Query Details
Tags: Query: DeviceFileEvents | where isnotempty(FileOriginUrl) | where FileOriginUrl contains "cdn.discordapp.com/attachments/" or FileOriginReferrerUrl contains "cdn.discordapp.com/attachments/" | where FileName contains "pass" References:
This query is looking for specific file events on devices. Here's a simple breakdown:
In summary, this query is searching for files that originated from Discord attachments and have "pass" in their filenames.

Ali Hussein
Released: October 1, 2023
Tables
Keywords
Operators