Hunting-Queries-Detection-Rules icon indicating copy to clipboard operation
Hunting-Queries-Detection-Rules copied to clipboard

Exposure management - EEG-criticalassets

Open mhobbelen opened this issue 8 months ago • 0 comments
trafficstars

This query only returns the default criticalassets defined by MS, not the custom classifications or the default ones which are manually changed to a higer classication. At the moment, only domaincontrollers and entraID connect servers are returned as level 0. In the GUI, also ADCS servers are promoted to level 0 and SCCM also. This is not returned by the query

mhobbelen avatar Mar 19 '25 10:03 mhobbelen