Microsoft Sentinel high experimental kql
ApexOne - Attack Discovery Detection
'Detects Attack Discovery Detection events.'
Detection Logic
TMApexOneEvent
| where EventMessage has "Attack Discovery Detection"
| extend IPCustomEntity = SrcIpAddr, AccountCustomEntity = DstUserName Field Validations
Loading…
Comments (0)
Loading comments...