-
Notifications
You must be signed in to change notification settings - Fork 539
User ID's Monitoring #335
Comments
@PuneethRaya Hi Puneeth, ATP doesn't log web authentication logs however, if your web application redirect to url that contain "user ID" after successful login you can use below query to check user machine's AD login info.
|
Thank you very much!! |
@PuneethRaya Sure, Just save your hunting query as detection rule. Add Timestamp and ReportId in your project, something like below..
|
Wonderful!!one more last request... Is it possible get in output which web URL successful authentication happened ? |
DeviceNetworkEvents This helped me !!thank you !! |
Is there any way to restrict post authentication user shouldn't perform any activity/block or at least sending an auto email to the that particular AD users? |
@PuneethRaya hey, when you save your query as a detection rule, you can configure your email for alert notification. after that you can forward that email to that particular user based on the email content. |
@PuneethRaya FYI there are also two tables which monitor identities logons : |
Hello Team,
In our workstations , we have set of applications access from the browser. We want to monitor if any one logged in the respective applications with one particular user ID. Is there any way to monitor and get an alerts by using custom scripts and any other way? Any solution will be really appreciable.
The text was updated successfully, but these errors were encountered: