Skip to content
This repository has been archived by the owner on Nov 16, 2023. It is now read-only.

Releases: microsoft/Microsoft-365-Defender-Hunting-Queries

MDATP Advanced Hunting sample queries

22 Apr 08:55
434dc39
Compare
Choose a tag to compare
Merge pull request #105 from pasilva-msft/patch-1

Change from AccountName To AccountSid

MDATP Advanced Hunting sample queries

22 Apr 08:52
163db56
Compare
Choose a tag to compare
Merge pull request #114 from anvascon/patch-1

Update WD AV Signature and Platform Version.txt

MDATP Advanced Hunting sample queries

22 Apr 08:50
b31f46c
Compare
Choose a tag to compare
Merge pull request #113 from rosenmoore/master

improve detection of use of net.exe on CLI

MDATP Advanced Hunting sample queries

22 Apr 08:46
2146930
Compare
Choose a tag to compare
Merge pull request #71 from anthonws/master

PUA ThreatName Per Computer

MDATP Advanced Hunting sample queries

22 Apr 08:33
e437abd
Compare
Choose a tag to compare
Merge pull request #65 from FlyingBlueMonkey/patch-1

Create ExploitGuardNetworkProtectionEvents.txt

MDATP Advanced Hunting sample queries

05 Jan 15:18
5aa4bb9
Compare
Choose a tag to compare
Merge pull request #104 from makislev/master

Update github queries to use the new advanced hunting device schema

MDATP Advanced Hunting sample queries

11 Dec 20:27
Compare
Choose a tag to compare
Exclude Engine Updates and Empty lines (#101)

* Exclude Engine Updates and Empty lines

This excludes engine updates (so really only signature updates are shown) and excludes empty lines.

Engine Updates where in the result set due to entries like this:

MpSigStub.exe /stub 1.1.16500.1 /payload 1.1.16500.1 /MpWUStub /program C:\windows\SoftwareDistribution\Download\Install\AM_Engine.exe /LastPackage

AM_Engine.exe is the file name of engine updates.

Empty results came from this command line "MpSigStub.exe /Store" and the corresponding file name is wuauclt.exe

* Removed case sensitivity

MDATP Advanced Hunting sample queries

28 Oct 12:23
fbb2b73
Compare
Choose a tag to compare
95390

Update README.md

About

24 Oct 07:54
6826947
Compare
Choose a tag to compare
94552

Update README.md