Check for multiple signs of ransomware activity

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Instead of running several queries separately, you can also use a comprehensive query that checks for multiple signs of ransomware activity to identify affected devices. The following consolidated query: Looks for both relatively concrete and subtle signs of ransomware activity Weighs the presence of these signs Identifies devices with a higher chance of being targets of ransomware When run, this consolidated query returns a list of devices that have exhibited multiple signs of attack. The count

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 3b0a6901-6149-4856-bc6e-149ca654bc8c
Tactics Ransomware
Required Connectors MicrosoftThreatProtection
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Microsoft%20365%20Defender/Ransomware/Check%20for%20multiple%20signs%20of%20ransomware%20activity.yaml)

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceProcessEvents ProcessCommandLine has "cl"
ProcessCommandLine has "config"
ProcessCommandLine has "delete"
ProcessCommandLine has "deletejournal"
ProcessCommandLine has "disabled"
ProcessCommandLine has "sc"
ProcessCommandLine has "shadowcopy delete"
ProcessCommandLine has "usn"
ProcessCommandLine has "wbadmin"
ProcessCommandLine has "wevtutil"
ProcessCommandLine has "wmic"
✓ ✗ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries