| splunk |
Kubernetes newly seen UDP edge |
experimental |
2026-05-13 |
| splunk |
Kubernetes Nginx Ingress RFI |
production |
2026-05-13 |
| splunk |
Kubernetes Pod Created in Default Namespace |
production |
2026-05-13 |
| splunk |
Kubernetes Pod With Host Network Attachment |
production |
2026-05-13 |
| splunk |
Kubernetes Previously Unseen Container Image Name |
experimental |
2026-05-13 |
| splunk |
Kubernetes Previously Unseen Process |
experimental |
2026-05-13 |
| splunk |
Kubernetes Process Running From New Path |
experimental |
2026-05-13 |
| splunk |
Kubernetes Process with Anomalous Resource Utilisation |
experimental |
2026-05-13 |
| splunk |
Kubernetes Process with Resource Ratio Anomalies |
experimental |
2026-05-13 |
| splunk |
Kubernetes Scanner Image Pulling |
production |
2026-05-13 |
| splunk |
Kubernetes Scanning by Unauthenticated IP Address |
production |
2026-05-13 |
| splunk |
Kubernetes Shell Running on Worker Node |
experimental |
2026-05-13 |
| splunk |
Kubernetes Shell Running on Worker Node with CPU Activity |
experimental |
2026-05-13 |
| splunk |
Kubernetes Suspicious Image Pulling |
production |
2026-05-13 |
| splunk |
Kubernetes Unauthorized Access |
production |
2026-05-13 |
| splunk |
Microsoft Intune Bulk Wipe |
production |
2026-05-13 |
| splunk |
Windows Multiple Users Failed To Authenticate From Host Using NTLM |
production |
2026-05-13 |
| splunk |
Log4Shell CVE-2021-44228 Exploitation |
production |
2026-05-13 |
| splunk |
Logon Script Event Trigger Execution |
production |
2026-05-13 |
| splunk |
MacOS AMOS Stealer - Virtual Machine Check Activity |
production |
2026-05-13 |
| splunk |
MS Exchange Mailbox Replication service writing Active Server Pages |
experimental |
2026-05-13 |
| splunk |
MS Scripting Process Loading Ldap Module |
production |
2026-05-13 |
| splunk |
MS Scripting Process Loading WMI Module |
production |
2026-05-13 |
| splunk |
MSBuild Suspicious Spawned By Script Process |
production |
2026-05-13 |
| splunk |
Wmic Group Discovery |
production |
2026-05-13 |
| splunk |
WMI Recon Running Process Or Services |
production |
2026-05-13 |
| splunk |
WinRM Spawning a Process |
experimental |
2026-05-13 |
| splunk |
WinRAR Spawning Shell Application |
production |
2026-05-13 |
| splunk |
Winhlp32 Spawning a Process |
production |
2026-05-13 |
| splunk |
WinEvent Windows Task Scheduler Event Action Started |
production |
2026-05-13 |
| splunk |
WinEvent Scheduled Task Created Within Public Path |
production |
2026-05-13 |
| splunk |
WinEvent Scheduled Task Created to Spawn Shell |
production |
2026-05-13 |
| splunk |
Windows Visual Basic Commandline Compiler DNSQuery |
production |
2026-05-13 |
| splunk |
Windows User Execution Malicious URL Shortcut File |
production |
2026-05-13 |
| splunk |
Windows User Disabled Via Net |
production |
2026-05-13 |
| splunk |
Windows User Deletion Via Net |
production |
2026-05-13 |
| splunk |
Windows USBSTOR Registry Key Modification |
production |
2026-05-13 |
| splunk |
Windows Unusual NTLM Authentication Users By Source |
production |
2026-05-13 |
| splunk |
Windows Unusual NTLM Authentication Users By Destination |
production |
2026-05-13 |
| splunk |
Windows Unusual NTLM Authentication Destinations By User |
production |
2026-05-13 |