Update ProcessEntropy.txt
This commit is contained in:
Родитель
7befd2ff04
Коммит
5129fd46a5
|
@ -72,4 +72,6 @@ Results | join kind= inner (
|
|||
| project TimeGenerated, EventID, Computer, SubjectUserSid, Account, AccountType, Process, NewProcessName, CommandLine, ParentProcessName
|
||||
) on Computer, Process
|
||||
| project TimeGenerated, EventID, Computer, SubjectUserSid, Account, Weight, ProcessEntropy, Process, NewProcessName, CommandLine, ParentProcessName, TotalProcessCountOnHost, ProcessCountOnHost, DistinctComputersWithProcessCount
|
||||
| sort by Weight asc, ProcessEntropy asc, NewProcessName asc
|
||||
| sort by Weight asc, ProcessEntropy asc, NewProcessName asc
|
||||
| extend HostCustomEntity = Computer
|
||||
| extend AccountCustomEntity = Account
|
||||
|
|
Загрузка…
Ссылка в новой задаче