Global Search

Find entities, APIs, and schema fields.

Search covers display names, entity types, descriptions, relationships, schema fields, and official source URLs.

product

Microsoft Sentinel

Microsoft Sentinel is a cloud-native SIEM and security operations platform for attack detection, threat visibility, proactive hunting, investigation, and response.

product

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint is an enterprise endpoint security platform used to prevent, detect, investigate, and respond to advanced threats.

product

Microsoft Defender for Office 365

Microsoft Defender for Office 365 provides advanced protection for email and collaboration workloads against phishing, malware, and other email-based threats.

product

Microsoft Defender for Identity

Microsoft Defender for Identity helps detect, investigate, and respond to identity-based attacks across on-premises, cloud, and hybrid environments.

license

Microsoft Defender for Endpoint P1

Microsoft Defender for Endpoint Plan 1 provides foundational endpoint protection capabilities such as next-generation protection, attack surface reduction, and endpoint detection and response with limited manual response actions.

license

Microsoft Defender for Endpoint P2

Microsoft Defender for Endpoint Plan 2 provides the full Defender for Endpoint capability set, including advanced hunting over endpoint telemetry.

license

Microsoft Defender for Office 365 Plan 1

Microsoft Defender for Office 365 Plan 1 provides advanced email and collaboration protection, including Safe Links, Safe Attachments, anti-phishing policies, preset security policies, real-time detections, and threat submissions.

license

Microsoft Defender for Office 365 Plan 2

Microsoft Defender for Office 365 Plan 2 includes Plan 1 protection plus advanced investigation, hunting, automation, simulation, and Microsoft Defender XDR integration capabilities.

capability

Log Analytics Workspace

Microsoft Sentinel runs on a Log Analytics workspace that stores security data, analytics output, investigation records, and operational telemetry.

capability

Workspace Manager

Microsoft Sentinel workspace manager centrally manages analytics rules, automation rules, parsers, saved searches, hunting queries, and workbooks across parent and member Sentinel workspaces for MSSP and enterprise multi-workspace operations.

capability

Data Collection Rules at Scale

Data Collection Rules and Data Collection Endpoints control Azure Monitor data collection, transformation, routing, and association at scale for Sentinel-connected resources and custom logs.

capability

Cross-Workspace KQL and ASIM Strategy

Cross-workspace KQL lets managed security teams query Sentinel and Log Analytics data across customer or regional workspaces, while ASIM parsers normalize source-specific tables into common schemas for portable detections and hunts.

capability

Sentinel Data Lake Architecture

A Sentinel data lake architecture combines Analytics, Basic, Auxiliary, long-term retention, search/export jobs, Log Analytics data export rules, Azure Data Lake Storage Gen2, and Azure Data Explorer for tiered security data retention and analysis.

capability

Data Connectors

Microsoft Sentinel data connectors ingest security data from Microsoft services, Azure resources, clouds, networks, endpoints, and third-party products into the Sentinel workspace.

capability

Analytics Rules

Microsoft Sentinel analytics rules detect threats by running scheduled or near-real-time logic against workspace data and creating alerts and incidents.

capability

Incidents

Microsoft Sentinel incidents group related alerts and entities into investigation records that analysts can triage, assign, classify, and close.

capability

Automation Rules

Microsoft Sentinel automation rules triage incidents and alerts by changing incident properties, assigning owners, adding tasks, or launching playbooks.

capability

Workbooks

Microsoft Sentinel workbooks provide interactive visualization and monitoring dashboards for security data, incidents, connectors, and operational metrics.

capability

Watchlists

Microsoft Sentinel watchlists store reference data such as high-value assets, allow lists, user groups, or investigation enrichment values for correlation and hunting.

capability

Content Hub

Microsoft Sentinel content hub provides packaged solutions with data connectors, analytics rules, hunting queries, workbooks, playbooks, and related content.

capability

Threat Intelligence

Microsoft Sentinel threat intelligence stores, manages, queries, and uses threat indicators and STIX objects from Microsoft feeds, TAXII feeds, TIP integrations, manual analyst additions, and custom upload API ingestion.

capability

User and Entity Behavior Analytics

Microsoft Sentinel UEBA identifies threats by building behavioral baselines for users and entities, then surfacing anomalies and contextual insights for investigations.

capability

Data Retention and Tiers

Microsoft Sentinel data management controls interactive retention, long-term retention, data lake options, and data tiering for security operations data.

capability

Attack Surface Reduction

Attack surface reduction helps reduce exposure by applying rules and controls that block common malware behaviors and risky activity on endpoints.

capability

Endpoint Detection and Response

Endpoint detection and response helps detect, investigate, and respond to advanced threats on endpoints.

capability

Automated Investigation and Response

Automated investigation and response examines alerts, collects evidence, and can take remediation actions to reduce security operations workload.

capability

Advanced Hunting

Advanced hunting is a query-based threat hunting capability in Microsoft Defender XDR that uses KQL to inspect raw event data across supported Microsoft security products.

capability

Threat and Vulnerability Management

Threat and vulnerability management identifies exposed devices, software weaknesses, and security recommendations for reducing endpoint risk.

capability

Defender for Identity Sensors

Defender for Identity sensors collect signals from domain controllers, AD FS, AD CS, and related identity infrastructure for identity threat detection and investigation.

capability

Identity Health Issues

Defender for Identity health issues report sensor and agent problems such as configuration, connectivity, severity, and status across hybrid identity infrastructure.

capability

Identity Alerts and Incidents

Defender for Identity contributes identity-based alerts and incident context to Microsoft Defender XDR for attacks such as credential theft, lateral movement, and privilege escalation.

capability

Identity Response Actions

Defender for Identity and Microsoft Graph Security support identity investigation and response workflows such as viewing identity accounts and taking actions on compromised users.

capability

Safe Links

Safe Links in Defender for Office 365 protects users from malicious URLs in email and supported Office applications by checking links at click time.

capability

Safe Attachments

Safe Attachments opens email attachments in a virtual environment to detect malicious behavior before delivering messages to recipients.

capability

Threat Submissions

Threat submissions let analysts and automated workflows submit emails, URLs, and files to Microsoft for analysis and remediation workflows.

capability

Explorer and Real-time Detections

Explorer and Real-time Detections help investigate email and collaboration threats, message delivery, URLs, files, malware, phishing, and post-delivery actions.

capability

Office 365 Automated Investigation and Response

Defender for Office 365 automated investigation and response investigates email and collaboration threats and recommends or takes remediation actions.

capability

Attack Simulation Training

Attack Simulation Training creates and manages phishing simulations to help detect, prioritize, and remediate social engineering risk through targeted user training.

capability

MDO Advanced Hunting

Defender for Office 365 Plan 2 exposes email and collaboration telemetry in Microsoft Defender XDR advanced hunting for KQL-based investigation across messages, URLs, attachments, campaigns, clicks, and post-delivery actions.

capability

Microsoft Defender XDR Integration

Defender for Office 365 Plan 2 integrates email and collaboration protection signals into Microsoft Defender XDR for cross-domain incidents, investigation, hunting, and response.

capability

Preset Security Policies

Preset security policies provide built-in, Standard, and Strict protection baselines for Defender for Office 365 features such as Safe Links and Safe Attachments.

table

DeviceProcessEvents

DeviceProcessEvents contains process creation and related endpoint process activity available for advanced hunting.

table

DeviceEvents

DeviceEvents contains multiple event types reported by devices, including security control and endpoint activity events that are not represented in more specific advanced hunting tables.

table

DeviceFileEvents

DeviceFileEvents contains file creation, modification, and other file system events reported by Microsoft Defender for Endpoint.

table

DeviceNetworkEvents

DeviceNetworkEvents contains network connections and related endpoint network activity reported by Microsoft Defender for Endpoint.

table

DeviceRegistryEvents

DeviceRegistryEvents contains registry entry creation, modification, and related registry activity reported by Microsoft Defender for Endpoint.

table

DeviceLogonEvents

DeviceLogonEvents contains sign-in and authentication events on devices reported by Microsoft Defender for Endpoint.

table

DeviceImageLoadEvents

DeviceImageLoadEvents contains DLL and other image load events reported by Microsoft Defender for Endpoint.

table

DeviceInfo

DeviceInfo contains device inventory and state information, including operating system, onboarding, sensor health, and logged-on user details.

table

EmailEvents

EmailEvents contains Microsoft 365 email delivery and blocking events processed by Microsoft Defender for Office 365.

table

EmailUrlInfo

EmailUrlInfo contains information about URLs found in emails and attachments processed by Microsoft Defender for Office 365.

table

EmailAttachmentInfo

EmailAttachmentInfo contains information about attachments on emails processed by Microsoft Defender for Office 365.

table

EmailPostDeliveryEvents

EmailPostDeliveryEvents contains post-delivery actions taken on email messages after Microsoft 365 delivers them to recipient mailboxes.

table

UrlClickEvents

UrlClickEvents contains Safe Links click events from email messages, Teams, and Office 365 apps.

table

CampaignInfo

CampaignInfo contains information about email campaigns identified by Microsoft Defender for Office 365.

table

FileMaliciousContentInfo

FileMaliciousContentInfo contains preview information about files processed by Microsoft Defender for Office 365 in SharePoint Online, OneDrive, and Microsoft Teams.

table

MessageEvents

MessageEvents contains details about Microsoft Teams messages sent and received within the organization at delivery time.

table

MessageUrlInfo

MessageUrlInfo contains URL metadata for Microsoft Teams messages in the organization.

table

MessagePostDeliveryEvents

MessagePostDeliveryEvents contains security events that occur after Microsoft Teams message delivery.

table

SecurityAlert

SecurityAlert stores alerts generated by Microsoft Sentinel analytics rules and alerts ingested from connected Microsoft security products.

table

SecurityIncident

SecurityIncident stores Microsoft Sentinel incident state changes and SOC metrics in the Log Analytics workspace.

table

ThreatIntelIndicators

ThreatIntelIndicators stores Microsoft Sentinel STIX indicator records for threat intelligence imported through connectors, manual additions, or the upload API.

table

ThreatIntelObjects

ThreatIntelObjects stores generic STIX objects imported into Microsoft Sentinel threat intelligence, such as attack patterns, threat actors, identities, and relationships.

api

Microsoft Defender for Endpoint APIs

Microsoft Defender for Endpoint APIs expose endpoint alerts, devices, machine actions, indicators, vulnerability management, software inventory, recommendations, scores, remediation tasks, files, users, and advanced query operations.

api

Microsoft Defender for Endpoint Indicators API

The Microsoft Defender for Endpoint indicators API manages custom indicators of compromise for endpoint enforcement and alerting, including batch import for custom threat intelligence ingestion into Defender for Endpoint.

api

Microsoft Graph Security API

The Microsoft Graph Security API is the unified Microsoft Graph surface for security alerts, incidents, actions, threat submissions, identity security data, and related security operations workflows across supported Microsoft security providers.

api

Legacy Microsoft Defender XDR APIs

The legacy Microsoft Defender XDR API surface covers Defender XDR incidents and advanced hunting endpoints under api.security.microsoft.com. Microsoft Graph Security API is the forward-looking replacement for advanced hunting integrations, and Microsoft says the older advanced hunting endpoints stop returning data on February 1, 2027.

api

Microsoft Sentinel REST API

The Microsoft Sentinel REST API manages Sentinel resources such as incidents, analytics rules, data connectors, bookmarks, and entity information.

api

Azure Monitor Logs Ingestion API

The Azure Monitor Logs Ingestion API sends custom JSON log records through a Data Collection Rule stream into a Log Analytics workspace used by Microsoft Sentinel.

api

Microsoft Sentinel Threat Intelligence Upload API

The Microsoft Sentinel threat intelligence upload API imports custom threat intelligence STIX objects, including indicators, attack patterns, threat actors, identities, and relationships, into a Sentinel workspace without requiring a data connector.