From a8da6a5a14b2f4f6c10720d24624f8ac2eba2d34 Mon Sep 17 00:00:00 2001 From: Liza Mash Date: Sun, 25 Mar 2018 07:19:47 +0000 Subject: [PATCH 1/2] Updated advanced-hunting-windows-defender-advanced-threat-protection.md --- ...anced-hunting-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md index 1ceed89059..7394b1e678 100644 --- a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md @@ -160,7 +160,7 @@ The filter selections will resolve as an additional query term and the results w ## Public Advanced Hunting query GitHub repository -Check out the [Advanced Hunting repository](https://github.com/Microsoft/Advanced-Hunting-Queries). Contribute and use example queries shared by our customers. +Check out the [Advanced Hunting repository](https://github.com/Microsoft/WindowsDefenderATP-Hunting-Queries). Contribute and use example queries shared by our customers. >Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-advancedhunting-belowfoldlink) From 17b036ca54b66eb18a7b69e034e47f02eef8f115 Mon Sep 17 00:00:00 2001 From: Liza Mash Date: Sun, 25 Mar 2018 07:41:20 +0000 Subject: [PATCH 2/2] Updated advanced-hunting-windows-defender-advanced-threat-protection.md --- ...vanced-hunting-windows-defender-advanced-threat-protection.md | 1 - 1 file changed, 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md index 7394b1e678..5e9c033c35 100644 --- a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md @@ -97,7 +97,6 @@ The following tables are exposed as part of advanced hunting: - **LogonEvents** - Stores all login events - **ImageLoadEvents** - Stores all load dll events - **MiscEvents** - Stores several types of events, including Windows Defender Exploit Guard, Windows Defender SmartScreen, Windows Defender Application Guard, and Firewall events. -- **SuspiciousEvents** - Stores all events that deviate from typical event behavior ## Use shared queries Shared queries are prepopulated queries that give you a starting point on running queries on your organization's data. It includes a couple of examples that help demonstrate the query language capabilities.