Microsoft Sentinel high experimental kql
Acronis - Multiple Endpoints Infected by Ransomware
Detects when three or more distinct endpoints report ransomware detections within a single day.
Detection Logic
CommonSecurityLog
| where DeviceVendor == "Acronis"
| where DeviceEventClassID == "ActiveProtectionBlocksSuspiciousActivity"
| summarize ActiveProtectionBlocksSuspiciousActivity = count() by DeviceName Field Validations
Loading…
Comments (0)
Loading comments...