Skip to content

Commit

Permalink
Update cobalt-strike.md
Browse files Browse the repository at this point in the history
"Can you please change to AlertInfo table in MTP, the DeviceAlertEvents table is MDATP one and going to be deprecated."
  • Loading branch information
martyav committed Oct 14, 2020
1 parent 7bf1887 commit 73d9a2f
Showing 1 changed file with 1 addition and 1 deletion.
2 changes: 1 addition & 1 deletion Credential Access/cobalt-strike.md
Expand Up @@ -17,7 +17,7 @@ The following query identifies accounts that have logged on to compromised endpo

```Kusto
// Check for specific alerts
DeviceAlertEvents
AlertInfo
// Attempts to clear security event logs.
| where Title in("Event log was cleared",
// List alerts flagging attempts to delete backup files.
Expand Down

0 comments on commit 73d9a2f

Please sign in to comment.