MITRE ATT&CK techniques associated with the activity that triggered the alert
String
Category
Type of threat indicator or breach activity identified by the alert
String
DeviceId
Unique identifier for the device in Microsoft Defender for Endpoint
String
DeviceName
Fully qualified domain name (FQDN) of the device
String
FileName
Name of the file that the recorded action was applied to
String
MachineGroup
String
RemoteIP
IP address that was being connected to
String
RemoteUrl
URL or fully qualified domain name (FQDN) that was being connected to
String
ReportId
Event identifier based on a repeating counter.To identify unique events, this column must be used in conjunction with the DeviceName and Timestamp columns.
Int64
Severity
Indicates the potential impact (high, medium, or low) of the threat indicator or breach activity identified by the alert
String
SHA1
SHA-1 hash of the file that the recorded action was applied to
String
SourceSystem
String
Table
Indicates the table in which the event’s data is located