Forum Discussion
Advanced hunting query for pulling browser extension details and email address.
Hello,
I have created a query which pulls out users with lastpass on Edge browser extension, I'm not able to get email details from the "LoggedonUser".
1 Reply
Take this:
DeviceTvmBrowserExtensions
| join DeviceInfo on DeviceId
| where ExtensionName contains "LastPass"
| mv-expand LoggedOnUsers
| extend LoggedOnUser = tostring(LoggedOnUsers)
| where BrowserName == "edge"
| join kind=leftouter (
IdentityInfo
| where EmailAddress != ""
| project AccountName, EmailAddress, Department
) on $left.LoggedOnUser == $right.AccountName
| summarize
TotalDevices = dcount(DeviceName),
ExtensionOn = dcountif(DeviceId, IsActivated == "true"),
Accounts = makeset(AccountName),
Emails = makeset(EmailAddress),
Departments = makeset(Department)
by BrowserName, ExtensionName, ExtensionRisk, ExtensionId
| sort by ExtensionName asc