digicatM to blueteamsecEnglish · 8 months agoKQL: ExternalData - Cert Central, CertReport - "If this returns TRUE, it means that the cert has been reported in CertReport and therefore, there are high chances that this file is malicious."github.comexternal-linkmessage-square0linkfedilinkarrow-up14arrow-down10
arrow-up14arrow-down1external-linkKQL: ExternalData - Cert Central, CertReport - "If this returns TRUE, it means that the cert has been reported in CertReport and therefore, there are high chances that this file is malicious."github.comdigicatM to blueteamsecEnglish · 8 months agomessage-square0linkfedilink