Developing A Baseline For Sensitive Process Access

Description of the query:
A starter query which leverages field projection to provide a high-level view of SENSITIVE_PROCESS_ACCESS activity for an org for developing a baseline or identifying outliers.

Query:

-24h | * | SENSITIVE_PROCESS_ACCESS | event/*/event/TARGET/FILE_PATH contains "lsass" | ts as Timestamp event/*/event/SOURCE/FILE_PATH as SOURCE  event/*/event/TARGET/FILE_PATH as TARGET