Storage Alert Correlation with CommonSecurityLogs and StorageLogs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query combines different Storage alerts with CommonSecurityLogs and StorageLogs helping analysts triage and investigate any possible Storage related attacks faster thus reducing Mean Time To Respond

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 7098cae1-c632-4b40-b715-86d6b07720d7
Tactics InitialAccess, LateralMovement
Techniques T1586, T1570
Required Connectors AzureSecurityCenter, Fortinet
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/MultipleDataSources/StorageAlertCorrelationwithCommonSecurityLogsandStorageLogs.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries