Azure-Sentinel/Hunting Queries/BehaviorAnalytics
Shain Wray (MSTIC) 95e3a9bc52 updated empty connector, moved Teams queries into OfficeActivity, updated some entity mappings 2021-02-04 15:31:02 -08:00
..
Anomalous AAD Account Manipulation.yaml Removing unicod chars 2021-01-31 12:59:07 -08:00
Anomalous Account Creation.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00
Anomalous Activity Role Assignment.yaml updated empty connector, moved Teams queries into OfficeActivity, updated some entity mappings 2021-02-04 15:31:02 -08:00
Anomalous Code Execution.yaml Update Anomalous Code Execution.yaml 2020-09-23 14:58:49 -07:00
Anomalous Data Access.yaml Update Anomalous Data Access.yaml 2020-09-23 14:59:15 -07:00
Anomalous Defensive Mechanism Modification.yaml UEBA queries - fix tactics to be with no white spaces 2021-01-17 13:52:14 +02:00
Anomalous Failed Logon.yaml Fix | Hunting description 2020-08-27 10:04:50 +03:00
Anomalous Geo Location Logon.yaml Fix | Hunting description 2020-08-27 10:04:50 +03:00
Anomalous Login to Devices.yaml add 3 new queries + change description + mofidy queries 2020-09-10 13:43:44 +03:00
Anomalous Password Reset.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00
Anomalous RDP Activity.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00
Anomalous Resource Access.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00
Anomalous Role Assignment.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00
Anomalous Sign-in Activity.yaml comment fix - replace occurences of 'contains' -> 'has' in queries 2020-09-21 15:12:14 +03:00