Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium

A security analyst is investigating a series of suspicious activities involving a critical server that hosts sensitive customer data. Microsoft Defender for Identity has generated alerts indicating 'Suspicious service creation' and 'Remote code execution attempts'. The analyst needs to query the raw security events captured by Defender for Identity, specifically focusing on service creation events that might indicate persistence mechanisms. Which Advanced Hunting table should the analyst primarily use to find this information?

  1. AIdentityLogonEvents
  2. BDeviceRegistryEvents
  3. CDeviceProcessEvents
  4. DIdentityDirectoryEvents
Show answer & explanation

Correct answer: C. DeviceProcessEvents

Suspicious service creation and remote code execution attempts often involve the creation of new processes or modifications to existing ones. The DeviceProcessEvents table in Advanced Hunting captures detailed information about process creation, network connections, and other process-related activities on devices, which is crucial for investigating such alerts. While Defender for Identity generated the alert, the underlying event is often captured as a device event.

Why the other options are wrong

  • A. Contains information about user logon activities, not system service creation or process execution.
  • B. Contains information about registry modifications, which can be related to persistence, but process creation is more direct for 'service creation'.
  • D. Focuses on Active Directory events like user creations or group modifications, not process-level activities on devices.

Advanced Hunting: DeviceProcessEvents

An Advanced Hunting table in Microsoft Defender XDR that contains information about process creation, network connections, and other process-related events on monitored devices.

  • Crucial for investigating execution and persistence techniques.
  • Includes details like process ID, command line, parent process, and user account.
  • Often used in conjunction with other device-related tables.

Memory trick: Processes are events on a device.

More Mitigate threats using Microsoft Defender XDR questions