Microsoft Sentinel high experimental kql
Mimecast Audit - Logon Authentication Failed
Detects threat when logon authentication failure found in audit
Detection Logic
MimecastAudit_CL
| where src_s !="" and auditType_s == "Logon Authentication Failed" Field Validations
Loading…
Comments (0)
Loading comments...