Forum Discussion
Microsoft security threat protection reports - need kql please
- Apr 23, 2021
The [Microsoft 365 Defender (Preview)] connector only takes over Device* tables (and these are optional only if you need that data in Azure Sentinel) or put Alerts into the SecurityAlert table. You may not have enough data to re-create the precise alert even if you had the KQL
So you can use, KQL like:SecurityAlert | where ProductName in("Microsoft Defender Advanced Threat Protection", "Office 365 Advanced Threat Protection", "Azure Advanced Threat Protection", "Microsoft Cloud App Security", "Microsoft 365 Defender") | summarize count(AlertName) by ProductNameor (very basic KQL to read any Device* Table)
union Device* | summarize count() by DeviceName, Type
The [Microsoft 365 Defender (Preview)] connector only takes over Device* tables (and these are optional only if you need that data in Azure Sentinel) or put Alerts into the SecurityAlert table. You may not have enough data to re-create the precise alert even if you had the KQL
So you can use, KQL like:
SecurityAlert
| where ProductName in("Microsoft Defender Advanced Threat Protection", "Office 365 Advanced Threat Protection", "Azure Advanced Threat Protection", "Microsoft Cloud App Security", "Microsoft 365 Defender")
| summarize count(AlertName) by ProductName
or (very basic KQL to read any Device* Table)
union Device* | summarize count() by DeviceName, Type
- snteran385Aug 05, 2021Copper Contributor
I'm not finding the SecurityAlert table under Monitor > Logs, is that table only available for Sentinel? I thought you could use it to find ASC alerts?
Thanks,
Serge
- m_zorichAug 05, 2021Iron ContributorThe SecurityAlert table is just in Sentinel and will show you any alerts for connected MS security products - like Defender ATP, Azure Security Center, Cloud App Security, Identity Protection, Defender for ID and Sentinel alerts themselves.
SecurityAlert
| summarize count()by AlertName, ProviderName
So in the SecurityAlert table you will get alerts from MDE, and you also have the ability to send over any of the Device* tables, however as Clive mentioned that may not be enough to replicate that report. Having a look through my tenant it doesn't appear that the 'Detection source' is sent as part of the alert to the SecurityAlert table.- CliveWatsonAug 06, 2021Former EmployeeUnder Monitor > Logs you have the Alerts table, but as above the Security Alerts are in SecurityAlerts if you have ASC or Azure Sentinel.
- SocInABoxApr 23, 2021Iron ContributorThanks Clive, that's pretty much what we did - just took a couple of hours of playing around with it.