Firewall, proxy, and network appliance logs (CEF format) for traffic to malicious IPs.
KQL Query Preview
Read-only — detection query only
// Threat: CyberStrikeAI, AI-Native Platform Compromises 600+ FortiGate Devices [SCC-2026-0
let malicious_ips = dynamic(["212.11.64.250"]);
CommonSecurityLog
| where TimeGenerated > ago(30d)
| where DestinationIP in (malicious_ips) or SourceIP in (malicious_ips)
| project TimeGenerated, DeviceVendor, DeviceProduct, DeviceAction,
SourceIP, DestinationIP, DestinationPort, RequestURL,
Activity, LogSeverity
| sort by TimeGenerated desc