Web shell command alert enrichment

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


Extracts MDATP Alerts that indicate a command was executed by a web shell. Uses time window based querying to idneitfy the potential web shell location on the server, then enriches with Attacker IP and User Agent

Attribute Value
Type Hunting Query
Solution Standalone Content
ID d2e6f31b-add1-4f44-b54d-1975a5605c1d
Tactics PrivilegeEscalation, Persistence
Required Connectors MicrosoftDefenderAdvancedThreatProtection, AzureMonitor(IIS)
Source [View on GitHub](https://github.com/Azure/Azure-Sentinel/blob/master/Hunting Queries/SecurityAlert/WebShellCommandAlertEnrich.yaml)

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Hunting Queries