APT36 SHEETCREEP victim UID fingerprinting: rapid username+hostname enumeration
Detects rapid, consecutive execution of commands or scripts to enumerate both the username and computername on a system within a 30-second window. This behavior is consistent with initial host fingerprinting often performed by adversaries, including techniques used by SHEETCREEP malware.
Microsoft Sentinel (KQL)

