AlertInfo

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index


Alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity, including severity information and threat categorization

Attribute Value
Category Internal
Basic Logs Eligible ✓ Yes (source)
Supports Transformations ✓ Yes (source)
Ingestion API Supported ✗ No
Lake-Only Ingestion ✓ Yes
Azure Monitor Tables Reference View Documentation
Defender XDR Advanced Hunting Schema View Documentation

Contents

Schema (13 columns)

Source: Azure Monitor documentation

Column Name Type Description
_BilledSize real The record size in bytes
_IsBillable string Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account
AlertId string Unique identifier for the alert.
AttackTechniques string MITRE ATT&CK techniques associated with the activity that triggered the alert.
Category string Type of threat indicator or breach activity identified by the alert.
DetectionSource string Detection technology or sensor that identified the notable component or activity.
ServiceSource string Product or service that provided the alert information.
Severity string Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert.
SourceSystem string The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics
TenantId string The Log Analytics workspace ID
TimeGenerated datetime Date and time (UTC) when the record was generated.
Title string Title of the alert.
Type string The name of the table

Schema References

Official Microsoft Learn documentation for field/column information:

Solutions (1)

This table is used by the following solutions:


Content Items Using This Table (35)

Analytic Rules (1)

In solution Microsoft Defender XDR: Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected"

Analytic Rule
Potential Ransomware activity related to Cobalt Strike

Hunting Queries (32)

In solution Microsoft Defender XDR:

Hunting Query Selection Criteria
Alerts Related to Log4j Vulnerability Title == "Suspicious script launched"
Devices with Log4j vulnerability alerts and additional other alert related context
Microsoft Teams chat initiated by a suspicious external user Title == "Microsoft Teams chat initiated by a suspicious external user"
Potential Ransomware activity related to Cobalt Strike Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected"

GitHub Only:

Hunting Query Selection Criteria
Alerts related to Log4j vulnerability Title == "Suspicious script launched"
Antivirus detections (1) Title contains "Defender AV detected"
Baseline Comparison
Cobalt Strike Lateral Movement Title in "File dropped
launched from remote location,Suspicious transfer of an executable file"
Devices with Log4j vulnerability alerts and additional other alert related context
Distribution from remote location Title == "File dropped
launched from remote location"
Events surrounding alert (1)
Events surrounding alert (3)
ExploitGuardBlockOfficeChildProcess (1) ActionType == "AsrOfficeChildProcessAudited"
ExploitGuardBlockOfficeChildProcess (3) ActionType == "AsrOfficeChildProcessAudited"
File Backup Deletion Alerts Title == "File backups were deleted"
Gootkit File Delivery Title == "Suspected delivery of Gootkit malware"
Gootkit-malware Title == "Suspected delivery of Gootkit malware"
ImpersonatedUserFootprint ActionType == "LogonSuccess"
Microsoft Teams chat initiated by a suspicious external user Title == "Microsoft Teams chat initiated by a suspicious external user"
Open email link ActionType == "BrowserLaunchedToOpenUrl"
Potential ransomware activity related to Cobalt Strike Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected"
Ransomware hits healthcare - Backup deletion Title == "File backups were deleted"
Ransomware hits healthcare - Possible compromised accounts Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,malware was detected"
Sticky Keys Title == "Sticky Keys binary hijack detected"
SuspiciousUrlClicked ActionType == "BrowserLaunchedToOpenUrl"
URL click on ZAP email Title contains "Email messages containing malicious URL removed after delivery"
URL click on ZAP email Title contains "Email messages containing malicious URL removed after delivery"
URLClick details based on malicious URL click alert Title contains "Potentially malicious"
URLClick details based on malicious URL click alert Title contains "Potentially malicious"
backup-deletion Title == "File backups were deleted"
cobalt-strike Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected"
identify-accounts-logged-on-to-endpoints-affected-by-cobalt-strike Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected"

Workbooks (2)

GitHub Only: ActionType in "Add member to role,Add user,InteractiveLogon,LogonSuccess,RemoteInteractiveLogon,Reset user password,ResourceAccess,Sign-in,Update user"

Workbook
DoDZeroTrustWorkbook
ZeroTrustStrategyWorkbook

Selection Criteria Summary (16 criteria, 28 total references)

References by type: 0 connectors, 28 content items, 0 ASIM parsers, 0 other parsers.

Selection Criteria Connectors Content Items ASIM Parsers Other Parsers Total
Title in "An active \,Echo command over pipe on localhost,Event log was cleared,File backups were deleted,Known attack framework activity was observed,Suspicious \,Suspicious decoded content,Suspicious process launch by Rundll32.exe,\,behavior was prevented,malware was detected" - 3 - - 3
Title == "File backups were deleted" - 3 - - 3
Title == "Microsoft Teams chat initiated by a suspicious external user" - 2 - - 2
Title contains "Email messages containing malicious URL removed after delivery" - 2 - - 2
Title contains "Potentially malicious" - 2 - - 2
Title == "Suspicious script launched" - 2 - - 2
Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,\,malware was detected" - 2 - - 2
Title == "Suspected delivery of Gootkit malware" - 2 - - 2
ActionType == "BrowserLaunchedToOpenUrl" - 2 - - 2
ActionType == "AsrOfficeChildProcessAudited" - 2 - - 2
Title in "Event log was cleared,File backups were deleted,Suspicious decoded content,malware was detected" - 1 - - 1
ActionType == "LogonSuccess" - 1 - - 1
Title contains "Defender AV detected" - 1 - - 1
Title == "File dropped
launched from remote location"
- 1 - - 1
Title == "Sticky Keys binary hijack detected" - 1 - - 1
Title in "File dropped
launched from remote location,Suspicious transfer of an executable file"
- 1 - - 1
Total 0 28 0 0 28

ActionType

Value Connectors Content Items ASIM Parsers Other Parsers Total
BrowserLaunchedToOpenUrl - 2 - - 2
AsrOfficeChildProcessAudited - 2 - - 2
LogonSuccess - 1 - - 1

Title

Value Connectors Content Items ASIM Parsers Other Parsers Total
File backups were deleted - 9 - - 9
Event log was cleared - 6 - - 6
Suspicious decoded content - 6 - - 6
malware was detected - 6 - - 6
\ - 5 - - 5
An active \ - 3 - - 3
Echo command over pipe on localhost - 3 - - 3
Known attack framework activity was observed - 3 - - 3
Suspicious \ - 3 - - 3
Suspicious process launch by Rundll32.exe - 3 - - 3
behavior was prevented - 3 - - 3
Microsoft Teams chat initiated by a suspicious external user - 2 - - 2
contains Email messages containing malicious URL removed after delivery - 2 - - 2
contains Potentially malicious - 2 - - 2
Suspicious script launched - 2 - - 2
Suspected delivery of Gootkit malware - 2 - - 2
File dropped - 2 - - 2
contains Defender AV detected - 1 - - 1
Sticky Keys binary hijack detected - 1 - - 1

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

↑ Back to Tables Index