Query Details
Tags:
Query:
DeviceProcessEvents
| where ProcessCommandLine has_all ("osascript", "dialog", "password")
References:
The query is looking for DeviceProcessEvents where the ProcessCommandLine contains all three keywords: "osascript", "dialog", and "password".

Ali Hussein
Released: October 28, 2023
Tables
Keywords
Operators