โ† Library
kqlMITfrom Azure/Azure-Sentinel

Potential Build Process Compromise

'The query looks for source code files being modified immediately after a build process is started. The purpose of this is to look for malicious code injection during the build process. More details: https://techcommunity.microsoft.com/t5/azure-sentinel/monitoring-the-software-supply-chain-with-azure-sentinel/ba-p/2176463'

Quality
100
FP risk
โ€”
Forks
0
Views
2
ATT&CK techniques
Rule source๐Ÿ”’ locked
๐Ÿ”’

Sign in to view the rule source

Free accounts can view the source for the top-ranked rules. Create one in seconds โ€” no credit card required.

Sign in โ†’
Potential Build Process Compromise ยท KQL rule | DetectionLint