Bert-Jan Pals unknown stable kql

'File From Host Collected via Portal or Live Response

This query lists all the file downloads from an onboarded EDR device. The query lists the two file collection methods: 1. LiveResponseGetFile: Files collected through the getfile command in Live Response 2: DownloadFile: Files collected though the XDR portal by using the download file feature.

View Source

Detection Logic

CloudAppEvents
| where ActionType in ('LiveResponseGetFile', 'DownloadFile')
| extend FileName = tostring(RawEventData.FileName), FileSHA256 = tostring(RawEventData.FileSHA256), FileSize = tostring(RawEventData.FileSize)
| project-rename InitiatedByAccountName = AccountDisplayName, InitiatedByAccounttId = AccountId
| project-reorder TimeGenerated, InitiatedByAccountName, InitiatedByAccounttId, IPAddress, FileName, FileSHA256, FileSize

Field Validations

Loading…

Comments (0)

Loading comments...