Microsoft Sentinel high experimental kql

Cisco SE - Malware execusion on host

'Detects malware execution on host.'

View Source

Detection Logic

CiscoSecureEndpoint
| where EventMessage has 'Executed Malware'
| extend HostCustomEntity = DstHostname, MalwareCustomEntity = ThreatName

Field Validations

Loading…

Comments (0)

Loading comments...