DeviceProcessEvents
Notepad Chrysalis Backdoor Gupexe Spawned Binaries Excluding Known Good Notepad Hashes
DeviceNetworkEvents
Notepad Chrysalis Backdoor Gupexe Detection
DeviceProcessEventsDeviceNetworkEvents
Notepad Chrysalis Backdoor Spawned Binaries Network Connections Correlation
SigninLogs
Emergency Access Usage Alert
Nathan Hutchinson|Feb 2, 2026
AuditLogs
Azure RBAC Elevation Via User Access Admin Toggle
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceTvmInfoGatheringDeviceEvents
Windows Trigger Full Scan For Devices That Have Not Completed One Windows Clients Only
Nathan Hutchinson|Feb 2, 2026
IdentityLogonEventsIdentityInfo
Auto Disable High Risk AD User
Nathan Hutchinson|Feb 2, 2026
DeviceTvmInfoGatheringDeviceEvents
Windows Trigger Full Scan For Devices That Have Not Completed One
Nathan Hutchinson|Feb 2, 2026
DeviceTvmInfoGatheringDeviceEvents
Windows Recent Devices Missing Full Scan
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceFileEvents
Linux Suspicious Cron Persistence
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceNetworkEvents
Linux Server Public Egress Baseline High Fidelity
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceProcessEvents
Linux LO Lbin Downloads To Temporary Directories
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceEvents
Linux Script Activity Script Content
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceFileEvents
Linux File Activity Baseline
Nathan Hutchinson|Feb 2, 2026
DeviceProcessEventsDeviceNetworkEvents
Linux Archive Command Followed By Upload Egress
Nathan Hutchinson|Feb 2, 2026
DeviceNetworkEvents
Linux Network Fanout From The Upload Process
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceEvents
Linux Antivirus Activity
Nathan Hutchinson|Feb 2, 2026
DeviceProcessEvents
Linux User Activity Leading Up To Exfiltration
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceNetworkEvents
Linux Desktop Public Egress Baseline Low Noise
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceNetworkEvents
Linux Network Events Baseline Report Id Dedupe
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceLogonEvents
Linux Logon Activity
Nathan Hutchinson|Feb 2, 2026
DeviceInfoDeviceEventsDeviceProcessEvents+3
Linux Action Type Inventory All Tables
Nathan Hutchinson|Feb 2, 2026
DeviceNetworkEvents
Notepad Chrysalis Backdoor Network IO Cs
DeviceFileEvents
Notepad Chrysalis Backdoor File Hash IO Cs
DeviceInfoDeviceProcessEvents
Linux Telemetry Validation Test Process
Nathan Hutchinson|Feb 2, 2026
DeviceTvmSoftwareInventory
Microsoft Office Security Feature Bypass Vulnerability CVE 2026 21509
Sergio Albea|Jan 27, 2026
IdentityInfoExposureGraphNodes
Hunt Accounts With Leaked Credentials
Robbe Van den Daele|Jan 26, 2026
EntraIdSignInEventsAuditLogs
Authenticator Device Enrollment Country Risk Baseline
EntraIdSignInEvents
Sign In Risk Analysis
EmailUrlInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On URL IO Cs
Sergio Albea|Jan 17, 2026
EmailAttachmentInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On File Hashes IO Cs
Sergio Albea|Jan 17, 2026
EmailUrlInfoEmailEvents
IA Threat Intelligence Feed Evaluation Based On Domains IO Cs
Sergio Albea|Jan 17, 2026
EmailEventsUrlClickEventsSigninLogs
Suspicious Sign In After Phishing Link Click
Benjamin Zulliger|Jan 15, 2026
DeviceImageLoadEventsDeviceFileCertificateInfo
Monitor DL Ls By Signer
IdentityInfoSecurityEvent
Certificate Issued To Privileged User
Benjamin Zulliger|Jan 13, 2026
DeviceProcessEventsDeviceNetworkEvents
Detect Unkown Process Launched Via Win RM
Robbe Van den Daele|Jan 12, 2026
AuditLogsAADUserRiskEventsCloudAppEvents
Detect PIM Elevation With User Risk
Robbe Van den Daele|Jan 12, 2026
SigninLogsAADNonInteractiveUserSignInLogsAADUserRiskEvents
Detect Device Code With User Risk
Robbe Van den Daele|Jan 12, 2026
DeviceNetworkEventsDeviceProcessEvents
Detect Msiexec Executing Dll Network Connections
Robbe Van den Daele|Jan 12, 2026
DeviceProcessEventsDeviceFileCertificateInfo
Detect Unsigned Exec Launch From Scheduled Task
Robbe Van den Daele|Jan 12, 2026
DeviceEventsDeviceFileEvents
Detect Lol Driver Drop Or Load From Unkown Process
Robbe Van den Daele|Jan 12, 2026
DeviceProcessEvents
Detect Rare Scheduled Task Created
Robbe Van den Daele|Jan 12, 2026
DeviceNetworkEvents
Detect Unkown Process Using Smb And Winrm
Robbe Van den Daele|Jan 12, 2026
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
User With Uncommon Or Risky Behavior Is Deploying A Script With Intune To All Users Or All Devices
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
Delete An Intune Multi Approval Policy By User With Uncommon Or Risky Behavior
IntuneAuditLogsBehaviorEntitiesIdentityInfo+1
User With Uncommon Or Risky Behavior Is Deploying An Application With Intune To All Users Or All Devices
IntuneAuditLogsIdentityInfoGraphAPIAuditEvents+1
Managed Service Provider User B2B Or GDAP Without Device Compliance Or MFA Claim Is Managing Intune
IntuneAuditLogs
Mass Wipe Or Retire Device Action
SigninLogsAADNonInteractiveUserSignInLogsNetworkAccessTraffic
Consent Fix Hunting Confidence On Token And Network Signals
Thomas Naunheim|Jan 2, 2026
DeviceFileEvents
Mac OS Login Window Hooks Authorization Plugins
Benjamin Zulliger|Dec 31, 2025