Microsoft Sentinel high experimental kql

ApexOne - Attack Discovery Detection

'Detects Attack Discovery Detection events.'

View Source

Detection Logic

TMApexOneEvent
| where EventMessage has "Attack Discovery Detection"
| extend IPCustomEntity = SrcIpAddr, AccountCustomEntity = DstUserName

Field Validations

Loading…

Comments (0)

Loading comments...