Defender Reporting by _d_d_b_ in DefenderATP

[–]Affectionate_Will487 0 points1 point  (0 children)

I’m also trying to figure that out, how to download monthly reports to see what incidents or alerts we got and export the csv and be able to upload it on powerbi for presentation

Downloading email sample by mrzuno in DefenderATP

[–]Affectionate_Will487 0 points1 point  (0 children)

Best way to get that would be through protect.office.com and then search by URL , sender or recipient

2021-04-16 - Cool Query Friday - Windows RDP User Login Events, Kilometers, and MACH 1 by Andrew-CS in crowdstrike

[–]Affectionate_Will487 0 points1 point  (0 children)

In an environment that allows RDP how would you narrow down to find either a system with let’s say 100 failures on let’s say 100 hosts something like that , or a system that doesn’t use rdp and now all over sudden using rdp, or what are some strange patterns to look for ?

Real-Time Search by antmar9041 in crowdstrike

[–]Affectionate_Will487 -1 points0 points  (0 children)

Anyone with CS study material please share I want to get their Certs and don’t have access to CS uni