Microsoft Sentinel high experimental kql
ApexOne - Suspicious commandline arguments
'Detects suspicious commandline arguments.'
Detection Logic
TMApexOneEvent
| where EventMessage has "Endpoint Application"
| where Command has_any ("whoami", "dpkg", "useradd", "sudo")
| extend IPCustomEntity = SrcIpAddr, AccountCustomEntity = DstUserName Field Validations
Loading…
Comments (0)
Loading comments...