DeviceTvmInfoGathering

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index


Defender XDR Only: This table is available in Microsoft Defender XDR advanced hunting but is not available in the Azure Monitor Log Analytics table reference.

Defender Vulnerability Management assessment events including configuration and attack surface area states

Attribute Value
Category MDE
Ingestion API Supported ✗ No
Defender XDR Advanced Hunting Schema View Documentation

Schema (6 columns)

Source: Azure Monitor documentation

Column Name Type Description
AdditionalFields dynamic Additional information about the entity or event
DeviceId string Unique identifier for the device in the service
DeviceName string Fully qualified domain name (FQDN) of the device
LastSeenTime datetime Date and time when the service last saw the device
OSPlatform string Platform of the operating system running on the device. This indicates specific operating systems, including variations within the same family, such as Windows 10 and Windows 7.
Timestamp datetime Date and time when the record was generated

Content Items Using This Table (5)

Hunting Queries (5)

GitHub Only:

Hunting Query Selection Criteria
Microsoft Defender AV Engine up to date info
Microsoft Defender AV Platform up to date information
Microsoft Defender AV Security Intelligence up to date information
Microsoft Defender AV details
Microsoft Defender AV mode device count

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Tables Index