You have a Microsoft 365 subscription. You have the following KQL query.
DeviceEvents
| where ActionType == "AntivirusDetection*
You need to ensure that you can create a Microsoft Defender XDR custom detection rule by using the query.
What should you add to the query?
Lorean
1 months agoCory
1 months agoChantell
1 months agoRonny
5 days agoNickie
16 days agoDelsie
16 days agoKallie
22 days agoTonja
2 months agoClorinda
3 days agoLucia
4 days agoGeraldine
13 days agoThomasena
2 months agoDetra
1 days agoThersa
2 days agoMarta
22 days agoVon
1 months agoValene
2 months agoVeta
3 months agoTrinidad
3 months ago