Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDREasy
A security analyst needs to create a custom detection rule in Microsoft Defender XDR that triggers an alert when a specific PowerShell command containing a base64 encoded string is executed on any endpoint. The rule should identify the command line, the user, and the device involved. Which Advanced Hunting table is most appropriate for querying process execution events to extract this information?
- AIdentityLogonEvents
- BDeviceFileEvents
- CDeviceNetworkEvents
- DDeviceProcessEvents
Show answer & explanationAnswer & explanation
Correct answer: D. DeviceProcessEvents
The DeviceProcessEvents table in Advanced Hunting contains information about process creation, termination, and command-line arguments, which is precisely what is needed to detect a specific PowerShell command execution.
Why the other options are wrong
- A. IdentityLogonEvents focuses on user authentication activities, not process execution.
- B. DeviceFileEvents tracks file system activities like creation, modification, or deletion, not process execution details.
- C. DeviceNetworkEvents is for network connection activities, not process execution.
Advanced Hunting - DeviceProcessEvents
The DeviceProcessEvents table in Microsoft Defender XDR Advanced Hunting contains information about processes created and terminated on devices.
- Includes process command line, user, device, and parent process information.
- Essential for detecting malicious process execution patterns.
- Used to track execution of scripts and applications.
Memory trick: Processes are like recipes, and DeviceProcessEvents holds all the recipe steps (command lines).