mirror of https://github.com/MISP/misp-book
new: [attribute type] kusto-query attribute type
Kusto query is the query language for the Kusto services in Azure used to search large dataset. It's used in Windows Defender ATP Hunting-Queries and also Azure Sentinel (Cloud-native SIEM).pull/184/head
parent
c89ee905a6
commit
c6bfe2aaa9
|
@ -86,6 +86,7 @@
|
||||||
|issue-date-of-the-visa| | | | | | |
|
|issue-date-of-the-visa| | | | | | |
|
||||||
|ja3-fingerprint-md5| | | | X | | |
|
|ja3-fingerprint-md5| | | | X | | |
|
||||||
|jabber-id| | | | | | |
|
|jabber-id| | | | | | |
|
||||||
|
|kusto-query| | X | | | | |
|
||||||
|last-name| | | | | | |
|
|last-name| | | | | | |
|
||||||
|link| X | | | X | | X |
|
|link| X | | | X | | X |
|
||||||
|mac-address| | | | X | | |
|
|mac-address| | | | X | | |
|
||||||
|
@ -251,6 +252,7 @@
|
||||||
|issue-date-of-the-visa| | | | | | |
|
|issue-date-of-the-visa| | | | | | |
|
||||||
|ja3-fingerprint-md5| X | | X | | | |
|
|ja3-fingerprint-md5| X | | X | | | |
|
||||||
|jabber-id| | | | | | |
|
|jabber-id| | | | | | |
|
||||||
|
|kusto-query| | | | | | |
|
||||||
|last-name| | | | | | |
|
|last-name| | | | | | |
|
||||||
|link| | | X | | | |
|
|link| | | X | | | |
|
||||||
|mac-address| X | | X | | | |
|
|mac-address| X | | X | | | |
|
||||||
|
@ -416,6 +418,7 @@
|
||||||
|issue-date-of-the-visa| X | | | |
|
|issue-date-of-the-visa| X | | | |
|
||||||
|ja3-fingerprint-md5| | | | |
|
|ja3-fingerprint-md5| | | | |
|
||||||
|jabber-id| | X | | |
|
|jabber-id| | X | | |
|
||||||
|
|kusto-query| | | | |
|
||||||
|last-name| X | | | |
|
|last-name| X | | | |
|
||||||
|link| | | X | |
|
|link| | | X | |
|
||||||
|mac-address| | | | |
|
|mac-address| | | | |
|
||||||
|
@ -601,6 +604,7 @@
|
||||||
* **issue-date-of-the-visa**: The date on which the visa was issued
|
* **issue-date-of-the-visa**: The date on which the visa was issued
|
||||||
* **ja3-fingerprint-md5**: JA3 is a method for creating SSL/TLS client fingerprints that should be easy to produce on any platform and can be easily shared for threat intelligence.
|
* **ja3-fingerprint-md5**: JA3 is a method for creating SSL/TLS client fingerprints that should be easy to produce on any platform and can be easily shared for threat intelligence.
|
||||||
* **jabber-id**: Jabber ID
|
* **jabber-id**: Jabber ID
|
||||||
|
* **kusto-query**: Kusto query - Kusto from Microsoft Azure is a service for storing and running interactive analytics over Big Data.
|
||||||
* **last-name**: Last name of a natural person
|
* **last-name**: Last name of a natural person
|
||||||
* **link**: Link to an external information
|
* **link**: Link to an external information
|
||||||
* **mac-address**: Mac address
|
* **mac-address**: Mac address
|
||||||
|
|
Loading…
Reference in New Issue