Aqua Blizzard AV hits - Feb 2022

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


Identifies a match in the Security Alert table for MDATP hits related to the Aqua Blizzard actor

Attribute Value
Type Analytic Rule
Solution MicrosoftDefenderForEndpoint
ID 18dbdc22-b69f-4109-9e39-723d9465f45f
Severity High
Status Available
Kind Scheduled
Tactics Persistence
Techniques T1137
Required Connectors MicrosoftDefenderAdvancedThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityAlert ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Analytic Rules · Back to MicrosoftDefenderForEndpoint