Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Files, IP addresses, URLs, users, or devices associated with alerts
| Attribute | Value |
|---|---|
| Category | Internal |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes (source) |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AccountDomain | string | Domain of the account. |
| AccountName | string | User name of the account. |
| AccountObjectId | string | Unique identifier for the account in Microsoft Entra ID. |
| AccountSid | string | Security Identifier (SID) of the account. |
| AccountUpn | string | User principal name (UPN) of the account. |
| AdditionalFields | dynamic | Additional information about the event in JSON array format. |
| AlertId | string | Unique identifier for the alert. |
| Application | string | Application that performed the recorded action. |
| ApplicationId | int | Unique identifier for the application. |
| AttackTechniques | string | MITRE ATT&CK techniques associated with the activity that triggered the alert. |
| AzureResourceId | string | Unique identifier of the cloud resource associated with the alert. |
| AzureResourceType | string | Type of the cloud resource associated with the alert. |
| AzureSubscriptionId | string | Unique identifier of the Azure subscription associated with the alert. |
| Categories | string | List of categories that the information belongs to, in JSON array format. |
| CloudPlatform | string | The cloud platform that the resource belongs to, can be Azure, Amazon Web Services, or Google Cloud Platform. |
| CloudResource | string | Cloud resource name. |
| DetectionSource | string | Detection technology or sensor that identified the notable component or activity. |
| DeviceId | string | Unique identifier for the device in the service. |
| DeviceName | string | Fully qualified domain name (FQDN) of the machine. |
| EmailSubject | string | Subject of the email. |
| EntityType | string | Type of object, such as a file, a process, a device, or a user. |
| EvidenceDirection | string | Indicates whether the entity is the source or the destination of a network connection. |
| EvidenceRole | string | How the entity is involved in an alert, indicating whether it is impacted or is merely related. |
| FileName | string | Name of the file that the recorded action was applied to. |
| FileSize | long | Size of the file in bytes. |
| FolderPath | string | Folder containing the file that the recorded action was applied to. |
| LocalIP | string | IP address assigned to the local device used during communication. |
| NetworkMessageId | string | Unique identifier for the email, generated by Office 365. |
| OAuthApplicationId | string | Unique identifier of the third-party OAuth application. |
| ProcessCommandLine | string | Command line used to create the new process. |
| RegistryKey | string | Registry key that the recorded action was applied to. |
| RegistryValueData | string | Data of the registry value that the recorded action was applied to. |
| RegistryValueName | string | Name of the registry value that the recorded action was applied to. |
| RemoteIP | string | IP address that was being connected to. |
| RemoteUrl | string | URL or fully qualified domain name (FQDN) that was being connected to. |
| ServiceSource | string | Product or service that provided the alert information. |
| Severity | string | Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert. |
| SHA1 | string | SHA-1 of the file that the recorded action was applied to. |
| SHA256 | string | SHA-256 of the file that the recorded action was applied to. This field is usually not populated-use the SHA1 column when available. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| ThreatFamily | string | Malware family that the suspicious or malicious file or process has been classified under. |
| TimeGenerated | datetime | Date and time (UTC) when the record was generated. |
| Title | string | Title of the alert. |
| Type | string | The name of the table |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
In solution Microsoft Defender XDR: ActionType == "BrowserLaunchedToOpenUrl"EntityType in "MailMessage,Url"ServiceSource == "Microsoft Defender for Office 365"
| Analytic Rule |
|---|
| Possible Phishing with CSL and Network Sessions |
In solution Vectra XDR: EntityType in "Device,User"
| Analytic Rule |
|---|
| Defender Alert Evidence |
In solution Microsoft Defender XDR: ActionType == "Automated Remediation"
| Hunting Query |
|---|
| Automated Investigation Outcomes by Day |
Standalone Content:
| Hunting Query | Selection Criteria |
|---|---|
| MDE_Evidenceforasingledevice |
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| Automated Investigation Outcomes by Day | ActionType == "Automated Remediation" |
| Baseline Comparison | |
| Hunt for alerts correlated with Teams messages | ActionType == "ChatCreated" |
| Hunt for alerts correlated with Teams messages | ActionType == "ChatCreated" |
| Identify Microsoft Defender Antivirus detection related to EUROPIUM | |
| Identify acting user for reported phish | ActionType in "MoveToDeletedItems,MovedToDeletedItems" |
| Identify acting user for reported phish | ActionType in "MoveToDeletedItems,MovedToDeletedItems" |
| ImpersonatedUserFootprint | EntityType == "User" |
| KNOTWEED-AV Detections | |
| MDO daily detection summary report | |
| MDO daily detection summary report | |
| SuspiciousUrlClicked | |
| URL click on ZAP email | |
| URL click on ZAP email | |
| URLClick details based on malicious URL click alert | |
| URLClick details based on malicious URL click alert |
In solution ContinuousDiagnostics&Mitigation:
| Workbook | Selection Criteria |
|---|---|
| ContinuousDiagnostics&Mitigation |
In solution MaturityModelForEventLogManagementM2131:
| Workbook | Selection Criteria |
|---|---|
| MaturityModelForEventLogManagement_M2131 |
In solution Microsoft Defender XDR: ActionType in "AdminSubmission,AdminSubmissionSubmitted,AttackSimUserSubmission,CallParticipantDetail,CallReported,ClickAllowed,ClickBlocked,ClickBlockedByTenantPolicy,Malware ZAP,Phish ZAP,Spam ZAP,TeamsImpersonationDetected,UserSubmission"ActionType == "Automated Remediation"ActionType contains "Submission"ActionType contains "UserSubmission"ActionType contains "ZAP"ActionType has "ClickAllowed"ActionType has "ClickBlocked"ActionType has "Malware ZAP"ActionType has "Phish ZAP"ActionType has "Spam ZAP"ActionType has "ZAP"ActionType has_any "ClickAllowed"ActionType has_any "ClickBlocked"ActionType has_any "UrlErrorPage"ActionType has_any "UrlScanInProgress"
| Workbook |
|---|
| MicrosoftDefenderForOffice365detectionsandinsights |
In solution NISTSP80053:
| Workbook | Selection Criteria |
|---|---|
| NISTSP80053 |
In solution ZeroTrust(TIC3.0): ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"
| Workbook |
|---|
| ZeroTrustTIC3 |
GitHub Only:
| Workbook | Selection Criteria |
|---|---|
| DoDZeroTrustWorkbook | |
| ZeroTrustStrategyWorkbook |
| Parser | Schema | Product | Selection Criteria |
|---|---|---|---|
| ASimAlertEventMicrosoftDefenderXDR | AlertEvent | Microsoft Defender XDR |
References by type: 0 connectors, 11 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
ActionType == "ChatCreated" |
- | 2 | - | - | 2 |
ActionType == "Automated Remediation" |
- | 2 | - | - | 2 |
ActionType in "MoveToDeletedItems,MovedToDeletedItems" |
- | 2 | - | - | 2 |
ActionType == "BrowserLaunchedToOpenUrl"EntityType in "MailMessage,Url"ServiceSource == "Microsoft Defender for Office 365" |
- | 1 | - | - | 1 |
EntityType in "Device,User" |
- | 1 | - | - | 1 |
EntityType == "User" |
- | 1 | - | - | 1 |
ActionType in "AdminSubmission,AdminSubmissionSubmitted,AttackSimUserSubmission,CallParticipantDetail,CallReported,ClickAllowed,ClickBlocked,ClickBlockedByTenantPolicy,Malware ZAP,Phish ZAP,Spam ZAP,TeamsImpersonationDetected,UserSubmission"ActionType == "Automated Remediation"ActionType contains "Submission"ActionType contains "UserSubmission"ActionType contains "ZAP"ActionType has "ClickAllowed"ActionType has "ClickBlocked"ActionType has "Malware ZAP"ActionType has "Phish ZAP"ActionType has "Spam ZAP"ActionType has "ZAP"ActionType has_any "ClickAllowed"ActionType has_any "ClickBlocked"ActionType has_any "UrlErrorPage"ActionType has_any "UrlScanInProgress" |
- | 1 | - | - | 1 |
ActionType in "Add member to role,Add user,InteractiveLogon,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user" |
- | 1 | - | - | 1 |
| Total | 0 | 11 | 0 | 0 | 11 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Automated Remediation |
- | 3 | - | - | 3 |
ChatCreated |
- | 2 | - | - | 2 |
MoveToDeletedItems |
- | 2 | - | - | 2 |
MovedToDeletedItems |
- | 2 | - | - | 2 |
BrowserLaunchedToOpenUrl |
- | 1 | - | - | 1 |
AdminSubmission |
- | 1 | - | - | 1 |
AdminSubmissionSubmitted |
- | 1 | - | - | 1 |
AttackSimUserSubmission |
- | 1 | - | - | 1 |
CallParticipantDetail |
- | 1 | - | - | 1 |
CallReported |
- | 1 | - | - | 1 |
ClickAllowed |
- | 1 | - | - | 1 |
ClickBlocked |
- | 1 | - | - | 1 |
ClickBlockedByTenantPolicy |
- | 1 | - | - | 1 |
Malware ZAP |
- | 1 | - | - | 1 |
Phish ZAP |
- | 1 | - | - | 1 |
Spam ZAP |
- | 1 | - | - | 1 |
TeamsImpersonationDetected |
- | 1 | - | - | 1 |
UserSubmission |
- | 1 | - | - | 1 |
contains Submission |
- | 1 | - | - | 1 |
contains UserSubmission |
- | 1 | - | - | 1 |
contains ZAP |
- | 1 | - | - | 1 |
has ClickAllowed |
- | 1 | - | - | 1 |
has ClickBlocked |
- | 1 | - | - | 1 |
has Malware ZAP |
- | 1 | - | - | 1 |
has Phish ZAP |
- | 1 | - | - | 1 |
has Spam ZAP |
- | 1 | - | - | 1 |
has ZAP |
- | 1 | - | - | 1 |
has_any ClickAllowed |
- | 1 | - | - | 1 |
has_any ClickBlocked |
- | 1 | - | - | 1 |
has_any UrlErrorPage |
- | 1 | - | - | 1 |
has_any UrlScanInProgress |
- | 1 | - | - | 1 |
Add member to role |
- | 1 | - | - | 1 |
Add user |
- | 1 | - | - | 1 |
InteractiveLogon |
- | 1 | - | - | 1 |
RemoteInteractiveLogon |
- | 1 | - | - | 1 |
Reset user password |
- | 1 | - | - | 1 |
ResourceAccess |
- | 1 | - | - | 1 |
Sign-in |
- | 1 | - | - | 1 |
Update user |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
User |
- | 2 | - | - | 2 |
MailMessage |
- | 1 | - | - | 1 |
Url |
- | 1 | - | - | 1 |
Device |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Microsoft Defender for Office 365 |
- | 1 | - | - | 1 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊