| AccountEmail |
Email address of the account |
String |
| AccountUpn |
User principal name (UPN) of the account |
String |
| ActionCategory |
Category of action that triggered the event |
String |
| ActionType |
Type of activity that triggered the event |
String |
| ActivityCount |
Total user activity events recorded under this behavior |
Int32 |
| Application |
Application that performed the recorded action |
String |
| AttackTechniques |
MITRE ATT&CK techniques associated with the activity that triggered the alert |
String |
| BehaviorId |
Unique identifier for the behavior |
String |
| Categories |
List of categories that the information belongs to, in JSON array format |
String |
| Description |
Description of the information gathered |
String |
| DetectionSource |
Detection technology or sensor that identified the notable component or activity |
String |
| DeviceInfo |
List of device information for the device involved in this behavior, including device ID, device name, and the number of events in which the device is involved |
Object |
| EndTime |
Date and time of the last activity related to the behavior |
DateTime |
| IsAnomalous |
Indicates if this user behavior is anomalous by itself or based on insider risk management global settings |
Boolean |
| IsContentHidden |
Indicates if the behavior involves hidden content on a device |
Boolean |
| IsUnderIrmPolicy |
Indicates if this behavior is detected based on a Microsoft Purview Insider Risk Management policy |
Boolean |
| PolicyMatchInfo |
List of insider risk management policy matches with this behavior, including the unique identifier and the name of the policy configured in Microsoft Insider Risk Management, the number of events in this behavior that matches priority content defined in the insider risk management policy, and the risk score assigned to this behavior by specific policies |
Object |
| PrinterName |
List of printers involved in the behavior |
String |
| RecipientEmailInfo |
List of information about the recipient involved in the behavior, including the email address of the recipient and the number of events in the behavior involving the recipient |
Object |
| RemovableMediaInfo |
List of any removable media involved in the behavior, including the serial number of the removable media deivce, the manufacturer of the removable media device, and the model of the removable device |
Object |
| SensitiveInfoTypesInfo |
List of sensitive info types detected in the content involved in this behavior, including the unique identifier for the sensitive info type, the name of the sensitive info type, and the number of events in the behavior involving this sensitive info type |
Object |
| SensitivityLabelInfo |
List of sensitivity labels assigned to content involed in this behavior, including the unique identifier for the Microsoft Information Protection sensitivity label assigned to the related content, the name of the sensitivity label, and the number of events in the behavior involving this label |
Object |
| ServiceSource |
Product or service that provided the alert information |
String |
| SharepointSiteInfo |
List of SharePoint sites involved in this behavior, including the unique identifier for the SharePoint site, the name of the SharePoint site, and the number of events in the behavior involving the SharePoint site |
Object |
| SourceSystem |
|
String |
| StartTime |
Date and time of the first activity related to the behavior |
DateTime |
| TenantId |
|
String |
| TimeGenerated |
|
DateTime |
| Timestamp |
Date and time when the record was generated |
DateTime |
| Type |
|
String |
| UrlDomainInfo |
Details about the websites or service URLs involved in the event |
Object |