Find entities, APIs, and schema fields.
Search covers display names, entity types, descriptions, relationships, schema fields, and official source URLs.
Microsoft Sentinel
Microsoft Sentinel is a cloud-native SIEM and security operations platform for attack detection, threat visibility, proactive hunting, investigation, and response.
productMicrosoft Defender for Endpoint
Microsoft Defender for Endpoint is an enterprise endpoint security platform used to prevent, detect, investigate, and respond to advanced threats.
productMicrosoft Defender for Office 365
Microsoft Defender for Office 365 provides advanced protection for email and collaboration workloads against phishing, malware, and other email-based threats.
productMicrosoft Defender for Identity
Microsoft Defender for Identity helps detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments.
licenseMicrosoft Defender for Endpoint P1
Microsoft Defender for Endpoint Plan 1 provides foundational endpoint protection capabilities such as next-generation protection, attack surface reduction, and endpoint detection and response with limited manual response actions.
licenseMicrosoft Defender for Endpoint P2
Microsoft Defender for Endpoint Plan 2 provides the full Defender for Endpoint capability set, including advanced hunting over endpoint telemetry.
licenseMicrosoft Defender for Office 365 Plan 1
Microsoft Defender for Office 365 Plan 1 provides advanced email and collaboration protection, including Safe Links, Safe Attachments, anti-phishing policies, preset security policies, real-time detections, and threat submissions.
licenseMicrosoft Defender for Office 365 Plan 2
Microsoft Defender for Office 365 Plan 2 includes Plan 1 protection plus advanced investigation, hunting, automation, simulation, and Microsoft Defender XDR integration capabilities.
capabilityLog Analytics Workspace
Microsoft Sentinel runs on a Log Analytics workspace that stores security data, analytics output, investigation records, and operational telemetry.
capabilityWorkspace Manager
Microsoft Sentinel workspace manager centrally manages analytics rules, automation rules, parsers, saved searches, hunting queries, and workbooks across parent and member Sentinel workspaces for MSSP and enterprise multi-workspace operations.
capabilityData Collection Rules at Scale
Data Collection Rules and Data Collection Endpoints control Azure Monitor data collection, transformation, routing, and association at scale for Sentinel-connected resources and custom logs.
capabilityCross-Workspace KQL and ASIM Strategy
Cross-workspace KQL lets managed security teams query Sentinel and Log Analytics data across customer or regional workspaces, while ASIM parsers normalize source-specific tables into common schemas for portable detections and hunts.
capabilitySentinel Data Lake Architecture
A Sentinel data lake architecture combines Analytics, Basic, Auxiliary, long-term retention, search/export jobs, Log Analytics data export rules, Azure Data Lake Storage Gen2, and Azure Data Explorer for tiered security data retention and analysis.
capabilityData Connectors
Microsoft Sentinel data connectors ingest security data from Microsoft services, Azure resources, clouds, networks, endpoints, and third-party products into the Sentinel workspace.
capabilityAnalytics Rules
Microsoft Sentinel analytics rules detect threats by running scheduled or near-real-time logic against workspace data and creating alerts and incidents.
capabilityIncidents
Microsoft Sentinel incidents group related alerts and entities into investigation records that analysts can triage, assign, classify, and close.
capabilityAutomation Rules
Microsoft Sentinel automation rules triage incidents and alerts by changing incident properties, assigning owners, adding tasks, or launching playbooks.
capabilityWorkbooks
Microsoft Sentinel workbooks provide interactive visualization and monitoring dashboards for security data, incidents, connectors, and operational metrics.
capabilityWatchlists
Microsoft Sentinel watchlists store reference data such as high-value assets, allow lists, user groups, or investigation enrichment values for correlation and hunting.
capabilityContent Hub
Microsoft Sentinel content hub provides packaged solutions with data connectors, analytics rules, hunting queries, workbooks, playbooks, and related content.
capabilityThreat Intelligence
Microsoft Sentinel threat intelligence stores, manages, queries, and uses threat indicators and STIX objects from Microsoft feeds, TAXII feeds, TIP integrations, manual analyst additions, and custom upload API ingestion.
capabilityUser and Entity Behavior Analytics
Microsoft Sentinel UEBA identifies threats by building behavioral baselines for users and entities, then surfacing anomalies and contextual insights for investigations.
capabilityData Retention and Tiers
Microsoft Sentinel data management controls interactive retention, long-term retention, data lake options, and data tiering for security operations data.
capabilityAttack Surface Reduction
Attack surface reduction helps reduce exposure by applying rules and controls that block common malware behaviors and risky activity on endpoints.
capabilityEndpoint Detection and Response
Endpoint detection and response helps detect, investigate, and respond to advanced threats on endpoints.
capabilityAutomated Investigation and Response
Automated investigation and response examines alerts, collects evidence, and can take remediation actions to reduce security operations workload.
capabilityAdvanced Hunting
Advanced hunting is a query-based threat hunting capability in Microsoft Defender XDR that uses KQL to inspect raw event data across supported Microsoft security products.
capabilityThreat and Vulnerability Management
Threat and vulnerability management identifies exposed devices, software weaknesses, and security recommendations for reducing endpoint risk.
capabilityDefender for Identity Sensors
Defender for Identity sensors collect signals from domain controllers, AD FS, AD CS, and related identity infrastructure for identity threat detection and investigation.
capabilityIdentity Health Issues
Defender for Identity health issues report sensor and agent problems such as configuration, connectivity, severity, and status across hybrid identity infrastructure.
capabilityIdentity Alerts and Incidents
Defender for Identity contributes identity-based alerts and incident context to Microsoft Defender XDR for attacks such as credential theft, lateral movement, and privilege escalation.
capabilityIdentity Response Actions
Defender for Identity and Microsoft Graph Security support identity investigation and response workflows such as viewing identity accounts and taking actions on compromised users.
capabilitySafe Links
Safe Links in Defender for Office 365 protects users from malicious URLs in email and supported Office applications by checking links at click time.
capabilitySafe Attachments
Safe Attachments opens email attachments in a virtual environment to detect malicious behavior before delivering messages to recipients.
capabilityThreat Submissions
Threat submissions let analysts and automated workflows submit emails, URLs, and files to Microsoft for analysis and remediation workflows.
capabilityExplorer and Real-time Detections
Explorer and Real-time Detections help investigate email and collaboration threats, message delivery, URLs, files, malware, phishing, and post-delivery actions.
capabilityOffice 365 Automated Investigation and Response
Defender for Office 365 automated investigation and response investigates email and collaboration threats and recommends or takes remediation actions.
capabilityAttack Simulation Training
Attack Simulation Training creates and manages phishing simulations to help detect, prioritize, and remediate social engineering risk through targeted user training.
capabilityMDO Advanced Hunting
Defender for Office 365 Plan 2 exposes email and collaboration telemetry in Microsoft Defender XDR advanced hunting for KQL-based investigation across messages, URLs, attachments, campaigns, clicks, and post-delivery actions.
capabilityMicrosoft Defender XDR Integration
Defender for Office 365 Plan 2 integrates email and collaboration protection signals into Microsoft Defender XDR for cross-domain incidents, investigation, hunting, and response.
capabilityPreset Security Policies
Preset security policies provide built-in, Standard, and Strict protection baselines for Defender for Office 365 features such as Safe Links and Safe Attachments.
tableDeviceProcessEvents
DeviceProcessEvents contains process creation and related endpoint process activity available for advanced hunting.
tableDeviceEvents
DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables.
tableDeviceFileEvents
DeviceFileEvents contains file creation, modification, and other file system events reported by Microsoft Defender for Endpoint.
tableDeviceNetworkEvents
DeviceNetworkEvents contains network connections and related endpoint network activity reported by Microsoft Defender for Endpoint.
tableDeviceRegistryEvents
DeviceRegistryEvents contains registry entry creation, modification, and related registry activity reported by Microsoft Defender for Endpoint.
tableDeviceLogonEvents
DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint.
tableDeviceImageLoadEvents
DeviceImageLoadEvents contains DLL and other image load events reported by Microsoft Defender for Endpoint.
tableDeviceInfo
DeviceInfo contains device inventory and state information, including operating system, onboarding, sensor health, and logged-on user details.
tableEmailEvents
EmailEvents contains Microsoft 365 email delivery and blocking events processed by Microsoft Defender for Office 365.
tableEmailUrlInfo
EmailUrlInfo contains information about URLs found in emails and attachments processed by Microsoft Defender for Office 365.
tableEmailAttachmentInfo
EmailAttachmentInfo contains information about attachments on emails processed by Microsoft Defender for Office 365.
tableEmailPostDeliveryEvents
EmailPostDeliveryEvents contains post-delivery actions taken on email messages after Microsoft 365 delivers them to recipient mailboxes.
tableUrlClickEvents
UrlClickEvents contains Safe Links click events from email messages, Teams, and Office 365 apps.
tableCampaignInfo
CampaignInfo contains information about email campaigns identified by Microsoft Defender for Office 365.
tableFileMaliciousContentInfo
FileMaliciousContentInfo contains preview information about files processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams.
tableMessageEvents
MessageEvents contains details about Microsoft Teams messages sent and received within the organization at delivery time.
tableMessageUrlInfo
MessageUrlInfo contains URL metadata for Microsoft Teams messages in the organization.
tableMessagePostDeliveryEvents
MessagePostDeliveryEvents contains security events that occur after Microsoft Teams message delivery.
tableSecurityAlert
SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products.
tableSecurityIncident
SecurityIncident stores Microsoft Sentinel incident state changes and SOC metrics in the Log Analytics workspace.
tableThreatIntelIndicators
ThreatIntelIndicators stores Microsoft Sentinel STIX indicator records for threat intelligence imported through connectors, manual additions, or the upload API.
tableThreatIntelObjects
ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships.
apiMicrosoft Defender for Endpoint APIs
Microsoft Defender for Endpoint APIs expose endpoint alerts, devices, machine actions, indicators, vulnerability management, software inventory, recommendations, scores, remediation tasks, files, users, and advanced query operations.
apiMicrosoft Defender for Endpoint Indicators API
The Microsoft Defender for Endpoint indicators API manages custom indicators of compromise for endpoint enforcement and alerting, including batch import for custom threat intelligence ingestion into Defender for Endpoint.
apiMicrosoft Graph Security API
The Microsoft Graph Security API is the unified Microsoft Graph surface for security alerts, incidents, actions, threat submissions, identity security data, and related security operations workflows across supported Microsoft security providers.
apiLegacy Microsoft Defender XDR APIs
The legacy Microsoft Defender XDR API surface covers Defender XDR incidents and advanced hunting endpoints under api.security.microsoft.com. Microsoft Graph Security API is the forward-looking replacement for advanced hunting integrations, and Microsoft says the older advanced hunting endpoints stop returning data on February 1, 2027.
apiMicrosoft Sentinel REST API
The Microsoft Sentinel REST API manages Sentinel resources such as incidents, analytics rules, data connectors, bookmarks, and entity information.
apiAzure Monitor Logs Ingestion API
The Azure Monitor Logs Ingestion API sends custom JSON log records through a Data Collection Rule stream into a Log Analytics workspace used by Microsoft Sentinel.
apiMicrosoft Sentinel Threat Intelligence Upload API
The Microsoft Sentinel threat intelligence upload API imports custom threat intelligence STIX objects, including indicators, attack patterns, threat actors, identities, and relationships, into a Sentinel workspace without requiring a data connector.