Skip to content

Commit

Permalink
Monitoring restricted management administrative units abuse.kql
Browse files Browse the repository at this point in the history
  • Loading branch information
SlimKQL authored Sep 21, 2024
1 parent e54140d commit 0bafb16
Showing 1 changed file with 5 additions and 4 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -8,13 +8,14 @@

AuditLogs
| where TimeGenerated > (1h)
| where OperationName == "Add administrative unit"
| where parse_json(tostring(TargetResources[0].modifiedProperties))[2].displayName == "IsMemberManagementRestricted"
| where parse_json(tostring(parse_json(tostring(TargetResources[0].modifiedProperties))[2].newValue))[0] == true
| where (OperationName == "Add administrative unit" and
parse_json(tostring(TargetResources[0].modifiedProperties))[2].displayName == "IsMemberManagementRestricted" and
parse_json(tostring(parse_json(tostring(TargetResources[0].modifiedProperties))[2].newValue))[0] == true) or
OperationName == "Add member to restricted management administrative unit"
| extend RestrictedAUs = TargetResources[0].displayName
| extend UPN = parse_json(tostring(InitiatedBy.user)).userPrincipalName
| extend IPAddress = parse_json(tostring(InitiatedBy.user)).ipAddress
| project TimeGenerated, RestrictedAUs, UPN, IPAddress, AdditionalDetails
| project TimeGenerated, OperationName, RestrictedAUs, UPN, IPAddress, AdditionalDetails

// MITRE ATT&CK Technique Mapping

Expand Down

0 comments on commit 0bafb16

Please sign in to comment.