<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>T1110.003 on sentinelchangelog.net</title><link>http://sentinelchangelog.net/tags/t1110.003/</link><description>Recent content in T1110.003 on sentinelchangelog.net</description><generator>Hugo -- 0.157.0</generator><language>en</language><lastBuildDate>Mon, 01 Jun 2026 04:39:34 +0000</lastBuildDate><atom:link href="http://sentinelchangelog.net/tags/t1110.003/index.xml" rel="self" type="application/rss+xml"/><item><title>Slack Audit Solution: Enhanced Detection Logic and Alert Enrichment</title><link>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</link><pubDate>Mon, 01 Jun 2026 04:39:34 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-06-01-pr-14245/</guid><description>Slack Audit analytic rules, hunting queries, and workbook upgraded with improved KQL logic, custom alert details, and enhanced entity mappings for stronger workspace monitoring.</description></item><item><title>Microsoft Entra ID: Hunting Query for Password Spraying Detection via IP Failure Bursts</title><link>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</link><pubDate>Thu, 07 May 2026 10:50:43 +0000</pubDate><guid>http://sentinelchangelog.net/posts/2026-05-07-pr-14208/</guid><description>Correlates failed sign-ins across multiple identities followed by successful authentication from the same IP within 15 minutes, targeting password spraying patterns.</description></item></channel></rss>