Distribution from remote location

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query checks for alerts related to file drop and remote execution where the file name matches PsExec and similar tools used for distribution

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 4e070afe-7a9b-4313-a964-c3168fffc1e2
Tactics Ransomware
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
AlertInfo ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries