Skip to content
This repository has been archived by the owner on Nov 16, 2023. It is now read-only.

Query improvements - Exfiltration to Competitor #298

Open
Jay1508 opened this issue Feb 3, 2021 · 0 comments
Open

Query improvements - Exfiltration to Competitor #298

Jay1508 opened this issue Feb 3, 2021 · 0 comments

Comments

@Jay1508
Copy link

Jay1508 commented Feb 3, 2021

Hi,

I believe the query "Detect Exfiltration to Competitor Organization" could be improved. Instead of filtering on the string "competitor", cant we just put the domain of the competitors:

EmailEvents
| where RecipientEmailAddress contains "competitor.com" // domain of the competitor.

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant