Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security operations team is investigating a series of alerts from Microsoft Defender for Identity indicating 'Suspicious NTLM authentication activities' originating from a specific workstation. They need to query raw authentication events to identify all NTLM authentication attempts from that workstation, including successful and failed attempts, within a specific timeframe. Which Advanced Hunting table should the analyst primarily use to find this information?

  1. AIdentityDirectoryEvents
  2. BDeviceNetworkEvents
  3. CIdentityLogonEvents
  4. DDeviceLogonEvents
Show answer & explanation

Correct answer: C. IdentityLogonEvents

The 'IdentityLogonEvents' table in Advanced Hunting is the primary source for identity-related authentication activities, including NTLM authentications. This table captures detailed information about logon attempts, protocols used (like NTLM), source and destination devices, and success/failure status, which is crucial for investigating NTLM-related alerts from Defender for Identity.

Why the other options are wrong

  • A. IdentityDirectoryEvents focuses on Active Directory changes (e.g., user creations, group modifications), not authentication attempts.
  • B. DeviceNetworkEvents captures network connections, but not the authentication protocol details within those connections.
  • D. DeviceLogonEvents focuses on local device logon activities and is less comprehensive for domain-wide identity authentication protocols like NTLM.

Advanced Hunting: IdentityLogonEvents

An Advanced Hunting table in Microsoft Defender XDR that contains detailed information about identity-related logon and authentication activities (e.g., NTLM, Kerberos, interactive logons) across the network, collected by Microsoft Defender for Identity.

  • Crucial for investigating identity-based attacks and suspicious logon activities.
  • Includes details like account name, source/destination device, protocol, and logon type.
  • Aggregates data from domain controllers and other identity sensors.

Memory trick: Identity logon events reveal who tried to log on.

More Mitigate threats using Microsoft Defender XDR questions