KQL for search CVE in Sentinel #24
Replies: 4 comments
-
|
Hi, (partial image from the Microsoft 365 Defender connector that is currently in preview) You can read more here. Now, if you want to have this info from the Sentinel there are solutions with 3rd party solutions that you can deploy on Sentinel workspace i.e. Tenable TVM you can read a related blog post here. In case you want to do it with M365D you can go to https://security.microsoft.com and then go to "Advanced Hunting" and run the following type of query: and you will get something like that back: Don't forget that this is coming soon to Sentinel, so as always patience will be rewarding :) HTH |
Beta Was this translation helpful? Give feedback.
-
|
I see that the Tenable TVM solution is also available at the "Content Hub" inside the Sentinel's environment. |
Beta Was this translation helpful? Give feedback.
-
|
Thanks for the information, it will help a lot. I also need to associate the CVE with a certain incident. For example, in my entire incident history, I have someone associated with CVE-2022-33631. I need to find out if I have and if so how many incidents associated with a given CVE. |
Beta Was this translation helpful? Give feedback.
-
|
You can sometimes find other CVE info, but as above it depends what Tables you have and if there is any CVE to be found, a quick check would be: search "CVE-2022" |
Beta Was this translation helpful? Give feedback.


Uh oh!
There was an error while loading. Please reload this page.
-
What tip can you pass to create a query to validate if a particular CVE has generated an incident in the environment?
For example, CVE XXXX, in my environment I have incident related to it.
Beta Was this translation helpful? Give feedback.
All reactions