Endace - Pivot-to-Vision

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query displays a Pivot-to-Vision URL from the fields populated within the CommonSecurityLog. This KQL can be used as-is, or adapted to suite other threat-hunting and playbook functionality

Attribute Value
Type Hunting Query
Solution Endace
ID b70b02bd-fe1f-4466-8c4d-64d42adc59b3
Tactics ResourceDevelopment, InitialAccess, Discovery, LateralMovement, CommandandControl, Exfiltration
Required Connectors CefAma
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
CommonSecurityLog ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries · Back to Endace