List Unblocked Ngrok Events in Symantec with KQL
This article covers how to use a KQL (Kusto Query Language) script to list Ngrok activity detected by Symantec Endpoint
Read MoreWhere Every Failure Becomes A Manual
This article covers how to use a KQL (Kusto Query Language) script to list Ngrok activity detected by Symantec Endpoint
Read MoreThis KQL query identifies malicious scan attempts detected but not blocked by Symantec Endpoint Protection (SEP) by filtering relevant security
Read MoreThis KQL query is designed to identify all connections made to potential or malicious websites that Symantec Endpoint Protection (SEP)
Read MoreDescription This guide explains how to detect cloud persistence activities performed by users identified as at risk using KQL queries.
Read MoreThis KQL query identifies discovery events performed by users marked as at risk within an Azure environment. It targets actions
Read MoreAMSI script detection KQL query is a crucial tool for monitoring Windows environments where the Antimalware Scan Interface detects potentially
Read MoreDetect anomalous group policy discovery by leveraging KQL queries to identify devices performing group policy scans they have not executed
Read MoreGolden Certificates are an advanced persistence technique linked to Active Directory Certificate Services (AD CS) compromises. When attackers gain administrative
Read MoreAdversaries can use LDAP to collect environment information. The query below can be used to detect anomalous amounts of LDAP
Read More