Skip to content

Latest commit

 

History

History
19 lines (16 loc) · 398 Bytes

File metadata and controls

19 lines (16 loc) · 398 Bytes

List risky IP activities

Query Information

Description

This query activities from a Risky IP

Defender XDR

CloudAppEvents
| where IPCategory == "Risky"
| project Timestamp, ActionType, IPAddress, IPCategory, ISP, RawEventData

Sentinel

CloudAppEvents
| where IPCategory == "Risky"
| project TimeGenerated, ActionType, IPAddress, IPCategory, ISP, RawEventData