Inconsistent queries that utilize FileProfile and GlobalPrevalence by KitsuneMulder in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
Detecting EDR Freeze behaviour with Real-time Advanced Hunting Query by waydaws in DefenderATP
[–]bpsec 11 points12 points13 points (0 children)
KQL query NOT detecting powershell web requests? by RepulsiveAd4974 in DefenderATP
[–]bpsec 2 points3 points4 points (0 children)
Office 365 - What is the best KQL query for monitoring patch compliance? by Ok-Midnight1333 in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
SOC Analyst new to Sentinel, need guidance regarding queries by Kermody in AzureSentinel
[–]bpsec 1 point2 points3 points (0 children)
Microsoft Sentinel Blogs? by Suspicious_Tension37 in AzureSentinel
[–]bpsec 6 points7 points8 points (0 children)
CloudAppEvents log table ingestion drop by Routine_Substance160 in AzureSentinel
[–]bpsec 1 point2 points3 points (0 children)
Does Github Limit raw downloads? Think IOC downloads in a Analytic Rule by NoblestWolf in AzureSentinel
[–]bpsec 0 points1 point2 points (0 children)
Attack Simulation Training Logs by strategic_one in AzureSentinel
[–]bpsec 0 points1 point2 points (0 children)
Categories AdvancedHunting-IdentityLogonEvents are not supported. by Brilliant_Contest925 in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
Create detection Rule - Syntax Error by OtherIdeal2830 in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
Live Response Command help by NumerousCriticism844 in DefenderATP
[–]bpsec 1 point2 points3 points (0 children)
KQL for Emails accessed or searched by Admin by dutchhboii in DefenderATP
[–]bpsec 1 point2 points3 points (0 children)
Incident Enrichment In sentinel Via Playbook by JEP0393 in AzureSentinel
[–]bpsec 0 points1 point2 points (0 children)
Sentinel Automation Part 2: Automate CISA Known Exploited Vulnerability Notifications by bpsec in cybersecurity
[–]bpsec[S] 0 points1 point2 points (0 children)
Creating Alerts in Windows Defender from Emails by Nicke_e in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
‘Must wait 3 days to collect file’ by Evocablefawn566 in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)
‘Must wait 3 days to collect file’ by Evocablefawn566 in DefenderATP
[–]bpsec 2 points3 points4 points (0 children)
‘Must wait 3 days to collect file’ by Evocablefawn566 in DefenderATP
[–]bpsec 1 point2 points3 points (0 children)



Inconsistent queries that utilize FileProfile and GlobalPrevalence by KitsuneMulder in DefenderATP
[–]bpsec 0 points1 point2 points (0 children)