cloudflare/Azure-Sentinel
Publicmirrored fromhttps://github.com/cloudflare/Azure-Sentinel
| Name | Last committed | Last updated |
|---|---|---|
Replaced 'Domain' with 'Computer' in the join because domain will be 'Builtin' for the group and host/domain for the user, preventing a match. Also replaced 'CreatedUser' with 'CreatedUserSid' because the group add entry may not reliably include the name of the user added to the group (SID is also a more reliable identifier in general). Lasltly, removed 'where CreatedUserTime < GroupAddTime' because I'm not sure any other case is possible without manually rigging the logs.8454279 7 years ago | ||
| .github | 7 years ago | |
| Dashboards | 7 years ago | |
| Detections | 7 years ago | |
| docs | 7 years ago | |
| Exploration Queries | 7 years ago | |
| Functions | 7 years ago | |
| Hunting Queries | 7 years ago | |
| Notebooks | 7 years ago | |
| Parsers | 7 years ago | |
| Playbooks | 7 years ago | |