Query Details
DeviceProcessEvents | where ProcessCommandLine contains "msdt.exe" | where InitiatingProcessFileName has_any (@"WINWORD.EXE", @"EXCEL.EXE", @"OUTLOOK.EXE")
This query is looking for events related to a specific process called "msdt.exe". It then filters those events to only include cases where the initiating process is either "WINWORD.EXE", "EXCEL.EXE", or "OUTLOOK.EXE".

C.J. May
Released: June 30, 2022
Tables
Keywords
Operators