WorkStation Device uptime

Occasional Contributor

Hi Guys,

 

Has anyone created a query to show the uptime or last restart on workstations? For Cloud Resources you have UpdateSummary, but looking for all endpoint devices.

 

Cant seem to see anything to pull this info.

1 Reply
If you have MDE and the DeviceInfo table in Sentinel? See https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries/blob/d6da8647e41b6862278f50d7227... you could modify this - note Timestamp may need changing to TimeGenerated.