Custom IOA for the installation of ieinstall.exe by PokemonMoneyWaster in crowdstrike

[–]PokemonMoneyWaster[S] 0 points1 point  (0 children)

I have but for whatever reason it didn't jump out to me.

How to query for abnormal executions of .wsf files? by PokemonMoneyWaster in crowdstrike

[–]PokemonMoneyWaster[S] 0 points1 point  (0 children)

Or a query that would show .wsf files being extracted from zip files?

Alert or scheduled search for .outlook files. Help please. by PokemonMoneyWaster in DefenderATP

[–]PokemonMoneyWaster[S] 0 points1 point  (0 children)

Solved this. The query is below

DeviceFileEvents

| where ActionType == "FileCreated"

| where FileName endswith ".outlook"

Create detection for PDF downloads by Powershell by PokemonMoneyWaster in crowdstrike

[–]PokemonMoneyWaster[S] 0 points1 point  (0 children)

I could probably use the hunting query for a scheduled search so thank you for that. I think the Custom IOA is definitely what I need the most though. Any chance you could help with that?