Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security analyst is reviewing alerts from Microsoft Defender for Identity related to a potential 'Pass-the-Hash' attack. The alerts indicate suspicious NTLM authentication activities from a workstation. To further investigate, the analyst needs to query specific NTLM authentication events, including the source workstation, target server, and authentication type. Which Advanced Hunting table in Microsoft 365 Defender is most appropriate for this investigation?

  1. AIdentityQueryEvents
  2. BDeviceNetworkEvents
  3. CIdentityLogonEvents
  4. DIdentityDirectoryEvents
Show answer & explanation

Correct answer: C. IdentityLogonEvents

The IdentityLogonEvents table records information about NTLM and Kerberos authentications, which is critical for investigating Pass-the-Hash and other credential theft attacks. It contains details like authentication type, source workstation, and target server.

Why the other options are wrong

  • A. IdentityQueryEvents tracks queries made to Active Directory (e.g., LDAP queries), not authentication events.
  • B. DeviceNetworkEvents focuses on general network connections from endpoints, not specific identity authentication protocols like NTLM.
  • D. IdentityDirectoryEvents records changes made to Active Directory objects (e.g., user creation, group modification), not authentication attempts.

Advanced Hunting - IdentityLogonEvents

The IdentityLogonEvents table in Advanced Hunting contains information about user logon activities, including NTLM and Kerberos authentications.

  • Records authentication type (NTLM, Kerberos).
  • Includes source workstation, target server, and user details.
  • Crucial for investigating credential theft and lateral movement.

Memory trick: To see who 'logged on' and how, check 'IdentityLogonEvents'.

More Mitigate threats using Microsoft Defender XDR questions