Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security operations center (SOC) team is investigating a potential compromise involving a user's cloud application account. They need to review all activities performed by that user across various cloud applications, including logins, file access, and administrative actions, to identify any anomalous behavior. Which Kusto Query Language (KQL) table should they primarily query in Advanced Hunting for this investigation?

  1. ACloudAppEvents
  2. BEmailUrlInfo
  3. CDeviceProcessEvents
  4. DIdentityLogonEvents
Show answer & explanation

Correct answer: A. CloudAppEvents

The CloudAppEvents table in Advanced Hunting specifically aggregates activities from connected cloud applications, providing a comprehensive view of a user's interactions with services like Office 365, Azure AD, and other SaaS apps. This is the ideal table for investigating user behavior across cloud applications.

Why the other options are wrong

  • B. EmailUrlInfo provides details about URLs in emails and is not relevant for tracking user activities within cloud applications.
  • C. DeviceProcessEvents tracks processes running on endpoints, not activities within cloud applications.
  • D. IdentityLogonEvents focuses on identity-related logon activities but does not provide granular details of *in-app* activities like file access or administrative actions within cloud applications.

Advanced Hunting: CloudAppEvents

The CloudAppEvents table in Microsoft Defender XDR's Advanced Hunting schema records comprehensive activity data from connected cloud applications. It's crucial for understanding user behavior, detecting anomalies, and investigating incidents within cloud services.

  • Contains events from Microsoft 365 services (Exchange, SharePoint, Teams, Azure AD) and third-party cloud apps.
  • Includes details like activity type, user, IP address, device, application, and object involved.
  • Essential for investigating cloud-based compromises and insider threats.

Memory trick: CloudAppEvents is your 'CCTV' for what users do in cloud apps.

More Mitigate threats using Microsoft Defender XDR questions