Forum Discussion
Sohel68
Sep 26, 2023Copper Contributor
Can Defender for Endppoint alert on the download of any executable from the Internet?
Looking to if this is even possible from Defender for Endpoint alert on the download of any executable from the Internet?
Thanks in advance
- jaehwanCopper Contributor
1. DeviceFileEvents Table
DeviceFileEvents table in the advanced hunting schema | Microsoft Learn
2. Create Custom Alert
example query
DeviceFileEvents| where ingestion_time() > ago(7d)| where ActionType == "FileCreated"->