Update Sign-in Burst from Multiple Locations.yaml
This commit is contained in:
Родитель
295f79f41b
Коммит
178c303985
|
@ -16,11 +16,11 @@ tactics:
|
|||
relevantTechniques:
|
||||
- T1110
|
||||
query: |
|
||||
let RunTime = 1h;
|
||||
let RunTime = 1h;
|
||||
SigninLogs
|
||||
| where TimeGenerated > ago(RunTime)
|
||||
| where AppDisplayName == "GitHub.com"
|
||||
| where ResultType == 0
|
||||
| summarize CountOfLocations = dcount(Location), Locations = make_set(Location) by UserPrincipalName
|
||||
| summarize CountOfLocations = dcount(Location), Locations = make_set(Location), BurstStartTime = min(TimeGenerated), BurstEndTime = max(TimeGenerated) by UserPrincipalName
|
||||
| where CountOfLocations > 1
|
||||
| extend AccountCustomEntity = UserPrincipalName , timestamp = TimeGenerated
|
||||
| extend AccountCustomEntity = UserPrincipalName
|
||||
|
|
Загрузка…
Ссылка в новой задаче