Forum Discussion

GI472's avatar
GI472
Brass Contributor
Sep 07, 2023

Defender KQL query for Windows firewall status changes?

Hi all,   I would like a KQL query that finds when the Windows firewall is stopped or turned off on our servers in the last 7 days, with the aim of creating a custom detection rule to alert.   So...

Resources