List New UserAgent Used Based On SigninLogs
Description This KQL query can be used to detect new UserAgents that have been used to perform sign in activities
Read MoreWhere Every Failure Becomes A Manual
Description This KQL query can be used to detect new UserAgents that have been used to perform sign in activities
Read MoreDescription This KQL query lists the devices that are on-boarded in Intune and classifies them based on the status of
Read MoreDescription This KQL query lists devices that can be on-boarded to Defender For Endpoint and have recently been detected. You
Read MoreDescription This KQL query lists how many devices have been on-boarded per operating system. Query Defender For Endpoint Microsoft Sentinel
Read MoreDescription This KQL query looks for Defender For Identity identified lateral movement paths to all sensitive accounts (if possible). This
Read MoreDescription This KQL query visualizes the top 100 users that have performed the most interactive sign ins. Query Microsoft Defender
Read MoreDescription This KQL query visualizes the daily antivirus detection, which can give an indication in anomalous amount of activities that
Read MoreSMB can be used in various ways by attackers, such as accessing remote shares, transfering files, interacting with systems using
Read MoreDescription Collect the top 10 user with the most IP used to successfully sign in to a tenant. This KQL
Read More