Skip to content

Commit 93780c6

Browse files
authored
Merge pull request #11678 from Azure/v-sabiraj-SentinelOneAnalyticrule
Updating Analytic rule with correct Activity type
2 parents 3653fbd + 999cc82 commit 93780c6

File tree

4 files changed

+89
-91
lines changed

4 files changed

+89
-91
lines changed

Solutions/SentinelOne/Analytic Rules/SentinelOneAgentUninstalled.yaml

Lines changed: 3 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,14 +18,13 @@ relevantTechniques:
1818
- T1070
1919
query: |
2020
SentinelOne
21-
| where ActivityType == 31
21+
| where ActivityType == 51
2222
| summarize count() by DataComputerName, bin(TimeGenerated, 30m)
2323
| where count_ > 1
24-
| extend HostCustomEntity = DataComputerName
2524
entityMappings:
2625
- entityType: Host
2726
fieldMappings:
2827
- identifier: HostName
29-
columnName: HostCustomEntity
30-
version: 1.0.1
28+
columnName: DataComputerName
29+
version: 1.0.2
3130
kind: Scheduled
35.4 KB
Binary file not shown.

0 commit comments

Comments
 (0)