You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
"query": "DeviceEvents\n| where ActionType in (\"UserAccountCreated\",\"ScheduledTaskCreated\",\"ScheduledTaskDeleted\",\"UserAccountModified\",\"UserAccountAddedToLocalGroup\")\n| project Timestamp, DeviceName, ActionType"
495
+
"query": "DeviceEvents\n| where ActionType in (\"AntivirusDetection\",\"AntivirusDetectionCancelled\",\"AntivirusMalwareActionFailed\")\n| project Timestamp, DeviceName, ActionType"
406
496
},
407
497
"id": "{{dataStreams.advancedHuntingQuery}}",
408
498
"sort": {
@@ -433,7 +523,7 @@
433
523
"activePluginConfigIds": [
434
524
"{{configId}}"
435
525
],
436
-
"title": "Persistence & Privilege Escalation",
526
+
"title": "Malware & Antivirus Detected",
437
527
"visualisation": {
438
528
"type": "data-stream-scalar",
439
529
"config": {
@@ -453,15 +543,15 @@
453
543
"w": 1,
454
544
"moved": false,
455
545
"h": 2,
456
-
"x": 0,
546
+
"x": 1,
457
547
"y": 4,
458
-
"i": "6aa1942a-8390-4023-9454-b5accc992f77",
548
+
"i": "18116acd-6097-4b27-a0f3-9d8cee0c7611",
459
549
"z": 0,
460
550
"config": {
461
551
"dataStream": {
462
552
"name": "advancedHuntingQuery",
463
553
"dataSourceConfig": {
464
-
"query": "DeviceEvents\n| where ActionType in (\"AntivirusDetection\",\"AntivirusDetectionCancelled\",\"AntivirusMalwareActionFailed\")\n| project Timestamp, DeviceName, ActionType"
554
+
"query": "DeviceEvents\n| where ActionType in (\"UserAccountCreated\",\"ScheduledTaskCreated\",\"ScheduledTaskDeleted\",\"UserAccountModified\",\"UserAccountAddedToLocalGroup\")\n| project Timestamp, DeviceName, ActionType"
465
555
},
466
556
"id": "{{dataStreams.advancedHuntingQuery}}",
467
557
"sort": {
@@ -492,7 +582,7 @@
492
582
"activePluginConfigIds": [
493
583
"{{configId}}"
494
584
],
495
-
"title": "Malware & Antivirus Detected",
585
+
"title": "Persistence & Privilege Escalation",
496
586
"visualisation": {
497
587
"type": "data-stream-scalar",
498
588
"config": {
@@ -512,15 +602,15 @@
512
602
"w": 1,
513
603
"moved": false,
514
604
"h": 2,
515
-
"x": 1,
605
+
"x": 2,
516
606
"y": 6,
517
-
"i": "b94c9951-c17a-40b1-856f-f9a669d8ac44",
607
+
"i": "82ea55ee-eb36-4426-9ffc-a3af01c97297",
518
608
"z": 0,
519
609
"config": {
520
610
"dataStream": {
521
611
"name": "advancedHuntingQuery",
522
612
"dataSourceConfig": {
523
-
"query": "DeviceEvents\n| where ActionType in (\"UserAccountCreated\",\"ScheduledTaskCreated\",\"ScheduledTaskDeleted\",\"UserAccountModified\",\"UserAccountAddedToLocalGroup\")\n| project Timestamp, DeviceName, ActionType"
613
+
"query": "DeviceEvents\n| where ActionType startswith \"AppControl\"\n| project Timestamp, DeviceName, ActionType"
524
614
},
525
615
"id": "{{dataStreams.advancedHuntingQuery}}",
526
616
"sort": {
@@ -551,7 +641,7 @@
551
641
"activePluginConfigIds": [
552
642
"{{configId}}"
553
643
],
554
-
"title": "Persistence & Privilege Escalation",
644
+
"title": "Application Control",
555
645
"visualisation": {
556
646
"type": "data-stream-table",
557
647
"config": {
@@ -571,15 +661,15 @@
571
661
"w": 1,
572
662
"moved": false,
573
663
"h": 2,
574
-
"x": 2,
664
+
"x": 3,
575
665
"y": 6,
576
-
"i": "82ea55ee-eb36-4426-9ffc-a3af01c97297",
666
+
"i": "78729826-2fb5-4879-b90d-6be92c3cca55",
577
667
"z": 0,
578
668
"config": {
579
669
"dataStream": {
580
670
"name": "advancedHuntingQuery",
581
671
"dataSourceConfig": {
582
-
"query": "DeviceEvents\n| where ActionType startswith \"AppControl\"\n| project Timestamp, DeviceName, ActionType"
672
+
"query": "DeviceEvents\n| where ActionType in (\"ExploitGuardNetworkProtectionBlocked\",\"ExploitGuardNonMicrosoftSignedBlocked\")\n| project Timestamp, DeviceName, ActionType"
583
673
},
584
674
"id": "{{dataStreams.advancedHuntingQuery}}",
585
675
"sort": {
@@ -610,7 +700,7 @@
610
700
"activePluginConfigIds": [
611
701
"{{configId}}"
612
702
],
613
-
"title": "Application Control",
703
+
"title": "Exploits",
614
704
"visualisation": {
615
705
"type": "data-stream-table",
616
706
"config": {
@@ -630,15 +720,15 @@
630
720
"w": 1,
631
721
"moved": false,
632
722
"h": 2,
633
-
"x": 3,
723
+
"x": 0,
634
724
"y": 6,
635
-
"i": "78729826-2fb5-4879-b90d-6be92c3cca55",
725
+
"i": "3b81144e-1593-4d20-a786-aa4341398f66",
636
726
"z": 0,
637
727
"config": {
638
728
"dataStream": {
639
729
"name": "advancedHuntingQuery",
640
730
"dataSourceConfig": {
641
-
"query": "DeviceEvents\n| where ActionType in (\"ExploitGuardNetworkProtectionBlocked\",\"ExploitGuardNonMicrosoftSignedBlocked\")\n| project Timestamp, DeviceName, ActionType"
731
+
"query": "DeviceEvents\n| where ActionType in (\"AntivirusDetection\",\"AntivirusDetectionCancelled\",\"AntivirusMalwareActionFailed\")\n| project Timestamp, DeviceName, ActionType"
642
732
},
643
733
"id": "{{dataStreams.advancedHuntingQuery}}",
644
734
"sort": {
@@ -669,15 +759,12 @@
669
759
"activePluginConfigIds": [
670
760
"{{configId}}"
671
761
],
672
-
"title": "Exploits",
762
+
"title": "Malware & Antivirus Detected",
673
763
"visualisation": {
674
764
"type": "data-stream-table",
675
765
"config": {
676
766
"data-stream-table": {
677
-
"columnOrder": [
678
-
"DeviceName_uniqueValues",
679
-
"count"
680
-
],
767
+
"columnOrder": [],
681
768
"hiddenColumns": []
682
769
}
683
770
}
@@ -689,15 +776,15 @@
689
776
"w": 1,
690
777
"moved": false,
691
778
"h": 2,
692
-
"x": 0,
779
+
"x": 1,
693
780
"y": 6,
694
-
"i": "3b81144e-1593-4d20-a786-aa4341398f66",
781
+
"i": "b94c9951-c17a-40b1-856f-f9a669d8ac44",
695
782
"z": 0,
696
783
"config": {
697
784
"dataStream": {
698
785
"name": "advancedHuntingQuery",
699
786
"dataSourceConfig": {
700
-
"query": "DeviceEvents\n| where ActionType in (\"AntivirusDetection\",\"AntivirusDetectionCancelled\",\"AntivirusMalwareActionFailed\")\n| project Timestamp, DeviceName, ActionType"
787
+
"query": "DeviceEvents\n| where ActionType in (\"UserAccountCreated\",\"ScheduledTaskCreated\",\"ScheduledTaskDeleted\",\"UserAccountModified\",\"UserAccountAddedToLocalGroup\")\n| project Timestamp, DeviceName, ActionType"
0 commit comments