Mar 28 2023 07:57 AM - edited Mar 28 2023 08:01 AM
Should I expect to see any DNS query events from DFE endpoints in the IdentityQueryEvents schema table if I have DFI enabled?
This doc - Understand the advanced hunting schema - states the IdentityQueryEvents schema is for "Queries for Active Directory objects, such as users, groups, devices, and domains", but I my understanding was DNS query events from DFE endpoints would show up in the DeviceNetworkEvents schema table.
Mar 28 2023 02:59 PM
@SpeedRacer theoretically yes, but there might be edge-cases where some DNS requests won't be visible on MDI but rather on MDE, depending on what DNS server is used.
For MDE use ActionType: DnsQueryRequest
For MDI use ActionType: DNS query
I would suggest putting up usecases on both datasources.
Mar 29 2023 06:34 AM