Plugins

Query: Identify agents with active threats

Description

Identify agents currently reporting one or more active threats. These endpoints may be compromised or under attack and should be prioritized for investigation and remediation. Monitoring this helps ensure threats are addressed before they can spread laterally or cause further damage.

Query

Tables used in this query:

SQL