A
andrewdanis
First rule: Wed Jun 26 2024 02:00:00 GMT+0200 (Central European Summer Time)
0rules authored
2sole author
1co-authored
Top Log Sources
Rule Types
By Severity
critical
0
high
3
medium
0
low
0
informational
0
By Status
stable
0
test
1
experimental
2
deprecated
0
unsupported
0
0
Total Rules
0
Stable Rules
0
High / Critical
0
Log Source Types
Recent RulesAll rules →
Suspicious Speech Runtime Binary Child Process
Thu Oct 23 2025 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Suspicious BitLocker Access Agent Update Utility Execution
Sat Oct 18 2025 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Windows LAPS Credential Dump From Entra ID
Wed Jun 26 2024 02:00:00 GMT+0200 (Central European Summer Time)
highDetection
Browse all 3 rules by andrewdanis
Filter the full rule library to see only their contributions