mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-20 04:43:37 +00:00
Updated advanced-hunting-windows-defender-advanced-threat-protection.md
This commit is contained in:
@ -56,7 +56,7 @@ A typical query starts with a table name followed by a series of operators separ
|
||||
|
||||
In the following example, we start with the table name **ProcessCreationEvents** and add piped elements as needed.
|
||||
|
||||

|
||||

|
||||
|
||||
First, we define a time filter to review only records from the previous seven days.
|
||||
|
||||
|
Reference in New Issue
Block a user