Detection rules › Kusto Query Language
Google Threat Intelligence - Threat Hunting IP
'Google Threat Intelligence IP correlation.'
MITRE ATT&CK coverage
| Tactic | Techniques |
|---|---|
| Command & Control | T1071 Application Layer Protocol |
Event coverage
Stages and Predicates
Stage 1: source
_Im_NetworkSession
Stage 2: where
DstIpAddr is_not_null