tables
Browse every table record currently available in the local reference.
| Table | Source | License | API | Fields | Availability |
|---|---|---|---|---|---|
| DeviceProcessEvents DeviceProcessEvents contains process creation and related endpoint process activity available for advanced hunting. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 7 | Defender XDR |
| DeviceEvents DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 6 | Defender XDR |
| DeviceFileEvents DeviceFileEvents contains file creation, modification, and other file system events reported by Microsoft Defender for Endpoint. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 10 | Defender XDRSentinel |
| DeviceNetworkEvents DeviceNetworkEvents contains network connections and related endpoint network activity reported by Microsoft Defender for Endpoint. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 10 | Defender XDRSentinel |
| DeviceRegistryEvents DeviceRegistryEvents contains registry entry creation, modification, and related registry activity reported by Microsoft Defender for Endpoint. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 9 | Defender XDRSentinel |
| DeviceLogonEvents DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 10 | Defender XDRSentinel |
| DeviceImageLoadEvents DeviceImageLoadEvents contains DLL and other image load events reported by Microsoft Defender for Endpoint. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 9 | Defender XDRSentinel |
| DeviceInfo DeviceInfo contains device inventory and state information, including operating system, onboarding, sensor health, and logged-on user details. | Microsoft Defender for Endpoint | Microsoft Defender for Endpoint P2 | Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs | 10 | Defender XDRSentinel |
| EmailEvents EmailEvents contains Microsoft 365 email delivery and blocking events processed by Microsoft Defender for Office 365. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 49 | Defender XDR | |
| EmailUrlInfo EmailUrlInfo contains information about URLs found in emails and attachments processed by Microsoft Defender for Office 365. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 8 | Defender XDR | |
| EmailAttachmentInfo EmailAttachmentInfo contains information about attachments on emails processed by Microsoft Defender for Office 365. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 17 | Defender XDR | |
| EmailPostDeliveryEvents EmailPostDeliveryEvents contains post-delivery actions taken on email messages after Microsoft 365 delivers them to recipient mailboxes. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 15 | Defender XDR | |
| UrlClickEvents UrlClickEvents contains Safe Links click events from email messages, Teams, and Office 365 apps. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 19 | Defender XDR | |
| CampaignInfo CampaignInfo contains information about email campaigns identified by Microsoft Defender for Office 365. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 8 | Defender XDR | |
| FileMaliciousContentInfo FileMaliciousContentInfo contains preview information about files processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 16 | Defender XDR | |
| MessageEvents MessageEvents contains details about Microsoft Teams messages sent and received within the organization at delivery time. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 27 | Defender XDR | |
| MessageUrlInfo MessageUrlInfo contains URL metadata for Microsoft Teams messages in the organization. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 6 | Defender XDR | |
| MessagePostDeliveryEvents MessagePostDeliveryEvents contains security events that occur after Microsoft Teams message delivery. | Microsoft Defender for Office 365 | Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs | 15 | Defender XDR | |
| SecurityAlert SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products. | Microsoft Sentinel | Microsoft Sentinel REST API | 10 | No XDRSentinel | |
| SecurityIncident SecurityIncident stores Microsoft Sentinel incident state changes and SOC metrics in the Log Analytics workspace. | Microsoft Sentinel | Microsoft Sentinel REST API | 10 | No XDRSentinel | |
| ThreatIntelIndicators ThreatIntelIndicators stores Microsoft Sentinel STIX indicator records for threat intelligence imported through connectors, manual additions, or the upload API. | Microsoft Sentinel | Microsoft Sentinel Threat Intelligence Upload API, Microsoft Sentinel REST API | 26 | Defender XDRSentinel | |
| ThreatIntelObjects ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships. | Microsoft Sentinel | Microsoft Sentinel Threat Intelligence Upload API, Microsoft Sentinel REST API | 16 | Defender XDRSentinel |