Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This hunting query looks for file paths/hashes related to observed activity by Dev-0228. The actor is known to use custom version of popular tool like PsExec, Procdump etc. to carry its activity. The risk score associated with each result is based on a number of factors, hosts with higher risk events should be investigated first. This query uses the Microsoft Sentinel Information Model - https://docs.microsoft.com/azure/sentinel/normalization
| Attribute | Value |
|---|---|
| Type | Analytic Rule |
| Solution | Standalone Content |
| ID | 29a29e5d-354e-4f5e-8321-8b39d25047bf |
| Severity | High |
| Kind | Scheduled |
| Tactics | CredentialAccess, Execution |
| Techniques | T1569, T1003 |
| Source | View on GitHub |
This content item queries data from the following tables:
| Table | Selection Criteria | Transformations | Ingestion API | Lake-Only |
|---|---|---|---|---|
SecurityAlert |
ProviderName == "MDATP" |
✓ | ✗ | ✓ |
The following connectors provide data for this content item:
| Connector | Solution |
|---|---|
| MicrosoftDefenderAdvancedThreatProtection | MicrosoftDefenderForEndpoint |
Solutions: MicrosoftDefenderForEndpoint
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊