You have a Microsoft 365 subscription. You have the following KQL query.
DeviceEvents
| where ActionType == "AntivirusDetection*
You need to ensure that you can create a Microsoft Defender XDR custom detection rule by using the query.
What should you add to the query?
Lorean
2 months agoCory
2 months agoChantell
2 months agoLinwood
9 days agoSharee
10 days agoLaine
11 days agoRonny
1 months agoNickie
1 months agoDelsie
1 months agoKallie
2 months agoTonja
2 months agoClorinda
30 days agoLucia
1 months agoGeraldine
1 months agoThomasena
3 months agoDetra
28 days agoThersa
29 days agoMarta
2 months agoVon
2 months agoValene
3 months agoVeta
3 months agoTrinidad
4 months ago