Skip to content

DeviceProcess/VScodeExtensionofanUser.yaml - inaccurate & low fidelity #13288

@dpdug4n

Description

@dpdug4n

https://github.com/Azure/Azure-Sentinel/blob/master/Hunting%20Queries/DeviceProcess/VScodeExtensionofanUser.yaml

^ This query is empirically incorrect. It does not capture ALL extensions per user. Maybe do some more in-depth testing or adjust the description to account for the expected gaps in the query. In it's current state, it's misinformation.

Metadata

Metadata

Labels

HuntingHunting specialty review needed

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions