Sep 26 2023 12:10 PM
Looking to if this is even possible from Defender for Endpoint alert on the download of any executable from the Internet?
Thanks in advance
Sep 27 2023 01:01 AM
1. DeviceFileEvents Table
DeviceFileEvents table in the advanced hunting schema | Microsoft Learn
2. Create Custom Alert
example query
->