Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts


Description

'As part of content migration, this file is moved to new location. you can find here: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Web%20Shells%20Threat%20Protection'

Rule logic

Source file
Raw source Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts · KQL
Esc
Published by Azure/Azure-Sentinel ↗, licensed under MIT ↗. Reproduced here unmodified.
id: 9699e4c9-dca9-404b-be0b-6e342dd31aff
name: Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts
description: |
  'As part of content migration, this file is moved to new location. you can find here: https://github.com/Azure/Azure-Sentinel/blob/master/Solutions/Web%20Shells%20Threat%20Protection'
version: 1.0.3
kind: Scheduled

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.