mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-20 21:03:42 +00:00
Updated advanced-hunting-windows-defender-advanced-threat-protection.md
This commit is contained in:
@ -56,7 +56,7 @@ A typical query starts with a table name followed by a series of operators separ
|
|||||||
|
|
||||||
In the following example, we start with the table name **ProcessCreationEvents** and add piped elements as needed.
|
In the following example, we start with the table name **ProcessCreationEvents** and add piped elements as needed.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
First, we define a time filter to review only records from the previous seven days.
|
First, we define a time filter to review only records from the previous seven days.
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user