Microsoft Sentinel high experimental kql

Mimecast Targeted Threat Protection - Impersonation Protect

Detects a maliciously tagged impersonation

View Source

Detection Logic

MimecastTTPImpersonation_CL
| where taggedMalicious_b == true;

Field Validations

Loading…

Comments (0)

Loading comments...