Anomalous User Activity — Detection Rule

Indicates that there are anomalous patterns of behavior like suspicious changes to the directory.

Read the full analysis on IntelFusions