Microsoft Sentinel high experimental kql

ApexOne - Suspicious commandline arguments

'Detects suspicious commandline arguments.'

View Source

Detection Logic

TMApexOneEvent
| where EventMessage has "Endpoint Application"
| where Command has_any ("whoami", "dpkg", "useradd", "sudo")
| extend IPCustomEntity = SrcIpAddr, AccountCustomEntity = DstUserName

Field Validations

Loading…

Comments (0)

Loading comments...