Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a series of failed login attempts to cloud applications reported by Microsoft Defender for Cloud Apps. They need to determine the specific cloud applications involved and identify any unusual login patterns for a particular user over the last 24 hours. Which Advanced Hunting table should the analyst primarily query to gain this insight?
- ADeviceLogonEvents
- BEmailEvents
- CIdentityLogonEvents
- DCloudAppEvents
Show answer & explanationAnswer & explanation
Correct answer: D. CloudAppEvents
The CloudAppEvents table in Advanced Hunting specifically contains information about activities and events occurring within connected cloud applications, including login attempts, failed logins, and other user activities. This table is ideal for investigating cloud application usage and anomalies.
Why the other options are wrong
- A. DeviceLogonEvents focuses on logon activities to devices managed by Defender for Endpoint, not cloud applications.
- B. EmailEvents contains information about email-related activities and is not relevant for investigating cloud application logins.
- C. IdentityLogonEvents provides information about identity-related logon activities across various services, but CloudAppEvents offers more granular detail specifically for cloud application interactions.
Advanced Hunting: CloudAppEvents Table
The CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema contains information about activities performed in cloud applications discovered or connected to Microsoft Defender for Cloud Apps, including user logins, file activities, and administrative actions.
- Primary source for investigating cloud application activity.
- Captures events from connected apps like Office 365, Azure AD, and third-party SaaS apps.
- Includes details like activity type, user, IP address, device, and application.
Memory trick: CloudAppEvents tracks everything happening inside your cloud apps.