Detections
Explore public detection logic contributed by the community across SIEM and rule languages.
3 detections
Filters
Last updated
All Time
Detection languages
3
Contributors
3
Categories
2
1
1
1
1
Platforms
2
1
Products / Services
3
1
MITRE Techniques
17,957
15,455
12,307
8,184
6,031
This query helps you design client firewall rules based on data stored within DeviceNetworkEvents. Folder paths are alias'ed to help represent the
files making or receiving network connections without dealing with duplication from path variance due to different root drive letter or user profile
association.
To make the report easy to read, inbound remote IP addresses are not calculated by default (this can be changed by setting the value of IncludeInboundRemoteIPs to true).
Also, the ephemeral range is defaulted to 49152 to help eliminate false detections.
files making or receiving network connections without dealing with duplication from path variance due to different root drive letter or user profile
association.
To make the report easy to read, inbound remote IP addresses are not calculated by default (this can be changed by setting the value of IncludeInboundRemoteIPs to true).
Also, the ephemeral range is defaulted to 49152 to help eliminate false detections.
The following query surface network activity associated with exploitation of CVE-2022-22965.
Simple query to show the unique network connections that were audited or blocked by ExploitGuard.
For more questions on this query, feel free to ping @FlyingBlueMonki on twitter or mattegen@microsoft.com via email.
For more questions on this query, feel free to ping @FlyingBlueMonki on twitter or mattegen@microsoft.com via email.