A Microsoft 365 administrator is reviewing security recommendations from Microsoft Defender Vulnerability Management. They notice a recommendation to 'Update web browsers to the latest version' on several devices. The administrator wants to identify all devices that currently have an outdated version of Google Chrome installed. Which KQL query in Advanced Hunting would achieve this?
- ADeviceTvmSoftwareInventory | where SoftwareName == 'Google Chrome' | summarize arg_max(SoftwareVersion, *) by DeviceId | where IsUpToDate == false | project DeviceName, SoftwareVersion
- BDeviceTvmSoftwareInventory | where SoftwareName == 'Google Chrome' and SoftwareVersion < 'current_latest_version' | project DeviceName, SoftwareVersion
- CDeviceTvmSoftwareInventory | where SoftwareName == 'Google Chrome' and not IsUpToDate == true | project DeviceName, SoftwareVersion
- DDeviceTvmSoftwareInventory | where SoftwareName == 'Google Chrome' and Vulnerabilities > 0 | project DeviceName, SoftwareVersion
Show answer & explanationAnswer & explanation
Correct answer: C. DeviceTvmSoftwareInventory | where SoftwareName == 'Google Chrome' and not IsUpToDate == true | project DeviceName, SoftwareVersion
The `DeviceTvmSoftwareInventory` table contains information about installed software and its update status. The `IsUpToDate` column is a boolean indicating if the software is at its latest version according to Defender Vulnerability Management. Filtering for `SoftwareName == 'Google Chrome'` and `not IsUpToDate == true` (or `IsUpToDate == false`) directly identifies devices with outdated Chrome versions. Option B requires knowing the `current_latest_version` which is not dynamic. Option C looks for *any* vulnerability, not specifically outdated status. Option D uses `arg_max` and then `IsUpToDate == false` which is more complex and less direct, as `IsUpToDate` would typically be evaluated per inventory record.
Why the other options are wrong
- A. While `arg_max` could help find the latest *reported* version on a device, the direct `IsUpToDate` column in `DeviceTvmSoftwareInventory` is specifically designed for this purpose and is a much simpler and more accurate check for the recommended action from TVM.
- B. This approach requires the administrator to manually know and update the `current_latest_version` in the query, which is not practical or dynamic, and less reliable than using the built-in `IsUpToDate` flag provided by TVM.
- D. This query would identify devices with Chrome having *any* known vulnerability, which is a broader scope than specifically identifying outdated versions (an outdated version might have vulnerabilities, but an up-to-date one could also have newly discovered vulnerabilities).
DeviceTvmSoftwareInventory KQL Table
The `DeviceTvmSoftwareInventory` KQL table in Microsoft Defender XDR Advanced Hunting provides detailed information about installed software on devices, including its version and update status (`IsUpToDate`).
- Populated by Microsoft Defender Vulnerability Management.
- Lists all installed software and its properties.
- Includes `SoftwareName`, `SoftwareVersion`, `IsUpToDate`.
- Essential for identifying outdated software and managing software inventory.
Memory trick: Remember, for 'Device' 'Software' 'Inventory' and 'Vulnerability Management', use 'DeviceTvmSoftwareInventory' to find 'Outdated' apps.