Identify anomalous mass file download operations and data hoarding across SharePoint Online and OneDrive for Business using statistical KQL baseline thresholds.
Monitor high-privilege Azure RBAC grant operations (Owner, Contributor, User Access Administrator) in AzureActivity logs using proactive KQL alert rules.
Detect credential theft targeting the Local Security Authority Subsystem Service (LSASS) via native LOLBINs like comsvcs.dll and Sysinternals ProcDump in KQL.