Distribution from remote location

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query checks for alerts related to file drop and remote execution where the file name matches PsExec and similar tools used for distribution

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 4e070afe-7a9b-4313-a964-c3168fffc1e2
Tactics Ransomware
Required Connectors MicrosoftThreatProtection
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/Microsoft%20365%20Defender/Ransomware/Distribution%20from%20remote%20location.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries