Forum Discussion

Sohel68's avatar
Sohel68
Copper Contributor
Jul 12, 2023

Looking for KQL query when high volume of USB writes happens by a user

Hello, I did some online search, but I couldn't find any working one yet.  I'm looking for query which I can use in Advance threat hunting in MDE to generate an alert when a user copies huge number...

Resources