AlertEvidence

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index


Reference for AlertEvidence table in Azure Monitor Logs.

Attribute Value
Category Internal
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes (source)
Azure Monitor Tables Reference View Documentation

Contents

Schema (44 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable is false ingestion isn't billed to your Azure account
AccountDomain string Domain of the account.
AccountName string User name of the account.
AccountObjectId string Unique identifier for the account in Azure Active Directory.
AccountSid string Security Identifier (SID) of the account.
AccountUpn string User principal name (UPN) of the account.
AdditionalFields dynamic Additional information about the event in JSON array format.
AlertId string Unique identifier for the alert.
Application string Application that performed the recorded action.
ApplicationId int Unique identifier for the application.
AttackTechniques string MITRE ATT&CK techniques associated with the activity that triggered the alert.
Categories string List of categories that the information belongs to, in JSON array format.
CloudPlatform string The cloud platform that the resource belongs to, can be Azure, Amazon Web Services, or Google Cloud Platform.
CloudResource string Cloud resource name.
DetectionSource string Detection technology or sensor that identified the notable component or activity.
DeviceId string Unique identifier for the device in the service.
DeviceName string Fully qualified domain name (FQDN) of the machine.
EmailSubject string Subject of the email.
EntityType string Type of object, such as a file, a process, a device, or a user.
EvidenceDirection string Indicates whether the entity is the source or the destination of a network connection.
EvidenceRole string How the entity is involved in an alert, indicating whether it is impacted or is merely related.
FileName string Name of the file that the recorded action was applied to.
FileSize long Size of the file in bytes.
FolderPath string Folder containing the file that the recorded action was applied to.
LocalIP string IP address assigned to the local device used during communication.
NetworkMessageId string Unique identifier for the email, generated by Office 365.
OAuthApplicationId string Unique identifier of the third-party OAuth application.
ProcessCommandLine string Command line used to create the new process.
RegistryKey string Registry key that the recorded action was applied to.
RegistryValueData string Data of the registry value that the recorded action was applied to.
RegistryValueName string Name of the registry value that the recorded action was applied to.
RemoteIP string IP address that was being connected to.
RemoteUrl string URL or fully qualified domain name (FQDN) that was being connected to.
ServiceSource string Product or service that provided the alert information.
Severity string Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert.
SHA1 string SHA-1 of the file that the recorded action was applied to.
SHA256 string SHA-256 of the file that the recorded action was applied to. This field is usually not populated-use the SHA1 column when available.
SourceSystem string The type of agent the event was collected by. For example, OpsManager for Windows agent, either direct connect or Operations Manager, Linux for all Linux agents, or Azure for Azure Diagnostics
TenantId string The Log Analytics workspace ID
ThreatFamily string Malware family that the suspicious or malicious file or process has been classified under.
TimeGenerated datetime Date and time (UTC) when the record was generated.
Title string Title of the alert.
Type string The name of the table

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (6)

This table is used by the following solutions:


Content Items Using This Table (12)

Analytic Rules (2)

In solution Microsoft Defender XDR: ActionType == "BrowserLaunchedToOpenUrl"
EntityType in "MailMessage,Url"
ServiceSource == "Microsoft Defender for Office 365"

Analytic Rule
Possible Phishing with CSL and Network Sessions

In solution Vectra XDR: EntityType in "Device,User"

Analytic Rule
Defender Alert Evidence

Hunting Queries (5)

GitHub Only:

Hunting Query Selection Criteria
Hunt for alerts correlated with Teams messages ActionType == "ChatCreated"
Identify acting user for reported phish ActionType in "MoveToDeletedItems,MovedToDeletedItems"
MDO daily detection summary report
URL click on ZAP email
URLClick details based on malicious URL click alert

Workbooks (5)

In solution ContinuousDiagnostics&Mitigation:

Workbook Selection Criteria
ContinuousDiagnostics&Mitigation

In solution MaturityModelForEventLogManagementM2131: ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"

Workbook
MaturityModelForEventLogManagement_M2131

In solution Microsoft Defender XDR: ActionType in "AdminSubmissionSubmitted,AttackSimUserSubmission,ClickBlocked,Malware ZAP,Phish ZAP,Spam ZAP,UserSubmission"
ActionType == "Automated Remediation"
ActionType contains "Submission"
ActionType contains "UserSubmission"
ActionType contains "ZAP"
ActionType has "Malware ZAP"
ActionType has "Phish ZAP"
ActionType has "Spam ZAP"
ActionType has "ZAP"
ActionType has_any "ClickAllowed"
ActionType has_any "ClickBlocked"
ActionType has_any "UrlErrorPage"
ActionType has_any "UrlScanInProgress"

Workbook
MicrosoftDefenderForOffice365detectionsandinsights

In solution NISTSP80053:

Workbook Selection Criteria
NISTSP80053

In solution ZeroTrust(TIC3.0):

Workbook Selection Criteria
ZeroTrustTIC3

Parsers Using This Table (1)

ASIM Parsers (1)

Parser Schema Product Selection Criteria
ASimAlertEventMicrosoftDefenderXDR AlertEvent Microsoft Defender XDR

Selection Criteria Summary (6 criteria, 6 total references)

References by type: 0 connectors, 6 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
ActionType == "BrowserLaunchedToOpenUrl"
EntityType in "MailMessage,Url"
ServiceSource == "Microsoft Defender for Office 365"
- 1 - - 1
EntityType in "Device,User" - 1 - - 1
ActionType == "ChatCreated" - 1 - - 1
ActionType in "MoveToDeletedItems,MovedToDeletedItems" - 1 - - 1
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" - 1 - - 1
ActionType in "AdminSubmissionSubmitted,AttackSimUserSubmission,ClickBlocked,Malware ZAP,Phish ZAP,Spam ZAP,UserSubmission"
ActionType == "Automated Remediation"
ActionType contains "Submission"
ActionType contains "UserSubmission"
ActionType contains "ZAP"
ActionType has "Malware ZAP"
ActionType has "Phish ZAP"
ActionType has "Spam ZAP"
ActionType has "ZAP"
ActionType has_any "ClickAllowed"
ActionType has_any "ClickBlocked"
ActionType has_any "UrlErrorPage"
ActionType has_any "UrlScanInProgress"
- 1 - - 1
Total 0 6 0 0 6

ActionType

Value Connectors Content Items ASIM Parsers Other Parsers Total
BrowserLaunchedToOpenUrl - 1 - - 1
ChatCreated - 1 - - 1
MoveToDeletedItems - 1 - - 1
MovedToDeletedItems - 1 - - 1
Add member to role - 1 - - 1
Add user - 1 - - 1
InteractiveLogon - 1 - - 1
RemoteInteractiveLogon - 1 - - 1
Reset user password - 1 - - 1
ResourceAccess - 1 - - 1
Sign-in - 1 - - 1
Update user - 1 - - 1
AdminSubmissionSubmitted - 1 - - 1
AttackSimUserSubmission - 1 - - 1
ClickBlocked - 1 - - 1
Malware ZAP - 1 - - 1
Phish ZAP - 1 - - 1
Spam ZAP - 1 - - 1
UserSubmission - 1 - - 1
Automated Remediation - 1 - - 1
contains Submission - 1 - - 1
contains UserSubmission - 1 - - 1
contains ZAP - 1 - - 1
has Malware ZAP - 1 - - 1
has Phish ZAP - 1 - - 1
has Spam ZAP - 1 - - 1
has ZAP - 1 - - 1
has_any ClickAllowed - 1 - - 1
has_any ClickBlocked - 1 - - 1
has_any UrlErrorPage - 1 - - 1
has_any UrlScanInProgress - 1 - - 1

EntityType

Value Connectors Content Items ASIM Parsers Other Parsers Total
MailMessage - 1 - - 1
Url - 1 - - 1
Device - 1 - - 1
User - 1 - - 1

ServiceSource

Value Connectors Content Items ASIM Parsers Other Parsers Total
Microsoft Defender for Office 365 - 1 - - 1

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Tables Index