Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity, including severity information and threat categorization
| Attribute | Value |
|---|---|
| Category | Internal |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| AlertId | string | Unique identifier for the alert. |
| AttackTechniques | string | MITRE ATT&CK techniques associated with the activity that triggered the alert. |
| Category | string | Type of threat indicator or breach activity identified by the alert. |
| DetectionSource | string | Detection technology or sensor that identified the notable component or activity. |
| ServiceSource | string | Product or service that provided the alert information. |
| Severity | string | Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert. |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | Date and time (UTC) when the record was generated. |
| Title | string | Title of the alert. |
| Type | string | The name of the table |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
In solution Microsoft Defender XDR: Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected"
| Analytic Rule |
|---|
| Potential Ransomware activity related to Cobalt Strike |
In solution Microsoft Defender XDR:
| Hunting Query | Selection Criteria |
|---|---|
| Alerts Related to Log4j Vulnerability | Title == "Suspicious script launched" |
| Devices with Log4j vulnerability alerts and additional other alert related context | |
| Microsoft Teams chat initiated by a suspicious external user | Title == "Microsoft Teams chat initiated by a suspicious external user" |
| Potential Ransomware activity related to Cobalt Strike | Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected" |
GitHub Only:
| Hunting Query | Selection Criteria |
|---|---|
| Alerts related to Log4j vulnerability | Title == "Suspicious script launched" |
| Antivirus detections (1) | Title contains "Defender AV detected" |
| Baseline Comparison | |
| Cobalt Strike Lateral Movement | Title in "File droppedlaunched from remote location,Suspicious transfer of an executable file" |
| Devices with Log4j vulnerability alerts and additional other alert related context | |
| Distribution from remote location | Title == "File droppedlaunched from remote location" |
| Events surrounding alert (1) | |
| Events surrounding alert (3) | |
| ExploitGuardBlockOfficeChildProcess (1) | ActionType == "AsrOfficeChildProcessAudited" |
| ExploitGuardBlockOfficeChildProcess (3) | ActionType == "AsrOfficeChildProcessAudited" |
| File Backup Deletion Alerts | Title == "File backups were deleted" |
| Gootkit File Delivery | Title == "Suspected delivery of Gootkit malware" |
| Gootkit-malware | Title == "Suspected delivery of Gootkit malware" |
| ImpersonatedUserFootprint | ActionType == "LogonSuccess" |
| Microsoft Teams chat initiated by a suspicious external user | Title == "Microsoft Teams chat initiated by a suspicious external user" |
| Open email link | ActionType == "BrowserLaunchedToOpenUrl" |
| Potential ransomware activity related to Cobalt Strike | Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected" |
| Ransomware hits healthcare - Backup deletion | Title == "File backups were deleted" |
| Ransomware hits healthcare - Possible compromised accounts | Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,malware was detected" |
| Sticky Keys | Title == "Sticky Keys binary hijack detected" |
| SuspiciousUrlClicked | ActionType == "BrowserLaunchedToOpenUrl" |
| URL click on ZAP email | Title contains "Email messages containing malicious URL removed after delivery" |
| URL click on ZAP email | Title contains "Email messages containing malicious URL removed after delivery" |
| URLClick details based on malicious URL click alert | Title contains "Potentially malicious" |
| URLClick details based on malicious URL click alert | Title contains "Potentially malicious" |
| backup-deletion | Title == "File backups were deleted" |
| cobalt-strike | Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected" |
| identify-accounts-logged-on-to-endpoints-affected-by-cobalt-strike | Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected" |
GitHub Only: ActionType in "Add member to role,Add user,InteractiveLogon,LogonSuccess,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"
| Workbook |
|---|
| DoDZeroTrustWorkbook |
| ZeroTrustStrategyWorkbook |
References by type: 0 connectors, 28 content items, 0 ASIM parsers, 0 other parsers.
| Selection Criteria | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected" |
- | 3 | - | - | 3 |
Title == "File backups were deleted" |
- | 3 | - | - | 3 |
Title == "Microsoft Teams chat initiated by a suspicious external user" |
- | 2 | - | - | 2 |
Title contains "Email messages containing malicious URL removed after delivery" |
- | 2 | - | - | 2 |
Title contains "Potentially malicious" |
- | 2 | - | - | 2 |
Title == "Suspicious script launched" |
- | 2 | - | - | 2 |
Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected" |
- | 2 | - | - | 2 |
Title == "Suspected delivery of Gootkit malware" |
- | 2 | - | - | 2 |
ActionType == "BrowserLaunchedToOpenUrl" |
- | 2 | - | - | 2 |
ActionType == "AsrOfficeChildProcessAudited" |
- | 2 | - | - | 2 |
Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,malware was detected" |
- | 1 | - | - | 1 |
ActionType == "LogonSuccess" |
- | 1 | - | - | 1 |
Title contains "Defender AV detected" |
- | 1 | - | - | 1 |
Title == "File droppedlaunched from remote location" |
- | 1 | - | - | 1 |
Title == "Sticky Keys binary hijack detected" |
- | 1 | - | - | 1 |
Title in "File droppedlaunched from remote location,Suspicious transfer of an executable file" |
- | 1 | - | - | 1 |
| Total | 0 | 28 | 0 | 0 | 28 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
BrowserLaunchedToOpenUrl |
- | 2 | - | - | 2 |
AsrOfficeChildProcessAudited |
- | 2 | - | - | 2 |
LogonSuccess |
- | 1 | - | - | 1 |
| Value | Connectors | Content Items | ASIM Parsers | Other Parsers | Total |
|---|---|---|---|---|---|
File backups were deleted |
- | 9 | - | - | 9 |
Event log was cleared |
- | 6 | - | - | 6 |
Suspicious decoded content |
- | 6 | - | - | 6 |
malware was detected |
- | 6 | - | - | 6 |
\ |
- | 5 | - | - | 5 |
An active \ |
- | 3 | - | - | 3 |
Echo command over pipe on localhost |
- | 3 | - | - | 3 |
Known attack framework activity was observed |
- | 3 | - | - | 3 |
Suspicious \ |
- | 3 | - | - | 3 |
Suspicious process launch by Rundll32.exe |
- | 3 | - | - | 3 |
behavior was prevented |
- | 3 | - | - | 3 |
Microsoft Teams chat initiated by a suspicious external user |
- | 2 | - | - | 2 |
contains Email messages containing malicious URL removed after delivery |
- | 2 | - | - | 2 |
contains Potentially malicious |
- | 2 | - | - | 2 |
Suspicious script launched |
- | 2 | - | - | 2 |
Suspected delivery of Gootkit malware |
- | 2 | - | - | 2 |
File dropped |
- | 2 | - | - | 2 |
contains Defender AV detected |
- | 1 | - | - | 1 |
Sticky Keys binary hijack detected |
- | 1 | - | - | 1 |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊