Microsoft 365 Certified: Administrator ExpertImplement and manage Microsoft Defender XDRMedium

A security analyst is investigating an incident where a user's machine was compromised. The analyst needs to quickly gather detailed information about network connections established by a malicious process, including remote IP addresses and ports, to understand the extent of the breach. Which table in Advanced Hunting in Microsoft Defender XDR should the analyst query to retrieve this information?

  1. ADeviceRegistryEvents
  2. BDeviceProcessEvents
  3. CDeviceNetworkEvents
  4. DDeviceFileEvents
Show answer & explanation

Correct answer: C. DeviceNetworkEvents

The DeviceNetworkEvents table contains information about network connections made by devices, including details like remote IP addresses, ports, and protocols, which is crucial for understanding network activity of a malicious process.

Why the other options are wrong

  • A. DeviceRegistryEvents logs changes to the system registry, which is not relevant for network connection details.
  • B. DeviceProcessEvents records process creation, termination, and modifications, but not network connection details.
  • D. DeviceFileEvents tracks file-related activities like creation, modification, and deletion, not network connections.

Advanced Hunting Tables: DeviceNetworkEvents

The DeviceNetworkEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about network connections and related events on devices.

  • Records outbound and inbound network connections.
  • Includes details like LocalIP, RemoteIP, LocalPort, RemotePort, Protocol.
  • Useful for investigating command and control (C2) communication, data exfiltration, and lateral movement.

Memory trick: Network events are for NETWORK DETAILS, not processes or files.

More Implement and manage Microsoft Defender XDR questions