-
Notifications
You must be signed in to change notification settings - Fork 3.5k
Open
Labels
HuntingHunting specialty review neededHunting specialty review neededenhancementNew feature or requestNew feature or requestfeature request
Description
For the cx the ask is to have an analytical rule for "Rare Custom Script Extension" -(Which is a Hunting Query as of now):
The Kql seems to be old hence I have updated the OperationNameValue in the KQL.
The first part is trying to extract for value FileURL and CommandToExecute in the Setting value.
but the Settings value which is loading up in the output has only have ********
in it which means the value are redacted/masked unable to get the actual values of FileURL and CommandToExecute..
I also tried projecting the output for values FileURL and CommandToExecute and it confirmed no extraction from settings:
Metadata
Metadata
Assignees
Labels
HuntingHunting specialty review neededHunting specialty review neededenhancementNew feature or requestNew feature or requestfeature request