MicrosoftDefenderForEndPoint

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Content Index


Attribute Value
Type Workbook
Solution Microsoft Defender XDR
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Selection Criteria Transformations Ingestion API Lake-Only
DeviceEvents ActionType in "AntivirusDetection,FileCreated,PnpDeviceConnected,UsbDriveMounted"
ActionType endswith "Audited"
ActionType endswith "Blocked"
ActionType startswith "Asr"
✓ ✗ ✓
DeviceFileCertificateInfo ✓ ✗ ✓
DeviceFileEvents ActionType == "AntivirusDetection" ✓ ✗ ✓
DeviceImageLoadEvents ✓ ✗ ✓
DeviceInfo ✓ ✗ ✓
DeviceLogonEvents ✓ ✗ ✓
DeviceNetworkEvents ✓ ✗ ✓
DeviceNetworkInfo ✓ ✗ ✓
DeviceProcessEvents ✓ ✗ ✓
DeviceRegistryEvents ✓ ✗ ✓

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Workbooks · Back to Microsoft Defender XDR