Sentinel-Queries
Sentinel-Queries copied to clipboard
Create Device_LocateMaliciousFile
This query filters DeviceFileEvents for a given malicious file name and extension within the last 30 days. It projects key attributes such as event time, action type, device details, file origin URL, folder path, and initiating user UPN to support security investigations.