Consultas para a tabela DnsEvents

Clientes a Resolver Domínios Maliciosos

Clientes distintos que resolvem domínios maliciosos.

DnsEvents
| where SubType == 'LookupQuery' and isnotempty(MaliciousIP)
| summarize count() by ClientIP