@@ -17,11 +17,11 @@ SkillGroups:
1717 Settings :
1818 Target : Defender
1919 Template : |-
20- DeviceInfo
21- | where DeviceName contains '{{devicename}}'
22- | where Timestamp > ago(30d)
23- | summarize arg_max(Timestamp,*) by DeviceName
24- | project Timestamp, DeviceName, OSPlatform, OSVersionInfo, OSBuild, DeviceType, Vendor, JoinType
20+ DeviceInfo
21+ | where DeviceName contains '{{devicename}}'
22+ | where Timestamp > ago(30d)
23+ | summarize arg_max(Timestamp,*) by DeviceName
24+ | project Timestamp, DeviceName, OSPlatform, OSVersionInfo, OSBuild, DeviceType, Vendor, JoinType
2525
2626 - Name : DeviceIPInfo
2727 DisplayName : Device Current and Past IPs
@@ -33,14 +33,14 @@ SkillGroups:
3333 Settings :
3434 Target : Defender
3535 Template : |-
36- DeviceNetworkInfo
37- | where DeviceName contains '{{devicename}}'
38- | where Timestamp > ago(10d)
39- | mv-expand parsejson(IPAddresses)
40- | extend DeviceIPAddress = tostring(IPAddresses.IPAddress)
41- | summarize arg_max(Timestamp, DeviceIPAddress) by DeviceId, DeviceName, MacAddress
42- | project Timestamp, DeviceName, MacAddress, DeviceIPAddress
43- | sort by Timestamp
36+ DeviceNetworkInfo
37+ | where DeviceName contains '{{devicename}}'
38+ | where Timestamp > ago(10d)
39+ | mv-expand parsejson(IPAddresses)
40+ | extend DeviceIPAddress = tostring(IPAddresses.IPAddress)
41+ | summarize arg_max(Timestamp, DeviceIPAddress) by DeviceId, DeviceName, MacAddress
42+ | project Timestamp, DeviceName, MacAddress, DeviceIPAddress
43+ | sort by Timestamp
4444
4545 - Name : DeviceUserInfo
4646 DisplayName : Device Users and Login Counts
@@ -52,16 +52,16 @@ SkillGroups:
5252 Settings :
5353 Target : Defender
5454 Template : |-
55- DeviceInfo
56- | where DeviceName contains '{{devicename}}'
57- | where Timestamp > ago(30d)
58- | mv-expand parsejson(LoggedOnUsers)
59- | extend UserName = tostring(LoggedOnUsers.UserName)
60- | extend Domain = tostring(LoggedOnUsers.DomainName)
61- | extend Sid = tostring(LoggedOnUsers.Sid)
62- | summarize LoginCount = count() by DeviceName, UserName, Domain, Sid
63- | project DeviceName, UserName, LoginCount, Domain, Sid
64- | sort by LoginCount
55+ DeviceInfo
56+ | where DeviceName contains '{{devicename}}'
57+ | where Timestamp > ago(30d)
58+ | mv-expand parsejson(LoggedOnUsers)
59+ | extend UserName = tostring(LoggedOnUsers.UserName)
60+ | extend Domain = tostring(LoggedOnUsers.DomainName)
61+ | extend Sid = tostring(LoggedOnUsers.Sid)
62+ | summarize LoginCount = count() by DeviceName, UserName, Domain, Sid
63+ | project DeviceName, UserName, LoginCount, Domain, Sid
64+ | sort by LoginCount
6565
6666 - Name : DeviceAlertInfo
6767 DisplayName : Device Alert Information
@@ -73,13 +73,13 @@ SkillGroups:
7373 Settings :
7474 Target : Defender
7575 Template : |-
76- AlertInfo
77- | where Timestamp > ago(30d)
78- | join AlertEvidence on AlertId
79- | where DeviceName contains '{{devicename}}'
80- | extend Date = format_datetime(Timestamp, "yyyy-MM-dd")
81- | summarize by Date, Title, Severity, Categories, DetectionSource
82- | sort by Date desc, Categories
76+ AlertInfo
77+ | where Timestamp > ago(30d)
78+ | join AlertEvidence on AlertId
79+ | where DeviceName contains '{{devicename}}'
80+ | extend Date = format_datetime(Timestamp, "yyyy-MM-dd")
81+ | summarize by Date, Title, Severity, Categories, DetectionSource
82+ | sort by Date desc, Categories
8383
8484 - Name : DeviceAppInfo
8585 DisplayName : Device Installed Applications
0 commit comments