Storage Alerts Correlation with CommonSecurityLogs & AuditLogs

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This query combines different Storage alerts with CommonSecurityLogs and AuditLogs helping analysts investigate any possible storage related attacks faster thus reducing Mean Time To Respond

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 860a8df2-8d19-4c60-bf61-de1c02422797
Tactics InitialAccess, Impact
Techniques T1190, T1078
Required Connectors AzureSecurityCenter, Fortinet, AzureActiveDirectory
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/MultipleDataSources/StorageAlertCorrelationwithCommonSecurityLogsandAuditLogs.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries