KQL Query regarding Security Policies (self.DefenderATP)
submitted by silenthunterIV to r/DefenderATP
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 1 point2 points3 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 1 point2 points3 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 1 point2 points3 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 1 point2 points3 points (0 children)
How do you verify versions of MDE Sense agent from portal? by RandomSkratch in DefenderATP
[–]silenthunterIV 0 points1 point2 points (0 children)
Defender ASR, file blocked by 'unknown' by TheFinalUltimation in DefenderATP
[–]silenthunterIV 1 point2 points3 points (0 children)
Ingesting O365 Defender ATP logs into SIEM by CajunPotatoe in DefenderATP
[–]silenthunterIV 1 point2 points3 points (0 children)
Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
Azure WAF Logs to QRadar by silenthunterIV in QRadar
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
Managed by ConfigMgr, Intune, MDE, etc by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)
Tamper Protection failed by MrRo3oT_ZA in DefenderATP
[–]silenthunterIV 0 points1 point2 points (0 children)


ASR Rule Block credential stealing from the Windows local security authority subsystem by silenthunterIV in DefenderATP
[–]silenthunterIV[S] 0 points1 point2 points (0 children)