Query Details
//Exposure Management - Slim's Metric (MaxCVSS-DAW) //https://www.linkedin.com/posts/activity-7178429122094772224-aK3e/ //Maximum CVSS for Domain Admin Workstations. A favorite KQL wish list for all CISO 😜 Secure your "keys" to your kingdom before it gets breached! //KQL Code: ExposureGraphNodes | where NodeProperties.rawData.criticalityLevel contains "Domain Admin Workstations" | where isnotnull(NodeProperties.rawData.highRiskVulnerabilityInsights) | extend MaxCvssScore = toreal(NodeProperties.rawData.highRiskVulnerabilityInsights.maxCvssScore) | sort by MaxCvssScore desc
This KQL query is designed to identify and prioritize high-risk vulnerabilities on Domain Admin Workstations by focusing on their maximum CVSS (Common Vulnerability Scoring System) scores. Here's a simplified breakdown:
ExposureGraphNodes table.In essence, this query helps security teams quickly identify which Domain Admin Workstations have the highest risk vulnerabilities, allowing them to prioritize their security efforts effectively.

Steven Lim
Released: August 2, 2024
Tables
Keywords
Operators