You have a Microsoft 365 subscription. You have the following KQL query.
DeviceEvents
| where ActionType == "AntivirusDetection*
You need to ensure that you can create a Microsoft Defender XDR custom detection rule by using the query.
What should you add to the query?
Lorean
15 days agoCory
16 days agoChantell
17 days agoKallie
2 days agoTonja
25 days agoThomasena
1 months agoMarta
2 days agoVon
13 days agoValene
2 months agoVeta
2 months agoTrinidad
2 months ago