Skip to content

Instantly share code, notes, and snippets.

@Shivammalaviya
Last active July 29, 2021 03:54
Show Gist options
  • Save Shivammalaviya/ccc458ee77a45ef290be6b4e2681e004 to your computer and use it in GitHub Desktop.
Save Shivammalaviya/ccc458ee77a45ef290be6b4e2681e004 to your computer and use it in GitHub Desktop.
DeviceProcessEvents
| where Timestamp > ago(7d)
| where (InitiatingProcessCommandLine == 'gpresult /z'
or InitiatingProcessCommandLine == 'gpresult /v'
or InitiatingProcessCommandLine == 'gpresult'
or InitiatingProcessCommandLine == 'net view'
or InitiatingProcessCommandLine == 'net view /domain'
or InitiatingProcessCommandLine == 'netstat'
or InitiatingProcessCommandLine == 'netstat -nab'
or InitiatingProcessCommandLine == 'netstat -nao'
or InitiatingProcessCommandLine == 'nslookup 127.0.0.1'
or InitiatingProcessCommandLine == 'ipconfig /all'
or InitiatingProcessCommandLine == 'arp -a'
or InitiatingProcessCommandLine == 'net share'
or InitiatingProcessCommandLine == 'net use'
or InitiatingProcessCommandLine == 'systeminfo'
or InitiatingProcessCommandLine == 'net user'
or InitiatingProcessCommandLine == 'net user administrator'
or InitiatingProcessCommandLine == 'net user /domain'
or InitiatingProcessCommandLine == 'net group'
or InitiatingProcessCommandLine == 'net group /domain'
or InitiatingProcessCommandLine == 'net localgroup'
or InitiatingProcessCommandLine == 'net localgroup'
or InitiatingProcessCommandLine == 'net localgroup Administrators'
or InitiatingProcessCommandLine == 'net group \"Domain Computers\" /domain'
or InitiatingProcessCommandLine == 'net group \"Domain Admins\" /domain'
or InitiatingProcessCommandLine == 'net group \"Domain Controllers\" /domain'
or InitiatingProcessCommandLine == @'dir \\"%programfiles%\\"'
or InitiatingProcessCommandLine == 'net group \"Exchange Servers\" /domain'
or InitiatingProcessCommandLine == 'net accounts'
or InitiatingProcessCommandLine == 'net accounts /domain'
or InitiatingProcessCommandLine == 'net view 127.0.0.1 /all'
or InitiatingProcessCommandLine == 'net session'
or InitiatingProcessCommandLine == 'route print'
or InitiatingProcessCommandLine == 'ipconfig /displaydns')
|project Timestamp,DeviceName,InitiatingProcessCommandLine,InitiatingProcessAccountName
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment