Browse

tables

Browse every table record currently available in the local reference.

TableSourceLicenseAPIFieldsAvailability
DeviceProcessEvents

DeviceProcessEvents contains process creation and related endpoint process activity available for advanced hunting.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs7Defender XDR
DeviceEvents

DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs6Defender XDR
DeviceFileEvents

DeviceFileEvents contains file creation, modification, and other file system events reported by Microsoft Defender for Endpoint.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs10Defender XDRSentinel
DeviceNetworkEvents

DeviceNetworkEvents contains network connections and related endpoint network activity reported by Microsoft Defender for Endpoint.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs10Defender XDRSentinel
DeviceRegistryEvents

DeviceRegistryEvents contains registry entry creation, modification, and related registry activity reported by Microsoft Defender for Endpoint.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs9Defender XDRSentinel
DeviceLogonEvents

DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs10Defender XDRSentinel
DeviceImageLoadEvents

DeviceImageLoadEvents contains DLL and other image load events reported by Microsoft Defender for Endpoint.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs9Defender XDRSentinel
DeviceInfo

DeviceInfo contains device inventory and state information, including operating system, onboarding, sensor health, and logged-on user details.

Microsoft Defender for EndpointMicrosoft Defender for Endpoint P2Microsoft Graph Security API, Microsoft Defender for Endpoint APIs, Legacy Microsoft Defender XDR APIs10Defender XDRSentinel
EmailEvents

EmailEvents contains Microsoft 365 email delivery and blocking events processed by Microsoft Defender for Office 365.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs49Defender XDR
EmailUrlInfo

EmailUrlInfo contains information about URLs found in emails and attachments processed by Microsoft Defender for Office 365.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs8Defender XDR
EmailAttachmentInfo

EmailAttachmentInfo contains information about attachments on emails processed by Microsoft Defender for Office 365.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs17Defender XDR
EmailPostDeliveryEvents

EmailPostDeliveryEvents contains post-delivery actions taken on email messages after Microsoft 365 delivers them to recipient mailboxes.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs15Defender XDR
UrlClickEvents

UrlClickEvents contains Safe Links click events from email messages, Teams, and Office 365 apps.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs19Defender XDR
CampaignInfo

CampaignInfo contains information about email campaigns identified by Microsoft Defender for Office 365.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs8Defender XDR
FileMaliciousContentInfo

FileMaliciousContentInfo contains preview information about files processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs16Defender XDR
MessageEvents

MessageEvents contains details about Microsoft Teams messages sent and received within the organization at delivery time.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs27Defender XDR
MessageUrlInfo

MessageUrlInfo contains URL metadata for Microsoft Teams messages in the organization.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs6Defender XDR
MessagePostDeliveryEvents

MessagePostDeliveryEvents contains security events that occur after Microsoft Teams message delivery.

Microsoft Defender for Office 365Microsoft Graph Security API, Legacy Microsoft Defender XDR APIs15Defender XDR
SecurityAlert

SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products.

Microsoft SentinelMicrosoft Sentinel REST API10No XDRSentinel
SecurityIncident

SecurityIncident stores Microsoft Sentinel incident state changes and SOC metrics in the Log Analytics workspace.

Microsoft SentinelMicrosoft Sentinel REST API10No XDRSentinel
ThreatIntelIndicators

ThreatIntelIndicators stores Microsoft Sentinel STIX indicator records for threat intelligence imported through connectors, manual additions, or the upload API.

Microsoft SentinelMicrosoft Sentinel Threat Intelligence Upload API, Microsoft Sentinel REST API26Defender XDRSentinel
ThreatIntelObjects

ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships.

Microsoft SentinelMicrosoft Sentinel Threat Intelligence Upload API, Microsoft Sentinel REST API16Defender XDRSentinel