace T1110.003 T1110.004 T1586.003 Anomaly GCP Account Takeover 2026-05-13
Azure AD Multiple Service Principals Created by User Azure Active Directory Add service principal T1136.003 Anomaly NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
Kubernetes Previously Unseen Process T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Kubernetes Abuse of Secret by Unusual User Group Kubernetes Audit T1552.007 Anomaly Kubernetes Security 2026-05-13
Detect New Open S3 buckets AWS CloudTrail T1530 TTP Suspicious AWS S3 Activities 2026-05-13
AWS Credential Access GetPasswordData AWS CloudTrail GetPasswordData T1110.001 T1586.003 Anomaly AWS Identity and Access Management Account Takeover 2026-05-13
ASL AWS Defense Evasion Stop Logging Cloudtrail ASL AWS CloudTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
GitHub Enterprise Delete Branch Ruleset GitHub Enterprise Audit Logs T1195 T1685 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
O365 Application Registration Owner Added O365 Add owner to application. T1098 TTP NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Azure AD User Consent Denied for OAuth Application Azure Active Directory Sign-in activity T1528 TTP Azure Active Directory Account Takeover 2026-05-13
ASL AWS Concurrent Sessions From Different Ips ASL AWS CloudTrail T1185 Anomaly Scattered Lapsus$ Hunters, Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
AWS SetDefaultPolicyVersion AWS CloudTrail SetDefaultPolicyVersion T1078.004 TTP AWS IAM Privilege Escalation 2026-05-13
O365 Security And Compliance Alert Triggered T1078.004 TTP Office 365 Account Takeover 2026-05-13
AWS Detect Users creating keys with encrypt policy without MFA AWS CloudTrail CreateKey, AWS CloudTrail PutKeyPolicy T1486 TTP Ransomware Cloud 2026-05-13
AWS Multiple Users Failing To Authenticate From Ip AWS CloudTrail ConsoleLogin T1110.003 T1110.004 Anomaly Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
ASL AWS Credential Access RDS Password reset ASL AWS CloudTrail T1110 T1586.003 TTP Scattered Lapsus$ Hunters, AWS Identity and Access Management Account Takeover 2026-05-13
Kubernetes newly seen TCP edge T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Circle CI Disable Security Job CircleCI T1554 Anomaly Dev Sec Ops 2026-05-13
Gdrive suspicious file sharing T1566 Hunting Data Exfiltration, Spearphishing Attachments, Scattered Lapsus$ Hunters 2026-05-13
Detect S3 access from a new IP T1530 Anomaly Suspicious AWS S3 Activities 2026-05-13
AWS Successful Console Authentication From Multiple IPs AWS CloudTrail ConsoleLogin T1535 T1586 Anomaly Compromised User Account, Suspicious AWS Login Activities 2026-05-13
GCP Authentication Failed During MFA Challenge Google Workspace login_failure T1078.004 T1586.003 T1621 TTP Scattered Lapsus$ Hunters, GCP Account Takeover 2026-05-13
Azure AD Service Principal Privilege Escalation Azure Active Directory Add app role assignment to service principal T1098.003 TTP Azure Active Directory Privilege Escalation 2026-05-13
ASL AWS Credential Access GetPasswordData ASL AWS CloudTrail T1110.001 T1586.003 Anomaly AWS Identity and Access Management Account Takeover 2026-05-13
Kubernetes Anomalous Inbound to Outbound Network IO Ratio T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
O365 Email Suspicious Search Behavior Office 365 Universal Audit Log T1114.002 T1552 Anomaly Office 365 Account Takeover, Compromised User Account, CISA AA22-320A, Office 365 Collection Techniques 2026-05-13
O365 OAuth App Mailbox Access via Graph API O365 MailItemsAccessed T1114.002 TTP Office 365 Collection Techniques, NOBELIUM Group 2026-05-13
AWS Exfiltration via Batch Service AWS CloudTrail JobCreated T1119 TTP Data Exfiltration 2026-05-13
O365 Service Principal New Client Credentials O365 T1098.001 TTP NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Microsoft Intune Bulk Wipe Azure Monitor Activity T1561.001 TTP Azure Active Directory Account Takeover 2026-05-13
GitHub Organizations Disable 2FA Requirement GitHub Organizations Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
O365 Mail Permissioned Application Consent Granted by User O365 Consent to application. T1528 TTP Office 365 Account Takeover 2026-05-13
Gsuite Email Suspicious Subject With Attachment G Suite Gmail T1566.001 Anomaly Dev Sec Ops 2026-05-13
O365 Email Password and Payroll Compromise Behavior Office 365 Reporting Message Trace, Office 365 Universal Audit Log T1070.008 T1114.001 T1485 TTP Office 365 Account Takeover, Data Destruction, Office 365 Collection Techniques, Suspicious Emails 2026-05-13
AWS ECR Container Upload Unknown User AWS CloudTrail PutImage T1204.003 Anomaly Dev Sec Ops 2026-05-13
Azure AD Multiple Failed MFA Requests For User Azure Active Directory Sign-in activity T1078.004 T1586.003 T1621 TTP Azure Active Directory Account Takeover 2026-05-13
O365 New Federated Domain Added O365 T1136.003 TTP Cloud Federated Credential Abuse, Office 365 Persistence Mechanisms 2026-05-13
O365 Threat Intelligence Suspicious File Detected Office 365 Universal Audit Log T1204.002 TTP Office 365 Account Takeover, Azure Active Directory Account Takeover, Ransomware Cloud 2026-05-13
Kubernetes Shell Running on Worker Node T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Circle CI Disable Security Step CircleCI T1554 Anomaly Dev Sec Ops 2026-05-13
O365 Mailbox Read Access Granted to Application O365 Update application. T1098.003 T1114.002 TTP Office 365 Persistence Mechanisms 2026-05-13
O365 Block User Consent For Risky Apps Disabled O365 Update authorization policy. T1685 TTP Office 365 Account Takeover 2026-05-13
GitHub Enterprise Disable Audit Log Event Stream GitHub Enterprise Audit Logs T1195 T1685.002 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
O365 Exfiltration via File Sync Download Office 365 Universal Audit Log T1530 T1567 Anomaly Office 365 Account Takeover, Data Exfiltration 2026-05-13
O365 Email Receive and Hard Delete Takeover Behavior Office 365 Reporting Message Trace, Office 365 Universal Audit Log T1070.008 T1114.001 T1485 Anomaly Office 365 Account Takeover, Data Destruction, Office 365 Collection Techniques, Suspicious Emails 2026-05-13
O365 New MFA Method Registered O365 Update user. T1098.005 TTP Office 365 Persistence Mechanisms 2026-05-13
O365 Disable MFA O365 Disable Strong Authentication. T1556 TTP Office 365 Persistence Mechanisms 2026-05-13
O365 Added Service Principal O365 T1136.003 TTP NOBELIUM Group, Cloud Federated Credential Abuse, Office 365 Persistence Mechanisms 2026-05-13
AWS Bedrock Delete GuardRails AWS CloudTrail DeleteGuardrail T1685.002 TTP AWS Bedrock Security 2026-05-13
ASL AWS Defense Evasion Impair Security Services ASL AWS CloudTrail T1685.002 Hunting AWS Defense Evasion 2026-05-13
AWS High Number Of Failed Authentications For User AWS CloudTrail ConsoleLogin T1201 Anomaly Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
AWS UpdateLoginProfile AWS CloudTrail UpdateLoginProfile T1136.003 TTP AWS IAM Privilege Escalation 2026-05-13
Detect AWS Console Login by User from New Region AWS CloudTrail T1535 T1586.003 Hunting Compromised User Account, Suspicious Cloud Authentication Activities, AWS Identity and Access Management Account Takeover, Suspicious AWS Login Activities 2026-05-13
Kubernetes Process with Resource Ratio Anomalies T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Cloud Compute Instance Created In Previously Unused Region AWS CloudTrail T1535 Anomaly Cloud Cryptomining 2026-05-13
Kubernetes Anomalous Inbound Outbound Network IO T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
ASL AWS Network Access Control List Deleted ASL AWS CloudTrail T1686.001 Anomaly Scattered Lapsus$ Hunters, AWS Network ACL Activity 2026-05-13
Kubernetes Node Port Creation Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
O365 High Privilege Role Granted O365 Add member to role. T1098.003 TTP Office 365 Persistence Mechanisms 2026-05-13
Azure AD Service Principal Created Azure Active Directory Add service principal T1136.003 TTP NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
Cloud Compute Instance Created With Previously Unseen Instance Type AWS CloudTrail T1578.002 Anomaly Cloud Cryptomining 2026-05-13
O365 Email Hard Delete Excessive Volume Office 365 Universal Audit Log T1070.008 T1485 Anomaly Office 365 Account Takeover, Data Destruction, Suspicious Emails 2026-05-13
Okta Non-Standard VPN Usage Okta T1078 T1090 T1572 TTP Remote Employment Fraud, Suspicious Okta Activity 2026-05-13
ASL AWS IAM Delete Policy ASL AWS CloudTrail T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
Azure AD Block User Consent For Risky Apps Disabled Azure Active Directory Update authorization policy T1685 TTP Azure Active Directory Account Takeover 2026-05-13
AWS AMI Attribute Modification for Exfiltration AWS CloudTrail ModifyImageAttribute T1537 TTP Data Exfiltration, Suspicious Cloud Instance Activities 2026-05-13
Cloud Provisioning Activity From Previously Unseen Country AWS CloudTrail T1078 Anomaly Suspicious Cloud Provisioning Activities 2026-05-13
Azure AD Service Principal Owner Added Azure Active Directory Add owner to application T1098 TTP NOBELIUM Group, Azure Active Directory Persistence, Azure Active Directory Privilege Escalation 2026-05-13
Azure Runbook Webhook Created Azure Audit Create or Update an Azure Automation webhook T1078.004 TTP Azure Active Directory Persistence 2026-05-13
AWS S3 Exfiltration Behavior Identified T1537 Correlation Data Exfiltration, Suspicious Cloud Instance Activities 2026-05-13
Detect AWS Console Login by User from New City AWS CloudTrail T1535 T1586.003 Hunting Compromised User Account, Suspicious Cloud Authentication Activities, AWS Identity and Access Management Account Takeover, Suspicious AWS Login Activities 2026-05-13
Kubernetes Suspicious Image Pulling Kubernetes Audit T1526 Anomaly Kubernetes Security 2026-05-13
AWS Defense Evasion Delete Cloudtrail AWS CloudTrail DeleteTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
ASL AWS EC2 Snapshot Shared Externally ASL AWS CloudTrail T1537 TTP Data Exfiltration, Suspicious Cloud Instance Activities 2026-05-13
O365 Multiple OS Vendors Authenticating From User Office 365 Universal Audit Log T1110 TTP Office 365 Account Takeover 2026-05-13
GitHub Organizations Disable Classic Branch Protection Rule GitHub Organizations Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
O365 SharePoint Allowed Domains Policy Changed Office 365 Universal Audit Log T1136.003 TTP Azure Active Directory Persistence 2026-05-13
Kubernetes Previously Unseen Container Image Name T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Microsoft Intune Manual Device Management Azure Monitor Activity T1021.007 T1072 T1529 Hunting Azure Active Directory Account Takeover 2026-05-13
Kubernetes Anomalous Inbound Network Activity from Process T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
O365 Exfiltration via File Access Office 365 Universal Audit Log T1530 T1567 Anomaly Office 365 Account Takeover, Data Exfiltration 2026-05-13
Kubernetes Pod With Host Network Attachment Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
O365 Email Suspicious Behavior Alert Office 365 Universal Audit Log T1114.003 TTP Office 365 Collection Techniques, Office 365 Account Takeover, Suspicious Emails 2026-05-13
O365 Compliance Content Search Started T1114.002 TTP Office 365 Collection Techniques 2026-05-13
Azure AD PIM Role Assignment Activated Azure Active Directory T1098.003 TTP Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
O365 Email New Inbox Rule Created Office 365 Universal Audit Log T1114.003 T1564.008 Anomaly Office 365 Collection Techniques 2026-05-13
AWS IAM Delete Policy AWS CloudTrail DeletePolicy T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
AWS Unusual Number of Failed Authentications From Ip AWS CloudTrail ConsoleLogin T1110.003 T1110.004 T1586.003 Anomaly AWS Identity and Access Management Account Takeover 2026-05-13
Cloud Compute Instance Created With Previously Unseen Image AWS CloudTrail N/A Anomaly Cloud Cryptomining 2026-05-13
Detect New Open S3 Buckets over AWS CLI AWS CloudTrail T1530 TTP Suspicious AWS S3 Activities 2026-05-13
O365 Multiple AppIDs and UserAgents Authentication Spike O365 UserLoginFailed, O365 UserLoggedIn T1078 Anomaly Office 365 Account Takeover 2026-05-13
AWS High Number Of Failed Authentications From Ip AWS CloudTrail ConsoleLogin T1110.003 T1110.004 Anomaly Compromised User Account, AWS Identity and Access Management Account Takeover 2026-05-13
GitHub Enterprise Modify Audit Log Event Stream GitHub Enterprise Audit Logs T1195 T1685.002 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
Azure AD Multiple AppIDs and UserAgents Authentication Spike Azure Active Directory Sign-in activity T1078 Anomaly Azure Active Directory Account Takeover 2026-05-13
GitHub Enterprise Disable Dependabot GitHub Enterprise Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
AWS Create Policy Version to allow all resources AWS CloudTrail CreatePolicyVersion T1078.004 TTP AWS IAM Privilege Escalation 2026-05-13
Gsuite Email With Known Abuse Web Service Link G Suite Gmail T1566.001 Anomaly Dev Sec Ops 2026-05-13
Cloud Instance Modified By Previously Unseen User AWS CloudTrail T1078.004 Anomaly Suspicious Cloud Instance Activities 2026-05-13
Azure AD Multiple Service Principals Created by SP Azure Active Directory Add service principal T1136.003 Anomaly NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
AWS New MFA Method Registered For User AWS CloudTrail CreateVirtualMFADevice T1556.006 TTP AWS Identity and Access Management Account Takeover 2026-05-13
Kubernetes Create or Update Privileged Pod Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
O365 New Email Forwarding Rule Enabled T1114.003 TTP Office 365 Collection Techniques 2026-05-13
Azure AD New Custom Domain Added Azure Active Directory Add unverified domain T1484.002 TTP Azure Active Directory Persistence 2026-05-13
O365 New Email Forwarding Rule Created T1114.003 TTP Office 365 Collection Techniques 2026-05-13
GitHub Enterprise Pause Audit Log Event Stream GitHub Enterprise Audit Logs T1195 T1685.002 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
Azure AD Unusual Number of Failed Authentications From Ip Azure Active Directory T1110.003 T1110.004 T1586.003 Anomaly Azure Active Directory Account Takeover 2026-05-13
AWS Defense Evasion PutBucketLifecycle AWS CloudTrail PutBucketLifecycle T1485.001 T1685.002 Hunting AWS Defense Evasion 2026-05-13
Azure Automation Account Created Azure Audit Create or Update an Azure Automation account T1136.003 TTP Azure Active Directory Persistence 2026-05-13
AWS IAM Failure Group Deletion AWS CloudTrail DeleteGroup T1098 Anomaly AWS IAM Privilege Escalation 2026-05-13
Azure AD FullAccessAsApp Permission Assigned Azure Active Directory Update application T1098.002 T1098.003 TTP NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
Azure AD Service Principal Enumeration Azure Active Directory MicrosoftGraphActivityLogs T1087.004 T1526 TTP Compromised User Account, Azure Active Directory Privilege Escalation 2026-05-13
Azure AD Multi-Factor Authentication Disabled Azure Active Directory Disable Strong Authentication T1556.006 T1586.003 TTP Azure Active Directory Account Takeover, Scattered Lapsus$ Hunters 2026-05-13
O365 External Guest User Invited Office 365 Universal Audit Log T1136.003 TTP Azure Active Directory Persistence 2026-05-13
Azure AD Successful Single-Factor Authentication Azure Active Directory T1078.004 T1586.003 TTP Azure Active Directory Account Takeover 2026-05-13
O365 Excessive Authentication Failures Alert T1110 Anomaly Office 365 Account Takeover 2026-05-13
Kubernetes Pod Created in Default Namespace Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
Kubernetes AWS detect suspicious kubectl calls Kubernetes Audit N/A Anomaly Kubernetes Security 2026-05-13
AWS Defense Evasion Stop Logging Cloudtrail AWS CloudTrail StopLogging T1685.002 TTP AWS Defense Evasion 2026-05-13
O365 Email Send and Hard Delete Exfiltration Behavior Office 365 Reporting Message Trace, Office 365 Universal Audit Log T1070.008 T1114.001 T1485 Anomaly Office 365 Account Takeover, Data Destruction, Office 365 Collection Techniques, Suspicious Emails 2026-05-13
Kubernetes DaemonSet Deployed Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
O365 Mailbox Folder Read Permission Assigned O365 ModifyFolderPermissions T1098.002 TTP Office 365 Collection Techniques 2026-05-13
Azure AD Service Principal New Client Credentials Azure Active Directory T1098.001 TTP NOBELIUM Group, Azure Active Directory Persistence, Azure Active Directory Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
Kubernetes Access Scanning Kubernetes Audit T1046 Anomaly Kubernetes Security 2026-05-13
AWS ECR Container Scanning Findings High AWS CloudTrail DescribeImageScanFindings T1204.003 TTP Dev Sec Ops 2026-05-13
Detect AWS Console Login by User from New Country AWS CloudTrail T1535 T1586.003 Hunting Compromised User Account, Suspicious Cloud Authentication Activities, AWS Identity and Access Management Account Takeover, Suspicious AWS Login Activities 2026-05-13
GitHub Enterprise Disable Classic Branch Protection Rule GitHub Enterprise Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
GSuite Email Suspicious Attachment G Suite Gmail T1566.001 Anomaly Dev Sec Ops 2026-05-13
O365 External Identity Policy Changed Office 365 Universal Audit Log T1136.003 TTP Azure Active Directory Persistence 2026-05-13
Azure AD Multiple Users Failing To Authenticate From Ip Azure Active Directory T1110.003 T1110.004 T1586.003 Anomaly Azure Active Directory Account Takeover 2026-05-13
O365 Threat Intelligence Suspicious Email Delivered Office 365 Universal Audit Log T1566.001 T1566.002 Anomaly Spearphishing Attachments, Suspicious Emails 2026-05-13
ASL AWS Create Policy Version to allow all resources ASL AWS CloudTrail T1078.004 TTP AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
AWS Exfiltration via DataSync Task AWS CloudTrail CreateTask T1119 TTP Hellcat Ransomware, Data Exfiltration, Suspicious AWS S3 Activities 2026-05-13
Azure AD Application Administrator Role Assigned Azure Active Directory Add member to role T1098.003 TTP Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation 2026-05-13
Detect New Open GCP Storage Buckets T1530 TTP Suspicious GCP Storage Activities 2026-05-13
O365 Application Available To Other Tenants Office 365 Universal Audit Log T1098.003 TTP Azure Active Directory Account Takeover, Azure Active Directory Persistence, Data Exfiltration 2026-05-13
Azure AD Privileged Role Assigned Azure Active Directory Add member to role T1098.003 TTP NOBELIUM Group, Azure Active Directory Persistence, Storm-0501 Ransomware, Scattered Lapsus$ Hunters 2026-05-13
Azure AD Privileged Graph API Permission Assigned Azure Active Directory Update application T1003.002 TTP NOBELIUM Group, Azure Active Directory Persistence 2026-05-13
O365 Multiple Service Principals Created by SP O365 Add service principal. T1136.003 Anomaly NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Kubernetes Process with Anomalous Resource Utilisation T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
Azure AD New MFA Method Registered Azure Active Directory Update user T1098.005 TTP Azure Active Directory Persistence, Scattered Lapsus$ Hunters 2026-05-13
Cloud API Calls From Previously Unseen User Roles AWS CloudTrail T1078 Anomaly Suspicious Cloud User Activities 2026-05-13
O365 Multiple Failed MFA Requests For User O365 UserLoginFailed T1621 TTP Office 365 Account Takeover, Scattered Lapsus$ Hunters 2026-05-13
ASL AWS Defense Evasion PutBucketLifecycle ASL AWS CloudTrail T1485.001 T1685.002 Hunting AWS Defense Evasion 2026-05-13
GitHub Organizations Repository Deleted GitHub Organizations Audit Logs T1195 T1485 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
O365 OAuth App Mailbox Access via EWS O365 MailItemsAccessed T1114.002 TTP Office 365 Collection Techniques, NOBELIUM Group 2026-05-13
O365 Admin Consent Bypassed by Service Principal O365 Add app role assignment to service principal. T1098.003 TTP Office 365 Persistence Mechanisms 2026-05-13
Azure AD New MFA Method Registered For User Azure Active Directory User registered security info T1556.006 TTP Azure Active Directory Account Takeover, Compromised User Account, Scattered Lapsus$ Hunters 2026-05-13
AWS Bedrock Invoke Model Access Denied AWS CloudTrail T1078 T1550 TTP AWS Bedrock Security 2026-05-13
Azure AD Privileged Role Assigned to Service Principal Azure Active Directory Add member to role T1098.003 TTP NOBELIUM Group, Scattered Lapsus$ Hunters, Azure Active Directory Privilege Escalation 2026-05-13
O365 ApplicationImpersonation Role Assigned O365 T1098.002 TTP Office 365 Collection Techniques, NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
Azure AD Multi-Source Failed Authentications Spike Azure Active Directory T1110.003 T1110.004 T1586.003 Hunting NOBELIUM Group, Azure Active Directory Account Takeover 2026-05-13
AWS Password Policy Changes AWS CloudTrail DeleteAccountPasswordPolicy, AWS CloudTrail GetAccountPasswordPolicy, AWS CloudTrail UpdateAccountPasswordPolicy T1201 Hunting AWS IAM Privilege Escalation, Compromised User Account 2026-05-13
ASL AWS Defense Evasion Delete Cloudtrail ASL AWS CloudTrail T1685.002 TTP AWS Defense Evasion 2026-05-13
AWS IAM Successful Group Deletion AWS CloudTrail DeleteGroup T1069.003 T1098 Hunting AWS IAM Privilege Escalation 2026-05-13
Azure AD User ImmutableId Attribute Updated Azure Active Directory Update user T1098 TTP Hellcat Ransomware, Azure Active Directory Persistence 2026-05-13
Gsuite Outbound Email With Attachment To External Domain G Suite Gmail T1048.003 Hunting Insider Threat, Dev Sec Ops 2026-05-13
Azure AD User Consent Blocked for Risky Application Azure Active Directory Consent to application T1528 TTP Azure Active Directory Account Takeover 2026-05-13
Azure AD Admin Consent Bypassed by Service Principal Azure Active Directory Add app role assignment to service principal T1098.003 TTP NOBELIUM Group, Azure Active Directory Privilege Escalation 2026-05-13
High Number of Login Failures from a single source O365 UserLoginFailed T1110.001 Anomaly Office 365 Account Takeover 2026-05-13
Kubernetes Anomalous Traffic on Network Edge T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
O365 User Consent Blocked for Risky Application O365 Consent to application. T1528 TTP Office 365 Account Takeover 2026-05-13
Kubernetes Process Running From New Path T1204 Anomaly Abnormal Kubernetes Behavior using Splunk Infrastructure Monitoring 2026-05-13
O365 Email Reported By Admin Found Malicious Office 365 Universal Audit Log T1566.001 T1566.002 TTP Spearphishing Attachments, Suspicious Emails 2026-05-13
GitHub Enterprise Remove Organization GitHub Enterprise Audit Logs T1195 T1485 Anomaly GitHub Malicious Activity 2026-05-13
Detect Spike in S3 Bucket deletion AWS CloudTrail T1530 Anomaly Suspicious AWS S3 Activities 2026-05-13
Kubernetes Unauthorized Access Kubernetes Audit T1204 Anomaly Kubernetes Security 2026-05-13
ASL AWS SAML Update identity provider ASL AWS CloudTrail T1078 TTP Cloud Federated Credential Abuse 2026-05-13
Azure Automation Runbook Created Azure Audit Create or Update an Azure Automation Runbook T1136.003 TTP Azure Active Directory Persistence 2026-05-13
Microsoft Intune DeviceManagementConfigurationPolicies Azure Monitor Activity T1021.007 T1072 T1484 T1685 T1686 Hunting Azure Active Directory Account Takeover 2026-05-13
AWS Multi-Factor Authentication Disabled AWS CloudTrail DeleteVirtualMFADevice, AWS CloudTrail DeactivateMFADevice T1556.006 T1586.003 T1621 TTP Scattered Lapsus$ Hunters, AWS Identity and Access Management Account Takeover 2026-05-13
Azure AD User Enabled And Password Reset Azure Active Directory Reset password (by admin), Azure Active Directory Update user, Azure Active Directory Enable account T1098 TTP Azure Active Directory Persistence, Scattered Lapsus$ Hunters 2026-05-13
Gsuite suspicious calendar invite T1566 Hunting Spearphishing Attachments 2026-05-13
Amazon EKS Kubernetes Pod scan detection T1526 Hunting Kubernetes Scanning Activity 2026-05-13
GitHub Enterprise Disable 2FA Requirement GitHub Enterprise Audit Logs T1195 T1685 Anomaly GitHub Malicious Activity 2026-05-13
Geographic Improbable Location Okta T1078 Anomaly Remote Employment Fraud 2026-05-13
ASL AWS IAM Failure Group Deletion ASL AWS CloudTrail T1098 Anomaly AWS IAM Privilege Escalation 2026-05-13
O365 Email Access By Security Administrator Office 365 Universal Audit Log T1114.002 T1567 TTP Office 365 Account Takeover, Data Exfiltration, Azure Active Directory Account Takeover 2026-05-13
Cloud Provisioning Activity From Previously Unseen Region AWS CloudTrail T1078 Anomaly Suspicious Cloud Provisioning Activities 2026-05-13
Azure AD Successful Authentication From Different Ips Azure Active Directory T1110.001 T1110.003 TTP Azure Active Directory Account Takeover, Compromised User Account 2026-05-13
Risk Rule for Dev Sec Ops by Repository T1204.003 Correlation Dev Sec Ops 2026-05-13
GitHub Enterprise Repository Archived GitHub Enterprise Audit Logs T1195 T1485 Anomaly NPM Supply Chain Compromise, GitHub Malicious Activity 2026-05-13
O365 Concurrent Sessions From Different Ips O365 UserLoggedIn T1185 TTP Office 365 Account Takeover, Scattered Lapsus$ Hunters 2026-05-13
Azure AD Authentication Failed During MFA Challenge Azure Active Directory T1078.004 T1586.003 T1621 TTP Azure Active Directory Account Takeover 2026-05-13
O365 Multiple Users Failing To Authenticate From Ip O365 UserLoginFailed T1110.003 T1110.004 T1586.003 TTP Office 365 Account Takeover, NOBELIUM Group 2026-05-13
O365 Mailbox Inbox Folder Shared with All Users O365 ModifyFolderPermissions T1114.002 TTP Office 365 Persistence Mechanisms 2026-05-13
Cloud Security Groups Modifications by User AWS CloudTrail T1578.005 Anomaly Suspicious Cloud User Activities 2026-05-13
ASL AWS IAM Assume Role Policy Brute Force ASL AWS CloudTrail T1110 T1580 TTP AWS IAM Privilege Escalation, Scattered Lapsus$ Hunters 2026-05-13
GCP Multiple Failed MFA Requests For User Google Workspace T1078.004 T1586.003 T1621 TTP Scattered Lapsus$ Hunters, GCP Account Takeover 2026-05-13
O365 Tenant Wide Admin Consent Granted O365 Consent to application. T1098.003 TTP NOBELIUM Group, Office 365 Persistence Mechanisms 2026-05-13
GCP Kubernetes cluster pod scan detection T1526 Hunting Scattered Lapsus$ Hunters, Kubernetes Scanning Activity 2026-05-13
O365 Elevated Mailbox Permission Assigned O365 Add-MailboxPermission T1098.002 TTP Office 365 Collection Techniques 2026-05-13
Azure Active Directory High Risk Sign-in Azure Active Directory T1110.003 T1586.003 TTP Azure Active Directory Account Takeover 2026-05-13
AWS CreateAccessKey AWS CloudTrail CreateAccessKey T1136.003 Hunting AWS IAM Privilege Escalation 2026-05-13
O365 User Consent Denied for OAuth Application O365 T1528 TTP Office 365 Account Takeover 2026-05-13
O365 Exfiltration via File Download Office 365 Universal Audit Log T1530 T1567 Anomaly Office 365 Account Takeover, Data Exfiltration 2026-05-13
Detect GCP Storage access from a new IP T1530 Anomaly Suspicious GCP Storage Activities 2026-05-13
O365 Email Send and Hard Delete Suspicious Behavior Office 365 Universal Audit Log T1070.008 T1114.001 T1485 Anomaly Office 365 Account Takeover, Data Destruction, Office 365 Collection Techniques, Suspicious Emails 2026-05-13
O365 Compliance Content Search Exported T1114.002 TTP Office 365 Collection Techniques 2026-05-13
O365 BEC Email Hiding Rule Created T1564.008 TTP Office 365 Account Takeover 2026-05-13
O365 Mailbox Folder Read Permission Granted O365 ModifyFolderPermissions T1098.002 TTP Office 365 Collection Techniques 2026-05-13
Azure AD High Number Of Failed Authentications For User Azure Active Directory T1110.001 TTP Azure Active Directory Account Takeover, Compromised User Account 2026-05-13
AWS Bedrock High Number List Foundation Model Failures AWS CloudTrail T1580 TTP AWS Bedrock Security 2026-05-13