Forum Discussion

chetan787's avatar
chetan787
Copper Contributor
Jun 27, 2021

kql query for brute force/dictionary attack on a account in apptraces

I've been trying to create a KQL query on this use case. i've come up with the below. is this correct? appreciate suggestions    AppTraces | where TimeGenerated > ago(365d) | where Message contai...

Resources