Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Identifies Microsoft Sentinel Analytics Rules administrative operations
| Attribute | Value |
|---|---|
| Type | Hunting Query |
| Solution | Azure Activity |
| ID | ef7ef44e-6129-4d8e-94fe-b5530415d8e5 |
| Severity | Low |
| Tactics | Impact |
| Techniques | T1496 |
| Required Connectors | AzureActivity |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
AzureActivity |
ActivitySubstatusValue in "Created,OK"CategoryValue == "Administrative" |
✗ | ✗ | ✗ |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊