Proactive Threat Hunting - Execute Query
This playbook will be executed from the "Proactive Threat Hunting" layout button with the objective of executing a query that will be provided by the analyst. The playbook supports executing a query using the following integrations: - Cortex XDR XQL Engine - Microsoft Defender For Endpoint
- Pack
- ProactiveThreatHunting
- Tasks
- 16
Commands used
- microsoft-atp-advanced-hunting
- setIncident
- xdr-xql-generic-query