Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
Cloud audit events for various cloud platforms protected by the organization's Microsoft Defender for Cloud
| Attribute | Value |
|---|---|
| Category | Security, XDR |
| Basic Logs Eligible | ✓ Yes (source) |
| Supports Transformations | ✓ Yes (source) |
| Ingestion API Supported | ✗ No |
| Lake-Only Ingestion | ✓ Yes |
| Azure Monitor Tables Reference | View Documentation |
| Defender XDR Advanced Hunting Schema | View Documentation |
Source: Azure Monitor documentation
| Column Name | Type | Description |
|---|---|---|
| _BilledSize | real | The record size in bytes |
| _IsBillable | string | Specifies whether ingesting the data is billable. When _IsBillable isfalseingestion isn't billed to your Azure account |
| Account | string | The cloud account associated with the audit event. |
| ActionType | string | Type of activity that triggered the event, can be: Unknown, Create, Read, Update, Delete, Other |
| AdditionalFields | dynamic | Additional information about the audit event |
| AuditSource | string | The source of the cloud audit event. |
| AwsResourceName | string | Unique identifier of the AWS resource associated with the audit event. |
| AzureResourceId | string | Unique identifier of the Azure resource associated with the audit event |
| City | string | City where the client IP address is geolocated |
| CountryCode | string | Two-letter code indicating the country where the client IP address is geolocated |
| DataSource | string | Data source for the cloud audit events, can be GCP (for Google Cloud Platform), AWS (for Amazon Web Services), Azure (for Azure Resource Manager), Kubernetes Audit (for Kubernetes), or other cloud platforms |
| GcpFullResourceName | string | Unique identifier of the GCP resource associated with the audit event. |
| IPAddress | string | The client IP address used to access the cloud resource or control plane |
| IsAnonymousProxy | bool | Indicates whether the IP address belongs to a known anonymous proxy (1) or no (0) |
| ISP | string | Internet service provider (ISP) associated with the IP address |
| OperationName | string | Audit event operation name as it appears in the record, usually includes both resource type and operation |
| RawEventData | dynamic | Full raw event information from the data source in JSON format |
| ReportId | string | Unique identifier for the event |
| SourceSystem | string | The type of agent the event was collected by. For example,OpsManagerfor Windows agent, either direct connect or Operations Manager,Linuxfor all Linux agents, orAzurefor Azure Diagnostics |
| TenantId | string | The Log Analytics workspace ID |
| TimeGenerated | datetime | Date and time (UTC) when the record was generated |
| Type | string | The name of the table |
| UserAgent | string | User agent information from the web browser or other client application |
Official Microsoft Learn documentation for field/column information:
This table is used by the following solutions:
In solution Hybrid Attack - Cloud & Identity:
| Hunting Query | Selection Criteria |
|---|---|
| K8s token audit then novel cloud control plane operations | |
| Pod cloud CLI then KeyVault or storage access | |
| Pod token tooling then cloud RBAC write |
In solution Hybrid Attack - Cloud & Identity:
| Workbook | Selection Criteria |
|---|---|
| HybridAttack-Cloud&Identity |
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊