Microsoft Sentinel high experimental kql

Mimecast Audit - Logon Authentication Failed

Detects threat when logon authentication failure found in audit

View Source

Detection Logic

MimecastAudit_CL
| where src_s !="" and auditType_s == "Logon Authentication Failed"

Field Validations

Loading…

Comments (0)

Loading comments...