Web shell command alert enrichment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Extracts MDATP Alerts that indicate a command was executed by a web shell. Uses time window based querying to idneitfy the potential web shell location on the server, then enriches with Attacker IP and User Agent

Attribute Value
Type Hunting Query
Solution Standalone Content
ID d2e6f31b-add1-4f44-b54d-1975a5605c1d
Tactics PrivilegeEscalation, Persistence
Required Connectors MicrosoftDefenderAdvancedThreatProtection, AzureMonitor(IIS)
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SecurityAlert/WebShellCommandAlertEnrich.yaml)

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
SecurityAlert ✓ ✗ ✓
W3CIISLog ✓ ✗ ✗

Associated Connectors

The following connectors provide data for this content item:

Connector Solution
ESI-Opt5ExchangeIISLogs Microsoft Exchange Security - Exchange On-Premises

Solutions: Microsoft Exchange Security - Exchange On-Premises


Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Hunting Queries