Threat actors spend much of their time on surveillance. Typical services generate many audit logs that may be hard to parse and locate potentially malicious events. Since a lot of surveillance is ...