Skip to content

Latest commit

 

History

History
12 lines (11 loc) · 431 Bytes

ExposureManagement - DeviceActivities.md

File metadata and controls

12 lines (11 loc) · 431 Bytes

List Activities Compromised Device Can Perform as Source

Sentinel

// List activities device can do as source
let DeviceName = "laptop.test.com";
ExposureGraphEdges
| where SourceNodeLabel == "device"
| where SourceNodeName == DeviceName
| summarize Total = dcount(TargetNodeName), Details = make_set(TargetNodeName) by EdgeLabel, SourceNodeName
| project Source = SourceNodeName, Action = EdgeLabel, Details, Tota