Skip to content
This repository was archived by the owner on Nov 16, 2023. It is now read-only.

Commit 81dd736

Browse files
author
Alex Verboon
committed
query performance improvement
1 parent f18404b commit 81dd736

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

Persistence/LocalAdminGroupChanges.txt

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,11 @@ DeviceEvents
2020
| extend LocalGroup = AccountName
2121
| extend LocalGroupSID = AccountSid
2222
| extend Actor = trim(@"[^\w]+",InitiatingProcessAccountName)
23+
// limit to local administrators group
24+
// | where LocalGroupSID contains "S-1-5-32-544"
2325
| join kind= leftouter (NewUsers)
2426
on $left.AddedAccountSID == $right.NewUserSID
2527
| project Timestamp, DeviceName, LocalGroup,LocalGroupSID, AddedAccountSID, lUserAdded , Actor, ActionType , laccountdomain
26-
// limit to local administrators group
27-
// | where LocalGroupSID contains "S-1-5-32-544"
2828
| join kind= leftouter (ADAZUsers)
2929
on $left.AddedAccountSID == $right.OnPremSid
3030
| extend UserAdded = iff(isnotempty(lUserAdded),strcat(laccountdomain,"\\", lUserAdded), strcat(DirectoryDomain,"\\", DirectoryAccount))

0 commit comments

Comments
 (0)