Microsoft Sentinel high experimental kql

Mimecast Audit - Logon Authentication Failed

Detects threat when logon authentication failure found in audit

View Source

Detection Logic

MimecastAudit
| where ['Source IP'] !="" and ['Audit Type'] == "Logon Authentication Failed"
| extend   SourceIp = ['Source IP']

Field Validations

Loading…

Comments (0)

Loading comments...