Skip to content

Commit f1a4ca8

Browse files
Update Azure Firewall - High severity malicious activity detected.yaml
1 parent 070a38a commit f1a4ca8

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

Solutions/Azure Firewall/Analytic Rules/Azure Firewall - High severity malicious activity detected.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -22,7 +22,7 @@ relevantTechniques:
2222
- T1003
2323
- T1204
2424
query: |
25-
let TimeWindow = 90d; // How far back to look (aligns with queryPeriod)
25+
let TimeWindow = 90d; // How far back to look
2626
let HitThreshold = 10; // Minimum hits to alert per SourceIp + Category
2727
let MinSeverity = 1; // Set Minimum Severity
2828
let EnableCategoryFilter = true; // Filter 1: use CategoriesOfInterest

0 commit comments

Comments
 (0)