Microsoft Sentinel high experimental kql
Mimecast Audit - Logon Authentication Failed
Detects threat when logon authentication failure found in audit
Detection Logic
MimecastAudit
| where ['Source IP'] !="" and ['Audit Type'] == "Logon Authentication Failed"
| extend SourceIp = ['Source IP'] Field Validations
Loading…
Comments (0)
Loading comments...