{"payload":{"feedbackUrl":"https://github.com/orgs/community/discussions/53140","repo":{"id":395756791,"defaultBranch":"main","name":"AdvancedHuntingQueries","ownerLogin":"lawndoc","currentUserCanPush":false,"isFork":false,"isEmpty":false,"createdAt":"2021-08-13T18:35:30.000Z","ownerAvatar":"https://avatars.githubusercontent.com/u/24688343?v=4","public":true,"private":false,"isOrgOwned":false},"refInfo":{"name":"","listCacheKey":"v0:1628879730.706799","currentOid":""},"activityList":{"items":[{"before":"ffe9824c1b3d38fab6cdbb31c3a53ca8667666ed","after":"f449fd78124543f2269dd6656017b3d1035f5df2","ref":"refs/heads/main","pushedAt":"2023-11-22T17:39:28.000Z","pushType":"pr_merge","commitsCount":2,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"Merge pull request #1 from pemontto/patch-1\n\nUse direct URL to avoid intermittenet errors with redirected URL","shortMessageHtmlLink":"Merge pull request #1 from pemontto/patch-1"}},{"before":"448e44ad1a50008889c899619e9d6307170ad3ec","after":"ffe9824c1b3d38fab6cdbb31c3a53ca8667666ed","ref":"refs/heads/main","pushedAt":"2023-11-21T05:30:12.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"update RMM query and promote to detection rule","shortMessageHtmlLink":"update RMM query and promote to detection rule"}},{"before":"97b119f84b8ac6151b0a674c17eade4ba3dacfaf","after":"448e44ad1a50008889c899619e9d6307170ad3ec","ref":"refs/heads/main","pushedAt":"2023-11-06T16:49:25.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"add kerberos from unusual windows process","shortMessageHtmlLink":"add kerberos from unusual windows process"}},{"before":"0967c17e02eb1f8f6ccc0274f763bde9f1a6c675","after":"97b119f84b8ac6151b0a674c17eade4ba3dacfaf","ref":"refs/heads/main","pushedAt":"2023-09-22T16:41:01.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"add potential QR code phish detection","shortMessageHtmlLink":"add potential QR code phish detection"}},{"before":"6debe254db4460f7630c2f14a456921e47298c03","after":"0967c17e02eb1f8f6ccc0274f763bde9f1a6c675","ref":"refs/heads/main","pushedAt":"2023-09-06T12:42:51.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"move quick assist to new global exclusions list\n\nGives an example of excluding software from all devices","shortMessageHtmlLink":"move quick assist to new global exclusions list"}},{"before":"1d035ff3194bbc6caf13f896a0d1917dc0d15237","after":"6debe254db4460f7630c2f14a456921e47298c03","ref":"refs/heads/main","pushedAt":"2023-09-05T16:27:13.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"update RMM query","shortMessageHtmlLink":"update RMM query"}},{"before":"64e104b53ee7b378be164587a4943250e2c4c6d7","after":"1d035ff3194bbc6caf13f896a0d1917dc0d15237","ref":"refs/heads/main","pushedAt":"2023-08-21T16:18:17.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"fix ldap description","shortMessageHtmlLink":"fix ldap description"}},{"before":"f9970c14b255963f99aecd30fbd2ce1c11f6c544","after":"64e104b53ee7b378be164587a4943250e2c4c6d7","ref":"refs/heads/main","pushedAt":"2023-08-21T16:14:52.000Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"add undocumented RMM software hunt","shortMessageHtmlLink":"add undocumented RMM software hunt"}},{"before":"235267dd6bf5547ad807f8871657b207653b3741","after":"f9970c14b255963f99aecd30fbd2ce1c11f6c544","ref":"refs/heads/main","pushedAt":"2023-05-18T13:24:49.782Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"handle groups added to sensitive groups","shortMessageHtmlLink":"handle groups added to sensitive groups"}},{"before":"b85a10e420cd1387b8720a088b920e56d6de4f1c","after":"235267dd6bf5547ad807f8871657b207653b3741","ref":"refs/heads/main","pushedAt":"2023-05-16T22:34:12.637Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"updated rare service draft","shortMessageHtmlLink":"updated rare service draft"}},{"before":"626deedcb8a3659a0f9ef92777c4592ed66df3b8","after":"b85a10e420cd1387b8720a088b920e56d6de4f1c","ref":"refs/heads/main","pushedAt":"2023-05-16T21:24:14.711Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"forgot to add the content","shortMessageHtmlLink":"forgot to add the content"}},{"before":"4e510a3d7febcfdddfd9cda07e568cb33f733897","after":"626deedcb8a3659a0f9ef92777c4592ed66df3b8","ref":"refs/heads/main","pushedAt":"2023-05-16T18:18:17.086Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added emojies to categories as a visual aid","shortMessageHtmlLink":"added emojies to categories as a visual aid"}},{"before":"6192633e406f596156528bbd748d346d179095c5","after":"4e510a3d7febcfdddfd9cda07e568cb33f733897","ref":"refs/heads/main","pushedAt":"2023-05-16T18:12:13.913Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added rough drafts and user behavior categories","shortMessageHtmlLink":"added rough drafts and user behavior categories"}},{"before":"a7f61130a9b79696d11e8a15ccbee98b5a0be196","after":"6192633e406f596156528bbd748d346d179095c5","ref":"refs/heads/main","pushedAt":"2023-05-16T18:11:35.719Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"renamed interesting stats to user behavior","shortMessageHtmlLink":"renamed interesting stats to user behavior"}},{"before":"6f210503639374a7e81322d67c8e94ac23207137","after":"a7f61130a9b79696d11e8a15ccbee98b5a0be196","ref":"refs/heads/main","pushedAt":"2023-05-16T17:31:00.943Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added top remote logons query","shortMessageHtmlLink":"added top remote logons query"}},{"before":"1929702da6245494fad1378e059b39a4de9b236a","after":"6f210503639374a7e81322d67c8e94ac23207137","ref":"refs/heads/main","pushedAt":"2023-05-16T17:27:23.905Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"clean up wording","shortMessageHtmlLink":"clean up wording"}},{"before":"05ed7d3dba9cfc6afaa0a11712bd2f30530b829f","after":"1929702da6245494fad1378e059b39a4de9b236a","ref":"refs/heads/main","pushedAt":"2023-05-16T17:26:20.181Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"request credit when republished","shortMessageHtmlLink":"request credit when republished"}},{"before":"ee1d51fffd74984d540adb4494c63f016e10802c","after":"05ed7d3dba9cfc6afaa0a11712bd2f30530b829f","ref":"refs/heads/main","pushedAt":"2023-05-16T17:16:01.060Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"listed system process netcons issues","shortMessageHtmlLink":"listed system process netcons issues"}},{"before":"03882483fa220bad3d397c04b16744f34e9c75ab","after":"ee1d51fffd74984d540adb4494c63f016e10802c","ref":"refs/heads/main","pushedAt":"2023-05-16T17:14:07.737Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added system process network connections draft","shortMessageHtmlLink":"added system process network connections draft"}},{"before":"319b9687f025cdf9c790354e81463bdd77b31aa9","after":"03882483fa220bad3d397c04b16744f34e9c75ab","ref":"refs/heads/main","pushedAt":"2023-05-16T17:10:04.010Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added WiFi network names query","shortMessageHtmlLink":"added WiFi network names query"}},{"before":"cf0f75bd2261ef08bb6289bb0f0c9ecfaf851a13","after":"319b9687f025cdf9c790354e81463bdd77b31aa9","ref":"refs/heads/main","pushedAt":"2023-05-16T16:57:07.139Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added ucommon TLDs query","shortMessageHtmlLink":"added ucommon TLDs query"}},{"before":"687fb0dacb0056c7275e7619b88b494501da7342","after":"cf0f75bd2261ef08bb6289bb0f0c9ecfaf851a13","ref":"refs/heads/main","pushedAt":"2023-05-16T16:46:54.828Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"emphasize the importance of exploring the data for beginners","shortMessageHtmlLink":"emphasize the importance of exploring the data for beginners"}},{"before":"c492411cd3b1c9160bbc0dee13aad9069e1f3b5b","after":"687fb0dacb0056c7275e7619b88b494501da7342","ref":"refs/heads/main","pushedAt":"2023-05-16T16:44:17.669Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"clarified wording","shortMessageHtmlLink":"clarified wording"}},{"before":"e8abb76094dc0591093ad14dce0004a73b9757d5","after":"c492411cd3b1c9160bbc0dee13aad9069e1f3b5b","ref":"refs/heads/main","pushedAt":"2023-05-16T16:41:27.213Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added more getting started content","shortMessageHtmlLink":"added more getting started content"}},{"before":"82eec406b88985806ca46eb3793178fafaabe27c","after":"e8abb76094dc0591093ad14dce0004a73b9757d5","ref":"refs/heads/main","pushedAt":"2023-05-16T16:28:35.334Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added getting started with KQL section","shortMessageHtmlLink":"added getting started with KQL section"}},{"before":"431576ba595686c41a2314858308ccb9a01616f2","after":"82eec406b88985806ca46eb3793178fafaabe27c","ref":"refs/heads/main","pushedAt":"2023-05-16T16:10:32.852Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added detect all the things rough draft","shortMessageHtmlLink":"added detect all the things rough draft"}},{"before":"f732d05e0c529dfdfe0d743f9473b476845acd20","after":"431576ba595686c41a2314858308ccb9a01616f2","ref":"refs/heads/main","pushedAt":"2023-05-16T15:54:40.334Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added personal email usage query","shortMessageHtmlLink":"added personal email usage query"}},{"before":"9eca0ed47664895c79d4634239dfb4241580a78f","after":"f732d05e0c529dfdfe0d743f9473b476845acd20","ref":"refs/heads/main","pushedAt":"2023-05-16T15:52:01.229Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"added link to OneNote detection","shortMessageHtmlLink":"added link to OneNote detection"}},{"before":"1825c4e73235581343351881cc3ad2892ee33e7c","after":"9eca0ed47664895c79d4634239dfb4241580a78f","ref":"refs/heads/main","pushedAt":"2023-05-16T15:48:58.300Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"add anomalous OneNote location detection","shortMessageHtmlLink":"add anomalous OneNote location detection"}},{"before":"eaadcc149c8799c257faaba3144bfd3c97f324eb","after":"1825c4e73235581343351881cc3ad2892ee33e7c","ref":"refs/heads/main","pushedAt":"2023-05-16T15:34:45.820Z","pushType":"push","commitsCount":1,"pusher":{"login":"lawndoc","name":"C.J. May","path":"/lawndoc","primaryAvatarUrl":"https://avatars.githubusercontent.com/u/24688343?s=80&v=4"},"commit":{"message":"add top social media visitors","shortMessageHtmlLink":"add top social media visitors"}}],"hasNextPage":true,"hasPreviousPage":false,"activityType":"all","actor":null,"timePeriod":"all","sort":"DESC","perPage":30,"cursor":"djE6ks8AAAADtXSQuQA","startCursor":null,"endCursor":null}},"title":"Activity ยท lawndoc/AdvancedHuntingQueries"}