table

DeviceImageLoadEvents

DeviceImageLoadEvents contains DLL and other image load events reported by Microsoft Defender for Endpoint.

tablesCurrent

Relationships

Schema

FieldTypeDescriptionCopy
TimestampdatetimeDate and time when the event was recorded.
DeviceIdstringUnique identifier for the device in the service.
DeviceNamestringFully qualified domain name of the device.
ActionTypestringType of image load activity that triggered the event.
FileNamestringName of the image file loaded by a process.
FolderPathstringFolder containing the image file loaded by a process.
SHA1stringSHA-1 hash of the loaded image file.
SHA256stringSHA-256 hash of the loaded image file.
InitiatingProcessAccountSidstringSecurity identifier of the account that ran the process responsible for loading the image.