MICROSOFT DEFENDER XDR
Learn the schema.
Hunt with confidence.
Use the module.
Look up Advanced Hunting tables, track schema changes, and find the XDRInternals commands you need—all in one place.
This reference is community-maintained, so its schema may not include everything in your Defender XDR tenant. Change dates show when this site recorded an update, not necessarily when Microsoft released it.
REFERENCE LIBRARY
Find what you need
Everything here is designed to help you explore hunting data and work with XDRInternals.
Schema explorer
Find a table or column, check its type and retention, and see which action types it can contain.
Browse the schema CHANGE HISTORYSchema changes
See what has been added or removed, and narrow the history by table, change, or date.
View all changes HUNT ACROSS TABLESColumn relationships
See which fields connect tables, follow nested JSON values, and start a KQL join.
Explore connections POWERSHELL MODULEXDRInternals
Look up public PowerShell commands, their parameters, and examples from the module’s help.
Browse commandsRECENT ACTIVITY