Skip to content

Commit

Permalink
Update readme.md
Browse files Browse the repository at this point in the history
  • Loading branch information
KwachSean committed Apr 8, 2024
1 parent 8cb7f12 commit f4500cb
Showing 1 changed file with 3 additions and 2 deletions.
Original file line number Diff line number Diff line change
Expand Up @@ -34,8 +34,9 @@ Upon completing this technical guide, you will gain the following abilities:<br>

**Prompt 1: Could you show me the event IDs associated with Remote execution from the SANS_DFPS_FOR508_v4.10_02-23 (1).pdf document from the uploaded files in a table format**

![Hunt Evil Poster](https://github.com/Azure/Copilot-For-Security/blob/main/Images/KB%20Images/huntevil.png?raw=true)
![hunt evil poster 1](https://github.com/Azure/Copilot-For-Security/blob/main/Images/KB%20Images/huntevilfileupload1.png)


**Prompt 2: Leveraging the above Event IDs , hunt my defender environment for any events associated with them.**
![Hunt Evil Poster 2](https://github.com/Azure/Copilot-For-Security/blob/main/Images/KB%20Images/huntevil2.png?raw=true)
![Hunt Evil Poster 2](https://github.com/Azure/Copilot-For-Security/blob/main/Images/KB%20Images/huntevilfileupload2)

0 comments on commit f4500cb

Please sign in to comment.