Replies: 1 comment
-
Hi @bldm0202, in my experience when I ran into this issue I was missing either of those ActionType(s): |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi everyone, this is my first time on Github and I'm not the most technical of persons.
I am hoping someone can provide some advice about why my Defender Advanced Threat Hunt outputs are not successfully parsing in the WDAC wizard.
I have followed the threat hunt query template outlined here:
https://github.com/MicrosoftDocs/WDAC-Toolkit/blob/main/WDAC-Policy-Wizard/docs/using/advanced-hunting.md
I've ensured my .csv output has all the data fields.
However, in the WDAC wizard policy editor I am not able to parse the threat hunting events and receive an error message. At a loss as to how to troubleshoot further.
Would appreciate any advice you may have.
Many thanks!
Beta Was this translation helpful? Give feedback.
All reactions