- Detections
- -DT082
Windows Event Log, Local Firewall Changes - DT082
Contributor: The ITM Team @ - Detection DT082
- Detections
- -DT086
Shellbags, Network Drives - DT086
Contributor: The ITM Team @ - Detection DT086
- Detections
- -DT089
AzureAD PowerShell Log - DT089
Contributor: The ITM Team @ - Detection DT089
- Detections
- -DT090
Clipboard Payloads via ActivitiesCache.db - DT090
Contributor: The ITM Team @ - Detection DT090
- Detections
- -DT093
MFT and Shimcache Executable Timestamp Comparison - DT093
Contributor: The ITM Team @ - Detection DT093
- Detections
- -DT094
Microsoft Purview Audit Search - DT094
Contributor: The ITM Team @ - Detection DT094
- Detections
- -DT103
Photographic Identification Comparison - DT103
Contributor: The ITM Team @ - Detection DT103
- Detections
- -DT104
Leaver Watchlist - DT104
Contributor: The ITM Team @ - Detection DT104
- Detections
- -DT105
vssadmin Shadow Copy Deletion - DT105
Contributor: The ITM Team @ - Detection DT105
- Detections
- -DT107
Microsoft Teams Admin Center Meeting and Call History - DT107
Contributor: The ITM Team @ - Detection DT107