Forum Discussion

DKTimGjerlufsen's avatar
DKTimGjerlufsen
Copper Contributor
Apr 03, 2020

WDATP Alert detection query

Hi Community   I really need some help trying to build this query correct in KQL. The Query is reporting users who has created files onto a drive that is not the local C:\ I try to detect and aler...

Resources