<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1098 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1098/</link><description>Recent content in T1098 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Mon, 01 Jun 2026 04:39:34 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1098/index.xml" rel="self" type="application/rss+xml"/><item><title>Slack Audit Solution: Enhanced Detection Logic and Alert Enrichment</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</link><pubDate>Mon, 01 Jun 2026 04:39:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</guid><description>Slack Audit analytic rules, hunting queries, and workbook upgraded with improved KQL logic, custom alert details, and enhanced entity mappings for stronger workspace monitoring.</description></item><item><title>Entra ID Post-Credential Activity Detection: Service Principal Staging and Privileged Role Escalation</title><link>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</link><pubDate>Fri, 29 May 2026 10:56:48 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-29-pr-14299/</guid><description>Three new hunting queries target Midnight Blizzard-style persistence patterns — service principal credential staging, privileged role assignments to new accounts, and Temporary Access Pass abuse.</description></item><item><title>Entra ID Identity Boundary Expansion: Three New Hunting Queries for Stealthy Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</link><pubDate>Thu, 28 May 2026 11:14:14 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-28-pr-14307/</guid><description>Added three hunting queries targeting identity boundary expansion techniques in Entra ID that escalate privileges without creating new accounts.</description></item><item><title>Entra ID Authentication Anomalies: Advanced Hunting for Privilege Abuse and Defense Evasion</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</link><pubDate>Wed, 27 May 2026 13:42:33 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14339/</guid><description>Adds three-query pack detecting legacy auth bypass, guest account abuse, and post-reset privileged operations.</description></item><item><title>Entra ID Account Takeover: Three-Query Hunting Pack for Post-Compromise Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</link><pubDate>Wed, 27 May 2026 13:41:06 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14335/</guid><description>Adds hunting pack targeting device code phishing, service principal persistence, and bulk password resets by privileged actors.</description></item><item><title>Microsoft Entra ID OAuth Consent Query: Fixing Zero-Result Bug in High-Risk Permission Detection</title><link>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</link><pubDate>Wed, 27 May 2026 13:38:30 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-27-pr-14334/</guid><description>Corrects broken hunting query that returned no results due to incorrect property name filter.</description></item><item><title>Entra ID Cross-Source Hunting Pack: Post-Compromise Pattern Detection</title><link>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</link><pubDate>Tue, 19 May 2026 10:09:11 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-19-pr-14262/</guid><description>Three new hunting queries correlate AuditLogs and SigninLogs to surface post-compromise identity patterns using baseline-driven anomaly detection.</description></item><item><title>AWS Content Quality Overhaul: Standardized Detection Rules and Improved Entity Mappings</title><link>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</link><pubDate>Mon, 18 May 2026 07:30:57 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-18-pr-14101/</guid><description>Comprehensive quality improvements to 61 AWS Analytic Rules and 35 Hunting Queries with standardized naming conventions, normalized MITRE technique mappings, and updated entity field references from legacy AccountCustomEntity to UserIdentityUserName.</description></item><item><title>Entra ID Attack Chain Detection: 5 New Hunting Queries Target Application Layer Persistence</title><link>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</link><pubDate>Wed, 13 May 2026 10:29:56 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-13-pr-14239/</guid><description>Five hunting queries expose OAuth consent abuse, privileged escalation, and Conditional Access evasion used in Midnight Blizzard and Storm-0558 campaigns.</description></item><item><title>Valimail Enforce Solution: New Email Authentication Monitoring for DMARC/SPF/DKIM Configuration Changes</title><link>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</link><pubDate>Fri, 24 Apr 2026 05:26:39 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-24-pr-14045/</guid><description>Complete Valimail Enforce monitoring solution delivers real-time detection of email authentication policy weakening and suspicious admin activity affecting domain security posture.</description></item><item><title>Microsoft Sentinel Training Lab: Comprehensive Hands-On Security Operations Environment Now Available</title><link>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</link><pubDate>Fri, 10 Apr 2026 15:05:24 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-04-10-pr-13848/</guid><description>New deployment-ready training lab delivers 14 guided exercises with pre-recorded telemetry, detection rules, and automation workflows for practical Microsoft Sentinel skill development.</description></item><item><title>Microsoft Security Copilot: Six New Detections for AI Assistant Abuse</title><link>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</link><pubDate>Fri, 27 Mar 2026 05:01:42 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-03-27-pr-13735/</guid><description>New analytic rules target jailbreak attempts, external access, plugin tampering, and file upload disabling - covering major AI security attack vectors.</description></item><item><title>UEBA Essentials: Enhanced Multi-Cloud Detection with 6 New AWS, GCP &amp; Okta Hunting Queries</title><link>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</link><pubDate>Wed, 12 Nov 2025 11:17:58 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2025-11-12-pr-13065/</guid><description>Major update adds comprehensive multi-cloud anomaly detection capabilities across AWS, GCP, and Okta platforms with 6 new hunting queries.</description></item></channel></rss>