Forum Discussion
How to get the Protection History from a device
Hi Deleted,
you could try some queries at Advanced hunting > Queries > Community queries > Protection events, probably Antivirus detections would fit your search.
You can specify the device if you are interested in narrowing down your search with the line:
| where DeviceName contains "PLACEDEVICENAMEHERE"
And also narrow down recent results by specifying days (or hours):
| where Timestamp > ago(1d)
Hope this answers your request.
- AnonymousJan 19, 2023
cyb3rmik3Hi ! Thanks a lot for this, that help me a lot !
Question : Is it a way to add the "Affected Item" & "Detail" of the detection ?
Regards
- cyb3rmik3Jan 20, 2023
Microsoft
Hello Deleted,
I am not quite sure that you can get that information exactly as it is stored locally. However, you may try the following query which brings the title of the alert and the related information about filename and path.
AlertEvidence| where Timestamp > ago(3d) // Define days or hours| where EntityType contains "File"| where DetectionSource contains "Antivirus"| project Title, FolderPath, FileNameI truly hope this will help you in some way.