
Detecting File transers to USB devices
Using this query you can review file transfers to usb devices

CVE-2025-53770 Microsoft SharePoint RCE
This query identifies known file names and paths observed during exploitation

Users Added to Sensitive Groups
This is a great way to monitor users that are added to groups. For this query to work,...