EmailUrlInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On URL IO Cs
Sergio Albea|Jan 17, 2026
EmailAttachmentInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On File Hashes IO Cs
Sergio Albea|Jan 17, 2026
EmailUrlInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On Domains IO Cs
Sergio Albea|Jan 17, 2026
EmailEventsUrlClickEventsSigninLogs
Suspicious Sign In After Phishing Link Click
Benjamin Zulliger|Jan 15, 2026
DeviceImageLoadEventsDeviceFileCertificateInfo
Monitor DL Ls By Signer
IdentityInfoSecurityEvent
Certificate Issued To Privileged User
Benjamin Zulliger|Jan 13, 2026
DeviceEventsDeviceFileEvents
Detect Lol Driver Drop Or Load From Unkown Process
Robbe Van den Daele|Jan 12, 2026
SigninLogsAADNonInteractiveUserSignInLogsAADUserRiskEvents
Detect Device Code With User Risk
Robbe Van den Daele|Jan 12, 2026
DeviceNetworkEventsDeviceProcessEvents
Detect Msiexec Executing Dll Network Connections
Robbe Van den Daele|Jan 12, 2026
DeviceProcessEventsDeviceNetworkEvents
Detect Unkown Process Launched Via Win RM
Robbe Van den Daele|Jan 12, 2026
DeviceNetworkEvents
Detect Unkown Process Using Smb And Winrm
Robbe Van den Daele|Jan 12, 2026
DeviceProcessEventsDeviceFileCertificateInfo
Detect Unsigned Exec Launch From Scheduled Task
Robbe Van den Daele|Jan 12, 2026
DeviceProcessEvents
Detect Rare Scheduled Task Created
Robbe Van den Daele|Jan 12, 2026
AuditLogsAADUserRiskEventsCloudAppEvents
Detect PIM Elevation With User Risk
Robbe Van den Daele|Jan 12, 2026
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
User With Uncommon Or Risky Behavior Is Deploying A Script With Intune To All Users Or All Devices
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
Delete An Intune Multi Approval Policy By User With Uncommon Or Risky Behavior
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
User With Uncommon Or Risky Behavior Is Deploying An Application With Intune To All Users Or All Devices
IntuneAuditLogsIdentityInfoGraphAPIAuditEvents+1
Managed Service Provider User B2B Or GDAP Without Device Compliance Or MFA Claim Is Managing Intune
IntuneAuditLogs
Mass Wipe Or Retire Device Action
SigninLogsAADNonInteractiveUserSignInLogsNetworkAccessTraffic
Consent Fix Hunting Confidence On Token And Network Signals
Thomas Naunheim|Jan 2, 2026
KnowExploitesVulnsCISA
CISAKEV Year To Date Vulnerabilities
Bert-Jan Pals|Dec 30, 2025
KnowExploitesVulnsCISA
CISAKEV Year To Date Vulnerabilities Product
Bert-Jan Pals|Dec 30, 2025
KnowExploitesVulnsCISA
CISAKEV Year To Date Vulnerabilities Release Year
Bert-Jan Pals|Dec 30, 2025
KnowExploitesVulnsCISA
CISAKEV Year To Date Vulnerabilities Edge Devices
Bert-Jan Pals|Dec 30, 2025
AADSignInEventsBeta
AADSTS Errorcodes KQL
Benjamin Zulliger|Dec 30, 2025
DeviceProcessEvents
MDE Data Collection
Alex Verboon|Dec 22, 2025
DeviceProcessEvents
Mshta Executions
Bert-Jan Pals|Dec 22, 2025
DeviceTvmCertificateInfoDeviceInfoDeviceTvmSoftwareVulnerabilities
MDE Digi Cert Global Root G2
Alex Verboon|Dec 19, 2025
SigninLogs
Correlation Id Equals Tenant Id In Peculiar Password Spray
Jose Sebastián Canós|Dec 18, 2025
accesslog
Parse Apache Accesslog
Benjamin Zulliger|Dec 17, 2025
DeviceEventsDeviceNetworkEventsDeviceProcessEvents
Suspicious MS Build Remote Thread
Bert-Jan Pals|Dec 15, 2025
DeviceEventsDeviceInfoAlertEvidence+1
Failed AV Scan On Devices With Vulnerabilities And Related Incidents
Benjamin Zulliger|Dec 15, 2025
DeviceProcessEvents
Pod Containerexec
DeviceFileEvents
Executable Files Program Data Folder
Bert-Jan Pals|Dec 10, 2025
DeviceProcessEventsDeviceNetworkEvents
Power Shell LOLBAS Execution With Public Network Connection
Benjamin Zulliger|Dec 9, 2025
DeviceInfo
MDE Device Active Inactive
DeviceInfo
MDE Device Groups
EmailEventsEmailUrlInfo
KQL Techniques For Email URL Redirect Hunting
IdentityAccountInfoIdentityInfo
MDI Identity Password Security Posture Assessment
OfficeActivityCloudAppEvents
MDO Auto Forwarding Mode
OAuthAppInfo
O Auth App Evaluation
Benjamin Zulliger|Dec 3, 2025
resources
Azure Resource Graph APIM With Basic Auth Enabled
AuditLogs
Entra Account Disabled
AuditLogs
Entra Group Changes
AuditLogs
Entra Password Resets
AuditLogs
User Deleted From Entra
AuditLogs
Device Deleted From Entra
resources
Audit Logic Apps With Office365 Connections Using Resource Query
DeviceProcessEvents
Executables In App Data Local Roaming
resourcechanges
Azure Resource VM Sku Sizes Changes