SecurityAlert

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Reference for SecurityAlert table in Azure Monitor Logs.

Attribute Value
Category Internal
Basic Logs Eligible ✗ No (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation

Contents

Schema (35 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AlertLink string
AlertName string
AlertSeverity string
AlertType string
CompromisedEntity string
ConfidenceLevel string
ConfidenceScore real
Description string
DisplayName string
EndTime datetime
Entities string
ExtendedLinks string
ExtendedProperties string
IsIncident bool
ProcessingEndTime datetime
ProductComponentName string
ProductName string
ProviderName string
RemediationSteps string
ResourceId string
SourceComputerId string
StartTime datetime
Status string
SubTechniques string
SystemAlertId string
Tactics string
Techniques string
TimeGenerated datetime
Type string The name of the table
VendorName string
VendorOriginalId string
WorkspaceResourceGroup string
WorkspaceSubscriptionId string

Schema References

Official Microsoft Learn documentation for field/column information:

Additional Information

📖 Related Documentation: Security alert schema reference - Describes the SecurityAlert table schema and field definitions

Solutions (51)

This table is used by the following solutions:


Content Items Using This Table (178)

Analytic Rules (56)

In solution AzureDevOpsAuditing: ProviderName == "IPC"

Analytic Rule
Azure DevOps Pipeline modified by a new user

In solution Dragos:

Analytic Rule Selection Criteria
Dragos Notifications

In solution IoTOTThreatMonitoringwithDefenderforIoT:

Analytic Rule Selection Criteria
Denial of Service (Microsoft Defender for IoT) AlertName == "Suspicion of Denial Of Service Attack"
ProviderName == "IoTSecurity"
Excessive Login Attempts (Microsoft Defender for IoT) AlertName in "Excessive Login Attempts,Excessive Number of Sessions,Excessive SMB login attempts,Password Guessing Attempt Detected"
ProviderName == "IoTSecurity"
Firmware Updates (Microsoft Defender for IoT) AlertName has_any "Beckhoff Software Changed"
ProviderName == "IoTSecurity"
High bandwidth in the network (Microsoft Defender for IoT) AlertName in "ARP Spoofing,Abnormal Traffic Bandwidth,Abnormal Traffic Bandwidth Between Devices,ICMP Flooding"
ProviderName == "IoTSecurity"
Illegal Function Codes for ICS traffic (Microsoft Defender for IoT) ProviderName == "IoTSecurity"
Internet Access (Microsoft Defender for IoT) AlertName has "Internet"
ProviderName == "IoTSecurity"
Multiple scans in the network (Microsoft Defender for IoT) AlertName has "Scan"
ProviderName == "IoTSecurity"
No traffic on Sensor Detected (Microsoft Defender for IoT) AlertName == "No Traffic Detected on Sensor Interface"
ProviderName == "IoTSecurity"
PLC Stop Command (Microsoft Defender for IoT) ProviderName == "IoTSecurity"
PLC unsecure key state (Microsoft Defender for IoT) AlertName has "PLC Operating Mode Changed"
ProviderName == "IoTSecurity"
Suspicious malware found in the network (Microsoft Defender for IoT) ProviderName == "IoTSecurity"
Unauthorized DHCP configuration in the network (Microsoft Defender for IoT) AlertName == "Device Failed to Receive a Dynamic IP Address"
ProviderName == "IoTSecurity"
Unauthorized PLC changes (Microsoft Defender for IoT) ProviderName == "IoTSecurity"
Unauthorized device in the network (Microsoft Defender for IoT) AlertName in "Abnormal usage of MAC Addresses,Field Device Discovered Unexpectedly,New Asset Detected,New LLDP Device Configuration"
ProviderName == "IoTSecurity"
Unauthorized remote access to the network (Microsoft Defender for IoT) AlertName == "Unauthorized SSH Access"
ProviderName == "IoTSecurity"

In solution Microsoft Business Applications:

Analytic Rule Selection Criteria
Dataverse - Guest user exfiltration following Power Platform defense impairment
Dataverse - Suspicious use of TDS endpoint Entities has "Type"
Dataverse - Terminated employee exfiltration over email
Power Apps - Multiple users access a malicious link after launching new app

In solution Microsoft Defender XDR:

Analytic Rule Selection Criteria
AV detections related to SpringShell Vulnerability
AV detections related to Tarrask malware
AV detections related to Ukraine threats ProviderName == "MDATP"

In solution Microsoft Defender for Cloud:

Analytic Rule Selection Criteria
Detect CoreBackUp Deletion Activity from related Security Alerts

In solution Microsoft Defender for Cloud Apps:

Analytic Rule Selection Criteria
Linked Malicious Storage Artifacts

In solution Microsoft Entra ID Protection:

Analytic Rule Selection Criteria
Correlate Unfamiliar sign-in properties & atypical travel alerts

In solution MicrosoftDefenderForEndpoint: ProviderName == "MDATP"

Analytic Rule
Aqua Blizzard AV hits - Feb 2022

In solution MicrosoftPurviewInsiderRiskManagement:

Analytic Rule Selection Criteria
Insider Risk_High User Security Alert Correlations
Insider Risk_Microsoft Purview Insider Risk Management Alert Observed ProductName == "Microsoft 365 Insider Risk Management"

In solution Multi Cloud Attack Coverage Essentials - Resource Abuse:

Analytic Rule Selection Criteria
Cross-Cloud Suspicious user activity observed in GCP Envourment ProductName !in "Azure Sentinel"
Successful AWS Console Login from IP Address Observed Conducting Password Spray AlertName in "Multiple failed user log on attempts to an app,Password Spray"
ProductName in "Azure Active Directory Identity Protection,Microsoft Cloud App Security"
Suspicious AWS console logins by credential access alerts AlertSeverity == "High"
ProductName in "Azure Active Directory,Azure Active Directory Identity Protection,Microsoft 365 Defender,Microsoft Cloud App Security,Microsoft Defender ATP,Microsoft Defender Advanced Threat Protection"
Tactics in "CredentialAccess,InitialAccess"
User impersonation by Identity Protection alerts AlertSeverity == "High"
ProductName has "Azure Active Directory Identity Protection"

In solution Threat Intelligence:

Analytic Rule Selection Criteria
TI Map URL Entity to SecurityAlert Data
TI map Domain entity to SecurityAlert
TI map Email entity to SecurityAlert

In solution Threat Intelligence (NEW):

Analytic Rule Selection Criteria
TI Map Domain entity to SecurityAlert
TI Map Email entity to SecurityAlert
TI Map URL Entity to SecurityAlert Data

In solution Web Shells Threat Protection:

Analytic Rule Selection Criteria
Malicious web application requests linked with Microsoft Defender for Endpoint (formerly Microsoft Defender ATP) alerts

In solution Zinc Open Source:

Analytic Rule Selection Criteria
AV detections related to Zinc actors

Standalone Content:

Analytic Rule Selection Criteria
AV detections related to Dev-0530 actors ProviderName == "MDATP"
AV detections related to Europium actors
AV detections related to Hive Ransomware
Detecting Impossible travel with mailbox permission tampering & Privilege Escalation attempt AlertName == "Impossible travel activity"
Dev-0228 File Path Hashes November 2021
Dev-0228 File Path Hashes November 2021 (ASIM Version) ProviderName == "MDATP"
M365D Alerts Correlation to non-Microsoft Network device network activity involved in successful sign-in Activity
Mass Download & copy to USB device by single user
Microsoft Defender for Endpoint (MDE) signatures for Azure Synapse pipelines and Azure Data Factory
Phishing link click observed in Network Traffic ProviderName in "OATP,Office 365 Advanced Threat Protection"
Prestige ransomware IOCs Oct 2022
Solorigate Defender Detections
Workspace deletion activity from an infected device AlertName == "Sign-in from an infected device"
ProductName == "Azure Active Directory Identity Protection"

GitHub Only: AlertSeverity has_any "Medium"
ProductName in "Azure Active Directory,Azure Active Directory Identity Protection,Microsoft 365 Defender,Microsoft Cloud App Security,Microsoft Defender ATP,Microsoft Defender Advanced Threat Protection"

Analytic Rule
Suspicious VM Instance Creation Activity Detected

Hunting Queries (31)

In solution AzureDevOpsAuditing: ProviderName == "IPC"

Hunting Query
Azure DevOps - New Package Feed Created
Azure DevOps - New Release Pipeline Created

In solution Cloud Identity Threat Protection Essentials:

Hunting Query Selection Criteria
Application Granted EWS Permissions

In solution Legacy IOC based Threat Protection:

Hunting Query Selection Criteria
Dev-0056 Command Line Activity November 2021
Dev-0322 Command Line Activity November 2021
Dev-0322 Command Line Activity November 2021 (ASIM Version)
Dev-0322 File Drop Activity November 2021
Dev-0322 File Drop Activity November 2021 (ASIM Version)
Nylon Typhoon Command Line Activity November 2021 ProductName == "Microsoft Defender Advanced Threat Protection"
Retrospective hunt for Forest Blizzard IP IOCs

In solution Microsoft Business Applications: ProviderName == "IPC"

Hunting Query
Dataverse - Activity after Microsoft Entra alerts

In solution MicrosoftPurviewInsiderRiskManagement:

Hunting Query Selection Criteria
Insider Risk_Entity Anomaly Followed by IRM Alert
Insider Risk_ISP Anomaly to Exfil
Insider Risk_Possible Sabotage

Standalone Content:

Hunting Query Selection Criteria
Alerts On Host
Alerts related to File
Alerts related to IP
Tracking Privileged Account Rare Activity
Web shell command alert enrichment
Web shell file alert enrichment ProviderName == "MDATP"

GitHub Only:

Hunting Query Selection Criteria
Alerts With This Process
Alerts related to account
BitLocker Key Retrieval
Dev-0056 Command Line Activity November 2021 (ASIM Version)
Exchange Servers and Associated Security Alerts
Integrate Purview with Cloud App Events
Recon Activity with Interactive Logon Correlation AlertName has_any "Atypical travel"
SQL Alert Correlation with CommonSecurityLogs and AuditLogs AlertName has_any "Potential SQL Injection"
Storage Alert Correlation with CommonSecurityLogs and StorageLogs DisplayName has_any "Potential malware uploaded to a storage blob container"
Storage Alerts Correlation with CommonSecurityLogs & AuditLogs AlertName has_any "Access from a suspicious IP to a storage file share"
Unfamiliar Signin Correlation with AzurePortal Signin Attempts and AuditLogs AlertName == "Unfamiliar sign-in properties"

Workbooks (73)

In solution Apache Log4j Vulnerability Detection:

Workbook Selection Criteria
Log4jImpactAssessment

In solution Azure Key Vault: AlertType startswith "KV_"

Workbook
AzureKeyVaultWorkbook

In solution Azure SQL Database solution for sentinel: AlertType startswith "SQL."
AlertType startswith "SQl."

Workbook
Workbook-AzureSQLSecurity

In solution Azure kubernetes Service: AlertType in "K8S_ClusterAdminBinding,K8S_MaliciousContainerExec,K8S_PrivilegedContainer,K8S_SensitiveMount"
AlertType startswith "K8S_"

Workbook
AksSecurity

In solution AzureSecurityBenchmark: AlertName contains "auth"
AlertName contains "cert"
AlertName contains "cred"
AlertName contains "password"
AlertName contains "secret"

Workbook
AzureSecurityBenchmark

In solution Censys:

Workbook Selection Criteria
Censys

In solution ContinuousDiagnostics&Mitigation: ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management,Microsoft Defender Advanced Threat Protection"

Workbook
ContinuousDiagnostics&Mitigation

In solution CybersecurityMaturityModelCertification(CMMC)2.0: ProductName == "Microsoft 365 Insider Risk Management"

Workbook
CybersecurityMaturityModelCertification_CMMCV2

In solution DNS Essentials:

Workbook Selection Criteria
DNSSolutionWorkbook

In solution DORA Compliance: AlertName has_any "Backup Failure"
AlertName has_any "Blocked"
AlertName has_any "Compliance Violation"
AlertName has_any "Credential Access"
AlertName has_any "Data Exfiltration"
AlertName has_any "Incident Reported"
AlertName has_any "Malware"
AlertName has_any "Policy Change"
AlertName has_any "Service Outage"
AlertName has_any "Suspicious Login"
AlertName has_any "TLPT"
AlertName has_any "Third-Party"
AlertName has_any "Threat Intelligence"
AlertName has_any "Unauthorized Access"
AlertName has_any "Vulnerability Exploitation"

Workbook
DORACompliance

In solution DPDP Compliance: AlertName contains "PII"
AlertName contains "confidential"
AlertName contains "intellectual"
AlertName contains "leak"
AlertName contains "sensitive"
AlertName contains "spill"
AlertName contains "steal"
AlertName contains "theft"
Tactics contains "exfil"

Workbook
DPDPCompliance

In solution ExtraHop: ProductName == "ExtraHop"

Workbook
ExtraHopDetectionsOverview

In solution GDPR Compliance & Data Security: AlertName contains "PII"
AlertName contains "confidential"
AlertName contains "intellectual"
AlertName contains "leak"
AlertName contains "sensitive"
AlertName contains "spill"
AlertName contains "steal"
AlertName contains "theft"
Tactics contains "exfil"

Workbook
GDPRComplianceAndDataSecurity

In solution GreyNoiseThreatIntelligence:

Workbook Selection Criteria
GreyNoiseOverview

In solution HIPAA Compliance:

Workbook Selection Criteria
HIPAACompliance

In solution Infoblox:

Workbook Selection Criteria
Infoblox_Lookup_Workbook
Infoblox_Workbook

In solution Infoblox SOC Insights:

Workbook Selection Criteria
InfobloxSOCInsightsWorkbook

In solution Lumen Defender Threat Feed:

Workbook Selection Criteria
Lumen-Threat-Feed-Overview

In solution MaturityModelForEventLogManagementM2131:

Workbook Selection Criteria
MaturityModelForEventLogManagement_M2131

In solution Microsoft Active Directory Tier Model:

Workbook Selection Criteria
MicrosoftADTierModel

In solution Microsoft Defender Threat Intelligence:

Workbook Selection Criteria
MicrosoftThreatIntelligence

In solution Microsoft Defender XDR:

Workbook Selection Criteria
MicrosoftDefenderForIdentity
MicrosoftDefenderForOffice365detectionsandinsights

In solution Microsoft Defender for Cloud Apps: AlertType has "DISCOVERY"
ProductName == "Microsoft Cloud App Security"

Workbook
MicrosoftCloudAppSecurity

In solution MicrosoftPurviewInsiderRiskManagement: AlertName contains "PII"
AlertName contains "anomal"
AlertName contains "confidential"
AlertName contains "data"
AlertName contains "fusion"
AlertName contains "intellectual"
AlertName contains "leak"
AlertName contains "sensitive"
AlertName contains "spill"
AlertName contains "steal"
AlertName contains "theft"
ProductName == "Microsoft 365 Insider Risk Management"
Tactics contains "exfil"

Workbook
InsiderRiskManagement

In solution NISTSP80053: ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"

Workbook
NISTSP80053

In solution Network Session Essentials:

Workbook Selection Criteria
NetworkSessionEssentials
NetworkSessionEssentialsV2

In solution ReversingLabs:

Workbook Selection Criteria
ReversingLabs-CapabilitiesOverview

In solution SAP BTP: Entities has "SAP BTP"

Workbook
SAPBTPActivity

In solution SOC Handbook:

Workbook Selection Criteria
AnalyticsEfficiency ProductName == "Azure Sentinel"
AnomalyData
AzureSentinelSecurityAlerts
IncidentOverview ProductName == "Azure Sentinel"
IntsightsIOCWorkbook
InvestigationInsights
MITREAttack
SentinelCentral DisplayName has "Incident"
DisplayName has "Investigation"
DisplayName has "Security operations efficiency"

In solution Threat Intelligence:

Workbook Selection Criteria
ThreatIntelligence

In solution Threat Intelligence (NEW):

Workbook Selection Criteria
ThreatIntelligenceNew

In solution ThreatAnalysis&Response:

Workbook Selection Criteria
DynamicThreatModeling&Response ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"
ThreatAnalysis&Response

In solution ThreatConnect:

Workbook Selection Criteria
ThreatConnectOverview

In solution Web Session Essentials:

Workbook Selection Criteria
WebSessionEssentials

In solution ZeroTrust(TIC3.0): AlertName contains "mal"
Entities contains "Fail"
Entities contains "inbound"
Entities contains "outbound"
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"

Workbook
ZeroTrustTIC3

GitHub Only:

Workbook Selection Criteria
ASC-ComplianceandProtection
AdvancedWorkbookConcepts
AksSecurity AlertType in "K8S_ClusterAdminBinding,K8S_MaliciousContainerExec,K8S_PrivilegedContainer,K8S_SensitiveMount"
AlertType startswith "K8S_"
AnalyticsEfficiency ProductName == "Azure Sentinel"
AnomalyData
AzureKeyVaultWorkbook AlertType startswith "KV_"
AzureSentinelSecurityAlerts
DSTIMWorkbook
DoDZeroTrustWorkbook AlertName contains "unsanctioned"
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"
ExchangeCompromiseHunting
IOT_Alerts AlertSeverity in "High,Low,Medium"
ProductName == "Azure Security Center for IoT"
IntsightsIOCWorkbook
InvestigationInsights
MITREAttack
MicrosoftCloudAppSecurity AlertType contains "DISCOVERY"
ProductName == "Microsoft Cloud App Security"
MicrosoftSecurityLicenseUtilization
MicrosoftSentinelDeploymentandMigrationTracker DisplayName has "Playbooks health"
OptimizationWorkbook
PhishingAnalysis
SentinelWorkspaceReconTools
Sentinel_Central DisplayName has "Incident"
DisplayName has "Investigation"
DisplayName has "Security operations efficiency"
SolarWindsPostCompromiseHunting ProviderName in "Azure Security Center,MDATP"
ThreatIntelligence
UserEntityBehaviorAnalytics
VisualizationDemo
ZeroTrustStrategyWorkbook AlertName contains "unsanctioned"
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"
microsoftdefenderforidentity

Parsers Using This Table (2)

Other Parsers (2)

Parser Solution Selection Criteria
DragosNotificationsToSentinel Dragos
DragosPullNotificationsToSentinel Dragos

Resource Types

This table collects data from the following Azure resource types:

Selection Criteria Summary (45 criteria, 59 total references)

References by type: 0 connectors, 59 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
ProviderName == "MDATP" - 5 - - 5
ProviderName == "IPC" - 4 - - 4
ProviderName == "IoTSecurity" - 4 - - 4
ProductName == "Microsoft 365 Insider Risk Management" - 2 - - 2
AlertName contains "PII"
AlertName contains "confidential"
AlertName contains "intellectual"
AlertName contains "leak"
AlertName contains "sensitive"
AlertName contains "spill"
AlertName contains "steal"
AlertName contains "theft"
Tactics contains "exfil"
- 2 - - 2
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management" - 2 - - 2
ProductName == "Azure Sentinel" - 2 - - 2
AlertName == "Suspicion of Denial Of Service Attack"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName in "Excessive Login Attempts,Excessive Number of Sessions,Excessive SMB login attempts,Password Guessing Attempt Detected"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName has_any "Beckhoff Software Changed"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName in "ARP Spoofing,Abnormal Traffic Bandwidth,Abnormal Traffic Bandwidth Between Devices,ICMP Flooding"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName == "No Traffic Detected on Sensor Interface"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName has "PLC Operating Mode Changed"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName has "Internet"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName has "Scan"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName in "Abnormal usage of MAC Addresses,Field Device Discovered Unexpectedly,New Asset Detected,New LLDP Device Configuration"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName == "Device Failed to Receive a Dynamic IP Address"
ProviderName == "IoTSecurity"
- 1 - - 1
AlertName == "Unauthorized SSH Access"
ProviderName == "IoTSecurity"
- 1 - - 1
Entities has "Type" - 1 - - 1
ProductName !in "Azure Sentinel" - 1 - - 1
AlertName in "Multiple failed user log on attempts to an app,Password Spray"
ProductName in "Azure Active Directory Identity Protection,Microsoft Cloud App Security"
- 1 - - 1
AlertSeverity == "High"
ProductName in "Azure Active Directory,Azure Active Directory Identity Protection,Microsoft 365 Defender,Microsoft Cloud App Security,Microsoft Defender ATP,Microsoft Defender Advanced Threat Protection"
Tactics in "CredentialAccess,InitialAccess"
- 1 - - 1
AlertSeverity == "High"
ProductName has "Azure Active Directory Identity Protection"
- 1 - - 1
AlertName == "Impossible travel activity" - 1 - - 1
ProviderName in "OATP,Office 365 Advanced Threat Protection" - 1 - - 1
AlertSeverity has_any "Medium"
ProductName in "Azure Active Directory,Azure Active Directory Identity Protection,Microsoft 365 Defender,Microsoft Cloud App Security,Microsoft Defender ATP,Microsoft Defender Advanced Threat Protection"
- 1 - - 1
AlertName == "Sign-in from an infected device"
ProductName == "Azure Active Directory Identity Protection"
- 1 - - 1
ProductName == "Microsoft Defender Advanced Threat Protection" - 1 - - 1
AlertName has_any "Atypical travel" - 1 - - 1
AlertName has_any "Potential SQL Injection" - 1 - - 1
AlertName has_any "Access from a suspicious IP to a storage file share" - 1 - - 1
DisplayName has_any "Potential malware uploaded to a storage blob container" - 1 - - 1
AlertName == "Unfamiliar sign-in properties" - 1 - - 1
AlertType startswith "KV_" - 1 - - 1
AlertType in "K8S_ClusterAdminBinding,K8S_MaliciousContainerExec,K8S_PrivilegedContainer,K8S_SensitiveMount"
AlertType startswith "K8S_"
- 1 - - 1
AlertType startswith "SQL."
AlertType startswith "SQl."
- 1 - - 1
AlertName contains "auth"
AlertName contains "cert"
AlertName contains "cred"
AlertName contains "password"
AlertName contains "secret"
- 1 - - 1
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management,Microsoft Defender Advanced Threat Protection" - 1 - - 1
AlertName has_any "Backup Failure"
AlertName has_any "Blocked"
AlertName has_any "Compliance Violation"
AlertName has_any "Credential Access"
AlertName has_any "Data Exfiltration"
AlertName has_any "Incident Reported"
AlertName has_any "Malware"
AlertName has_any "Policy Change"
AlertName has_any "Service Outage"
AlertName has_any "Suspicious Login"
AlertName has_any "TLPT"
AlertName has_any "Third-Party"
AlertName has_any "Threat Intelligence"
AlertName has_any "Unauthorized Access"
AlertName has_any "Vulnerability Exploitation"
- 1 - - 1
ProductName == "ExtraHop" - 1 - - 1
AlertType has "DISCOVERY"
ProductName == "Microsoft Cloud App Security"
- 1 - - 1
AlertName contains "PII"
AlertName contains "anomal"
AlertName contains "confidential"
AlertName contains "data"
AlertName contains "fusion"
AlertName contains "intellectual"
AlertName contains "leak"
AlertName contains "sensitive"
AlertName contains "spill"
AlertName contains "steal"
AlertName contains "theft"
ProductName == "Microsoft 365 Insider Risk Management"
Tactics contains "exfil"
- 1 - - 1
Entities has "SAP BTP" - 1 - - 1
DisplayName has "Incident"
DisplayName has "Investigation"
DisplayName has "Security operations efficiency"
- 1 - - 1
AlertName contains "mal"
Entities contains "Fail"
Entities contains "inbound"
Entities contains "outbound"
ProductName in "Azure Active Directory Identity Protection,Azure Security Center for IoT,Microsoft 365 Insider Risk Management"
- 1 - - 1
Total 0 59 0 0 59

AlertName

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains PII - 3 - - 3
contains confidential - 3 - - 3
contains intellectual - 3 - - 3
contains leak - 3 - - 3
contains sensitive - 3 - - 3
contains spill - 3 - - 3
contains steal - 3 - - 3
contains theft - 3 - - 3
Suspicion of Denial Of Service Attack - 1 - - 1
Excessive Login Attempts - 1 - - 1
Excessive Number of Sessions - 1 - - 1
Excessive SMB login attempts - 1 - - 1
Password Guessing Attempt Detected - 1 - - 1
has_any Beckhoff Software Changed - 1 - - 1
ARP Spoofing - 1 - - 1
Abnormal Traffic Bandwidth - 1 - - 1
Abnormal Traffic Bandwidth Between Devices - 1 - - 1
ICMP Flooding - 1 - - 1
No Traffic Detected on Sensor Interface - 1 - - 1
has PLC Operating Mode Changed - 1 - - 1
has Internet - 1 - - 1
has Scan - 1 - - 1
Abnormal usage of MAC Addresses - 1 - - 1
Field Device Discovered Unexpectedly - 1 - - 1
New Asset Detected - 1 - - 1
New LLDP Device Configuration - 1 - - 1
Device Failed to Receive a Dynamic IP Address - 1 - - 1
Unauthorized SSH Access - 1 - - 1
Multiple failed user log on attempts to an app - 1 - - 1
Password Spray - 1 - - 1
Impossible travel activity - 1 - - 1
Sign-in from an infected device - 1 - - 1
has_any Atypical travel - 1 - - 1
has_any Potential SQL Injection - 1 - - 1
has_any Access from a suspicious IP to a storage file share - 1 - - 1
Unfamiliar sign-in properties - 1 - - 1
contains auth - 1 - - 1
contains cert - 1 - - 1
contains cred - 1 - - 1
contains password - 1 - - 1
contains secret - 1 - - 1
has_any Backup Failure - 1 - - 1
has_any Blocked - 1 - - 1
has_any Compliance Violation - 1 - - 1
has_any Credential Access - 1 - - 1
has_any Data Exfiltration - 1 - - 1
has_any Incident Reported - 1 - - 1
has_any Malware - 1 - - 1
has_any Policy Change - 1 - - 1
has_any Service Outage - 1 - - 1
has_any Suspicious Login - 1 - - 1
has_any TLPT - 1 - - 1
has_any Third-Party - 1 - - 1
has_any Threat Intelligence - 1 - - 1
has_any Unauthorized Access - 1 - - 1
has_any Vulnerability Exploitation - 1 - - 1
contains anomal - 1 - - 1
contains data - 1 - - 1
contains fusion - 1 - - 1
contains mal - 1 - - 1

AlertSeverity

Value Connectors Content Items ASIM Parsers Other Parsers Total
High - 2 - - 2
has_any Medium - 1 - - 1

AlertType

Value Connectors Content Items ASIM Parsers Other Parsers Total
startswith KV_ - 1 - - 1
K8S_ClusterAdminBinding - 1 - - 1
K8S_MaliciousContainerExec - 1 - - 1
K8S_PrivilegedContainer - 1 - - 1
K8S_SensitiveMount - 1 - - 1
startswith K8S_ - 1 - - 1
startswith SQL. - 1 - - 1
startswith SQl. - 1 - - 1
has DISCOVERY - 1 - - 1

DisplayName

Value Connectors Content Items ASIM Parsers Other Parsers Total
has_any Potential malware uploaded to a storage blob container - 1 - - 1
has Incident - 1 - - 1
has Investigation - 1 - - 1
has Security operations efficiency - 1 - - 1

Entities

Value Connectors Content Items ASIM Parsers Other Parsers Total
has Type - 1 - - 1
has SAP BTP - 1 - - 1
contains Fail - 1 - - 1
contains inbound - 1 - - 1
contains outbound - 1 - - 1

ProductName

Value Connectors Content Items ASIM Parsers Other Parsers Total
Azure Active Directory Identity Protection - 8 - - 8
Microsoft 365 Insider Risk Management - 7 - - 7
Microsoft Cloud App Security - 4 - - 4
Microsoft Defender Advanced Threat Protection - 4 - - 4
Azure Security Center for IoT - 4 - - 4
Azure Active Directory - 2 - - 2
Microsoft 365 Defender - 2 - - 2
Microsoft Defender ATP - 2 - - 2
Azure Sentinel - 2 - - 2
!= Azure Sentinel - 1 - - 1
has Azure Active Directory Identity Protection - 1 - - 1
ExtraHop - 1 - - 1

ProviderName

Value Connectors Content Items ASIM Parsers Other Parsers Total
IoTSecurity - 15 - - 15
MDATP - 5 - - 5
IPC - 4 - - 4
OATP - 1 - - 1
Office 365 Advanced Threat Protection - 1 - - 1

Tactics

Value Connectors Content Items ASIM Parsers Other Parsers Total
contains exfil - 3 - - 3
CredentialAccess - 1 - - 1
InitialAccess - 1 - - 1

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index