Forum Discussion

JMSHW0420's avatar
JMSHW0420
Iron Contributor
Feb 10, 2023

RE: Tracking Security Incidents linked to an Intune device

Hello,

 

I already have a similar request asking about this but wanted to change the scoping of the query being asked.

 

Is it possible with KQL to 'track' ANY Security Incidents (primarily generated from an Analytics Rule) that are associated or linked to an 'Intune' Device?

 

I know the 'SecurityIncident' table can locate the 'Incidents' but which table(s) can I perform a JOIN on to find those Incidents associated with an 'Intune' Device?

Resources