Release 19 - Out-of-the-box alerts
Detection name | Detection description | Devo table / Data source / Category | Update |
| This alert shows a anonymous IP detection made by MCAS |
| Updated alert logic |
| An adversary may attempt to dump credentials to obtain account login and credential material in the form of hashes or clear text passwords. |
| Updated alert logic |
| Detects and attempt to access lsass using mimikatz and/or a possible mimikatz driver load |
| Updated alert logic and updated field naming |