How can I identify a grandparent process in Defender ATP detections?

后端 未结 0 1972
难免孤独
难免孤独 2021-01-21 05:02

I\'ve got a custom detection in Defender ATP that looks like this:


DeviceEvents
| where Timestamp > ago(1h)
| where ActionType startswith \'AsrLsassCredential         


        
相关标签:
回答
  • 消灭零回复
提交回复
热议问题