Last active
July 29, 2021 03:54
-
-
Save Shivammalaviya/ccc458ee77a45ef290be6b4e2681e004 to your computer and use it in GitHub Desktop.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
DeviceProcessEvents | |
| where Timestamp > ago(7d) | |
| where (InitiatingProcessCommandLine == 'gpresult /z' | |
or InitiatingProcessCommandLine == 'gpresult /v' | |
or InitiatingProcessCommandLine == 'gpresult' | |
or InitiatingProcessCommandLine == 'net view' | |
or InitiatingProcessCommandLine == 'net view /domain' | |
or InitiatingProcessCommandLine == 'netstat' | |
or InitiatingProcessCommandLine == 'netstat -nab' | |
or InitiatingProcessCommandLine == 'netstat -nao' | |
or InitiatingProcessCommandLine == 'nslookup 127.0.0.1' | |
or InitiatingProcessCommandLine == 'ipconfig /all' | |
or InitiatingProcessCommandLine == 'arp -a' | |
or InitiatingProcessCommandLine == 'net share' | |
or InitiatingProcessCommandLine == 'net use' | |
or InitiatingProcessCommandLine == 'systeminfo' | |
or InitiatingProcessCommandLine == 'net user' | |
or InitiatingProcessCommandLine == 'net user administrator' | |
or InitiatingProcessCommandLine == 'net user /domain' | |
or InitiatingProcessCommandLine == 'net group' | |
or InitiatingProcessCommandLine == 'net group /domain' | |
or InitiatingProcessCommandLine == 'net localgroup' | |
or InitiatingProcessCommandLine == 'net localgroup' | |
or InitiatingProcessCommandLine == 'net localgroup Administrators' | |
or InitiatingProcessCommandLine == 'net group \"Domain Computers\" /domain' | |
or InitiatingProcessCommandLine == 'net group \"Domain Admins\" /domain' | |
or InitiatingProcessCommandLine == 'net group \"Domain Controllers\" /domain' | |
or InitiatingProcessCommandLine == @'dir \\"%programfiles%\\"' | |
or InitiatingProcessCommandLine == 'net group \"Exchange Servers\" /domain' | |
or InitiatingProcessCommandLine == 'net accounts' | |
or InitiatingProcessCommandLine == 'net accounts /domain' | |
or InitiatingProcessCommandLine == 'net view 127.0.0.1 /all' | |
or InitiatingProcessCommandLine == 'net session' | |
or InitiatingProcessCommandLine == 'route print' | |
or InitiatingProcessCommandLine == 'ipconfig /displaydns') | |
|project Timestamp,DeviceName,InitiatingProcessCommandLine,InitiatingProcessAccountName |
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment