Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊
This query combines different Storage alerts with CommonSecurityLogs and StorageLogs helping analysts triage and investigate any possible Storage related attacks faster thus reducing Mean Time To Respond
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | GitHub Only |
| ID | 7098cae1-c632-4b40-b715-86d6b07720d7 |
| Tactics | InitialAccess, LateralMovement |
| Techniques | T1586, T1570 |
| Required Connectors | AzureSecurityCenter, Fortinet |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
CommonSecurityLog |
DeviceVendor == "Fortinet" |
✓ | ✓ | ? |
SecurityAlert |
✓ | ✗ | ? | |
StorageBlobLogs |
✓ | ✗ | ? | |
StorageFileLogs |
✓ | ✗ | ? |
The following connectors provide data for this content item:
Solutions: Azure Storage, Common Event Format, IoTOTThreatMonitoringwithDefenderforIoT, Microsoft Defender for Cloud, Microsoft Defender for Cloud Apps, Microsoft Defender for Identity, Microsoft Defender for Office 365, Microsoft Entra ID Protection, MicrosoftDefenderForEndpoint, MicrosoftPurviewInsiderRiskManagement, VirtualMetric DataStream, Zscaler Internet Access
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊