CopilotActivity
Excessive Copilot Prompt Activity
Benjamin Zulliger|Feb 26, 2026
CopilotActivity
Microsoft Copilot Access To External Resources XPIA
Benjamin Zulliger|Feb 26, 2026
CloudAppEvents
Microsoft Copilot Jailbreak Detected
Benjamin Zulliger|Feb 26, 2026
DeviceProcessEvents
Attempt To Disable Syslog Service
Benjamin Zulliger|Feb 26, 2026
DeviceProcessEvents
Attempt To Disable Auditd Service
Benjamin Zulliger|Feb 26, 2026
ADOAuditLogs_CL
Azure Dev Ops Activity From Newor Rare IP Outside Business Hours
Benjamin Zulliger|Feb 26, 2026
ADOAuditLogs_CL
Azure Dev Ops Critical Search Queries
Benjamin Zulliger|Feb 26, 2026
ADOAuditLogs_CL
Azure Dev Ops Critical Permission Modification
Benjamin Zulliger|Feb 26, 2026
LOLDriversDeviceEvents
MDE Asr Vulnerable Signed Driver Blocked
Alex Verboon|Feb 23, 2026
DeviceProcessEvents
Click Fix Lo L Bin Abuse
Benjamin Zulliger|Feb 23, 2026
DeviceProcessEvents
Click Fix Nslookup DNS Staging
Benjamin Zulliger|Feb 23, 2026
DeviceRegistryEvents
Run MRU Click Fix Detection
Benjamin Zulliger|Feb 23, 2026
SecurityIncidentSecurityAlert
Alert Efficiency
Bert-Jan Pals|Feb 22, 2026
EntraIdSignInEvents
Entra Id Sign In Events Suspicious User Agent
EntraIdSignInEvents
Entra Id Sign In Events Hunting Potential Seamless SSO Usage
DeviceEventsDeviceNetworkInfo
Windows Summarise Firewall Outbound Blocks By Firewall Profile
Nathan Hutchinson|Feb 17, 2026
DeviceEventsDeviceNetworkInfo
Windows Outbound Firewall Blocks Filtered By Firewall Profile
Nathan Hutchinson|Feb 17, 2026
DeviceEventsDeviceNetworkInfo
Windows Outbound Firewall Blocks Filter By Device And Firewall Profile
Nathan Hutchinson|Feb 17, 2026
DeviceEventsDeviceNetworkInfo
Windows Windows Firewall Outbound Blocked Connections
Nathan Hutchinson|Feb 17, 2026
AuditLogs
Security Copilot Agent Deleted
DeviceNetworkEvents
Windows Find Net BIOS Name Service NBNS Usage UDP 137
Nathan Hutchinson|Feb 15, 2026
EmailEventsEmailUrlInfo
Applying Shanon Entropy To Sender Domains Via Kusto
Sergio Albea|Feb 12, 2026
DeviceEvents
Windows All Firewall Inbound Block Events Last 100
Nathan Hutchinson|Feb 12, 2026
IdentityLogonEvents
Windows Detect NTLM Usage In The Environment
Nathan Hutchinson|Feb 12, 2026
DeviceEvents
Windows Inbound Firewall Blocks By Process
Nathan Hutchinson|Feb 12, 2026
DeviceTvmSoftwareVulnerabilitiesDeviceProcessEventsDeviceFileEvents+2
CVE 2026 21510 Windows Shell Security Feature Bypass
Benjamin Zulliger|Feb 11, 2026
EntraUsers
Detection Enrichment Entra User
Bert-Jan Pals|Feb 11, 2026
EntraGroupMembershipsEntraGroups
Detection Enrichment Entra Group Membership
Bert-Jan Pals|Feb 10, 2026
DeviceNetworkEvents
Device IP History
MessageEventsMessageUrlInfo
Detect Malicious Teams Message
Robbe Van den Daele|Feb 10, 2026
MessageEventsIdentityInfoMessageUrlInfo
Detect External User Sending Suspicious Link To Multiple Users
Robbe Van den Daele|Feb 10, 2026
MessageEventsIdentityInfo
Detect Possible Teams Bec Attack By High Teams Recipients
Robbe Van den Daele|Feb 10, 2026
DeviceRegistryEvents
Image File Execution Options IFEO Or Silent Process Exit Registry Modification
Benjamin Zulliger|Feb 9, 2026
DeviceFileEvents
Malicious Browser Extension Downloads Using Device File Events
SigninLogsAADNonInteractiveUserSignInLogs
Detect Potential Consent Fix O Auth Authorisation Code Theft Attempts
AuditLogs
MCP Server Registered To Entra
StorageBlobLogs
Anonymous Retrieval Of Azure Blob Versions
StorageBlobLogs
Potential Storage Enumeration Or Brute Force Attack
AzureActivityAuditLogs
Unauthorized Federated Credential Added To Managed Identity
MicrosoftGraphActivityLogs
Azurekid Blackcat Security Module Activity
AuditLogs
Granting Of High Risk Privilege Escalation Permissions To Service Principal
MicrosoftGraphActivityLogs
Service Principal Enumeration Of App Role Assignments
AuditLogs
Service Principal Adds Client Secret To Target Application
AADServicePrincipalSignInLogs
Service Principal Sign In From New Country
AuditLogs
Privileged Role Assignment Outside Of PIM
AuditLogs
Service Principal Added To Global Administrator Role
StorageFileLogs
Successful Azure Storage File Access From Unauthorized Geo Location
DeviceProcessEvents
Notepad Chrysalis Backdoor Gupexe Spawned Binaries Excluding Known Good Notepad Hashes
DeviceNetworkEvents
Notepad Chrysalis Backdoor Gupexe Detection
DeviceProcessEventsDeviceNetworkEvents
Notepad Chrysalis Backdoor Spawned Binaries Network Connections Correlation