Microsoft Sentinel high experimental kql

Acronis - Multiple Endpoints Infected by Ransomware

Detects when three or more distinct endpoints report ransomware detections within a single day.

View Source

Detection Logic

CommonSecurityLog
| where DeviceVendor == "Acronis"
| where DeviceEventClassID == "ActiveProtectionBlocksSuspiciousActivity"
| summarize ActiveProtectionBlocksSuspiciousActivity = count() by DeviceName

Field Validations

Loading…

Comments (0)

Loading comments...