Suspect Setup Actions
Detect suspect setup actions in major org
Will extract from audit trail all actions that are considered as suspect, excepted the ones related to the deployment user and a given list of users, like the release manager.
Sfdx-hardis command: sf hardis:org:diagnose:audittrail
Key: AUDIT_TRAIL