This repository has been archived by the owner on Nov 16, 2023. It is now read-only.
Releases: microsoft/Microsoft-365-Defender-Hunting-Queries
Releases · microsoft/Microsoft-365-Defender-Hunting-Queries
MDATP Advanced Hunting sample queries
Merge pull request #105 from pasilva-msft/patch-1 Change from AccountName To AccountSid
MDATP Advanced Hunting sample queries
Merge pull request #114 from anvascon/patch-1 Update WD AV Signature and Platform Version.txt
MDATP Advanced Hunting sample queries
Merge pull request #113 from rosenmoore/master improve detection of use of net.exe on CLI
MDATP Advanced Hunting sample queries
Merge pull request #71 from anthonws/master PUA ThreatName Per Computer
MDATP Advanced Hunting sample queries
Merge pull request #65 from FlyingBlueMonkey/patch-1 Create ExploitGuardNetworkProtectionEvents.txt
MDATP Advanced Hunting sample queries
Merge pull request #104 from makislev/master Update github queries to use the new advanced hunting device schema
MDATP Advanced Hunting sample queries
Exclude Engine Updates and Empty lines (#101) * Exclude Engine Updates and Empty lines This excludes engine updates (so really only signature updates are shown) and excludes empty lines. Engine Updates where in the result set due to entries like this: MpSigStub.exe /stub 1.1.16500.1 /payload 1.1.16500.1 /MpWUStub /program C:\windows\SoftwareDistribution\Download\Install\AM_Engine.exe /LastPackage AM_Engine.exe is the file name of engine updates. Empty results came from this command line "MpSigStub.exe /Store" and the corresponding file name is wuauclt.exe * Removed case sensitivity
MDATP Advanced Hunting sample queries
95390 Update README.md
About
94552 Update README.md