Skip to content

Instantly share code, notes, and snippets.

@P01JY
P01JY / wipe-threat-hunting.kql
Created April 12, 2026 21:05
Threat Hunting for Intune Wipe - BridgedCyber Blog #3 KQL
IntuneAuditLogs
| where TimeGenerated >= ago(7d)
| where OperationName == "wipe ManagedDevice"
| where Identity contains "JohnDoe"