| elastic |
AWS IAM Roles Anywhere Profile Creation |
production |
2026-09-18 |
| elastic |
AWS IAM Roles Anywhere Trust Anchor Created with External CA |
production |
2026-09-18 |
| elastic |
AWS IAM SAML Provider Created |
production |
2026-09-18 |
| elastic |
Okta User Session Impersonation |
production |
2026-09-18 |
| elastic |
Okta Successful Login After Credential Attack |
production |
2026-09-18 |
| elastic |
Potentially Successful Okta MFA Bombing via Push Notifications |
production |
2026-09-18 |
| elastic |
Potential Okta Password Spray (Single Source) |
production |
2026-09-18 |
| elastic |
Potential Okta Password Spray (Multi-Source) |
production |
2026-09-18 |
| elastic |
Potential Okta MFA Bombing via Push Notifications |
production |
2026-09-18 |
| elastic |
Potential Okta Credential Stuffing (Single Source) |
production |
2026-09-18 |
| elastic |
AWS SES Full Access Policy Attached to IAM Entity by Unusual User |
production |
2026-09-18 |
| elastic |
AWS IAM User Created Access Keys For Another User |
production |
2026-09-18 |
| elastic |
AWS IAM User Self-Created Access Key Subsequently Used |
production |
2026-09-18 |
| elastic |
AWS Lambda Function Policy Updated to Allow Public Invocation |
production |
2026-09-18 |
| elastic |
AWS Lambda Function Policy Updated to Allow Cross-Account Invocation |
production |
2026-09-18 |
| elastic |
AWS Lambda Event Source Mapping Creation |
production |
2026-09-18 |
| elastic |
AWS Lambda Function URL Created with Public Access |
production |
2026-09-18 |
| elastic |
AWS EC2 CreateKeyPair by New Principal from Non-Cloud AS Organization |
production |
2026-09-18 |
| elastic |
AWS Organizations Delegated Administrator Registered |
production |
2026-09-18 |
| elastic |
AWS RDS DB Instance or Cluster Password Modified |
production |
2026-09-18 |
| elastic |
AWS RDS DB Instance Made Public |
production |
2026-09-18 |
| elastic |
AWS Route 53 Domain Transfer Lock Disabled |
production |
2026-09-18 |
| elastic |
AWS Route 53 Domain Transferred to Another Account |
production |
2026-09-18 |
| elastic |
AWS Route 53 Private Hosted Zone Associated With a VPC |
production |
2026-09-18 |
| elastic |
AWS EC2 Route Table Created |
production |
2026-09-18 |
| elastic |
AWS SageMaker Notebook Lifecycle Configuration With Suspicious Script Content |
production |
2026-09-18 |
| elastic |
AWS Sensitive IAM Operations Performed via CloudShell |
production |
2026-09-18 |
| elastic |
Potential Okta Brute Force (Multi-Source) |
production |
2026-09-18 |
| elastic |
AWS STS AssumeRole with New MFA Device |
production |
2026-09-18 |
| elastic |
Azure Storage Anonymous Blob Access to Unusual Resource |
production |
2026-09-18 |
| elastic |
Entra ID Sign-in BloodHound Suite User-Agent Detected |
production |
2026-09-18 |
| elastic |
Entra ID Sign-in TeamFiltration User-Agent Detected |
production |
2026-09-18 |
| elastic |
Microsoft Graph Multi-Category Reconnaissance Burst |
production |
2026-09-18 |
| elastic |
Azure Blob Storage Container Access Level Modified |
production |
2026-09-18 |
| elastic |
Azure Automation Runbook Created or Modified |
production |
2026-09-18 |
| elastic |
Azure AKS Ephemeral Container Added to Pod |
production |
2026-09-18 |
| elastic |
Potential Okta Brute Force (Device Token Rotation) |
production |
2026-09-18 |
| elastic |
Multiple Okta User Authentication Events with Same Device Token Hash |
production |
2026-09-18 |
| elastic |
Okta AiTM Session Cookie Replay |
production |
2026-09-18 |
| elastic |
Okta Multiple OS Names Detected for a Single DT Hash |
production |
2026-09-18 |