IntuneAuditLogsBehaviorEntitiesIdentityInfo+1

Delete An Intune Multi Approval Policy By User With Uncommon Or Risky Behavior

IntuneAuditLogsBehaviorEntitiesIdentityInfo+1

User With Uncommon Or Risky Behavior Is Deploying An Application With Intune To All Users Or All Devices

IntuneAuditLogsBehaviorEntitiesIdentityInfo+1

User With Uncommon Or Risky Behavior Is Deploying A Script With Intune To All Users Or All Devices

IntuneAuditLogsIdentityInfoGraphAPIAuditEvents+1

Managed Service Provider User B2B Or GDAP Without Device Compliance Or MFA Claim Is Managing Intune

IntuneAuditLogs

Mass Wipe Or Retire Device Action

SigninLogsAADNonInteractiveUserSignInLogsNetworkAccessTraffic

Consent Fix Hunting Confidence On Token And Network Signals

KnowExploitesVulnsCISA

CISAKEV Year To Date Vulnerabilities

KnowExploitesVulnsCISA

CISAKEV Year To Date Vulnerabilities Product

KnowExploitesVulnsCISA

CISAKEV Year To Date Vulnerabilities Release Year

KnowExploitesVulnsCISA

CISAKEV Year To Date Vulnerabilities Edge Devices

AADSignInEventsBeta

AADSTS Errorcodes KQL

DeviceProcessEvents

MDE Data Collection

DeviceProcessEvents

Mshta Executions

DeviceTvmCertificateInfoDeviceInfoDeviceTvmSoftwareVulnerabilities

MDE Digi Cert Global Root G2

SigninLogs

Correlation Id Equals Tenant Id In Peculiar Password Spray

accesslog

Parse Apache Accesslog

DeviceEventsDeviceNetworkEventsDeviceProcessEvents

Suspicious MS Build Remote Thread

DeviceEventsDeviceInfoAlertEvidence+1

Failed AV Scan On Devices With Vulnerabilities And Related Incidents

DeviceProcessEvents

Pod Containerexec

DeviceFileEvents

Executable Files Program Data Folder

DeviceProcessEventsDeviceNetworkEvents

Power Shell LOLBAS Execution With Public Network Connection

DeviceInfo

MDE Device Active Inactive

DeviceInfo

MDE Device Groups

EmailEventsEmailUrlInfo

KQL Techniques For Email URL Redirect Hunting

IdentityAccountInfoIdentityInfo

MDI Identity Password Security Posture Assessment

OfficeActivityCloudAppEvents

MDO Auto Forwarding Mode

OAuthAppInfo

O Auth App Evaluation

resources

Azure Resource Graph APIM With Basic Auth Enabled

AuditLogs

Entra Account Disabled

AuditLogs

Entra Group Changes

AuditLogs

Entra Password Resets

AuditLogs

User Deleted From Entra

AuditLogs

Device Deleted From Entra

resources

Audit Logic Apps With Office365 Connections Using Resource Query

DeviceProcessEvents

Executables In App Data Local Roaming

resourcechanges

Azure Resource VM Sku Sizes Changes

IdentityInfo

UEBA Find Onpremise Users With Password Not Required

ThreatIntelIndicatorsMessageUrlInfoMessageEvents

TI URL Or Domain Hit In Teams Messages

resourcechanges

Azure Resource VM Sku Sizes

DeviceEvents

MDI Automatic Windows Auditing Configuration

DeviceTvmSoftwareInventory

Detect Compromised Chalk Packages

TorExitNodesHistoricDeviceNetworkEvents

IC Tor Exit Browser Hunting Based On Device Events

DeviceFileEvents

Mac OS Launch Agent Or Daemon Plist File Creation Or Modification

DeviceProcessEvents

Suspicious Unsigned File Executed In User Writeable Folder

DeviceProcessEventsDeviceImageLoadEvents

Rustdeskexecution

ExposureGraphNodesExposureGraphEdges

Hunt Critical Credentials On Non Cred Guard Devices

DeviceFileEventsDeviceNetworkEvents

Data Staging File Zilla Ps FTP Winscp

DeviceProcessEvents

Veeam PSQL Dump

DeviceEvents

DNS Zone Export

DeviceProcessEvents

Sshtunneltoexternalhost