Tag
low
advisory
Wallpaper Modification Detection
3 rules 1 TTPDetection of unauthorized or suspicious wallpaper modifications on endpoints can indicate malicious activity or policy violations.
Windows
endpoint
wallpaper
modification
registry
policy violation
3r
1t
high
advisory
Azure Application URI Configuration Modification
3 rules 4 TTPsDetection of Azure application URI modifications that can be indicative of malicious activity, such as using dangling URIs, non-HTTPS URIs, wildcard domains, or URIs pointing to uncontrolled domains, potentially leading to initial access, stealth, persistence, credential access, and privilege escalation.
Azure Active Directory
cloud
azure
application
uri
modification
persistence
credential-access
privilege-escalation
3r
4t