Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security operations team is investigating a series of alerts from Microsoft Defender for Identity indicating 'Suspicious NTLM authentication activities' originating from a specific workstation. They need to query raw authentication events to identify all NTLM authentication attempts from that workstation, including successful and failed attempts, within a specific timeframe. Which Advanced Hunting table should the analyst primarily use to find this information?
- AIdentityDirectoryEvents
- BDeviceNetworkEvents
- CIdentityLogonEvents
- DDeviceLogonEvents
Show answer & explanationAnswer & explanation
Correct answer: C. IdentityLogonEvents
The 'IdentityLogonEvents' table in Advanced Hunting is the primary source for identity-related authentication activities, including NTLM authentications. This table captures detailed information about logon attempts, protocols used (like NTLM), source and destination devices, and success/failure status, which is crucial for investigating NTLM-related alerts from Defender for Identity.
Why the other options are wrong
- A. IdentityDirectoryEvents focuses on Active Directory changes (e.g., user creations, group modifications), not authentication attempts.
- B. DeviceNetworkEvents captures network connections, but not the authentication protocol details within those connections.
- D. DeviceLogonEvents focuses on local device logon activities and is less comprehensive for domain-wide identity authentication protocols like NTLM.
Advanced Hunting: IdentityLogonEvents
An Advanced Hunting table in Microsoft Defender XDR that contains detailed information about identity-related logon and authentication activities (e.g., NTLM, Kerberos, interactive logons) across the network, collected by Microsoft Defender for Identity.
- Crucial for investigating identity-based attacks and suspicious logon activities.
- Includes details like account name, source/destination device, protocol, and logon type.
- Aggregates data from domain controllers and other identity sensors.
Memory trick: Identity logon events reveal who tried to log on.