SolarWinds -CVE-2021-35211

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


//Check for network connections with SolarWInds IP's based on DeviceNetworkEvents## Query

Attribute Value
Type Hunting Query
Solution GitHub Only
ID ff01fb94-9b27-48b9-a304-2e86108b5ca4
Tactics Command and control
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceNetworkEvents ActionType == "ConnectionSuccess" ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries