Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating a series of alerts in Microsoft Defender for Identity indicating suspicious movement of a service account. The alerts suggest potential 'Pass-the-Hash' or 'Pass-the-Ticket' attacks. The analyst needs to quickly identify all endpoints that the compromised service account has recently authenticated to, as well as any other accounts that authenticated to those same endpoints. Which advanced hunting table in Microsoft Defender XDR is most appropriate for this investigation?
- ADeviceProcessEvents
- BCloudAppEvents
- CEmailEvents
- DIdentityLogonEvents
Show answer & explanationAnswer & explanation
Correct answer: D. IdentityLogonEvents
The IdentityLogonEvents table in advanced hunting contains information about authentication activities, including logons from identity providers like Active Directory. This table is crucial for tracing account activity across devices and identifying lateral movement associated with 'Pass-the-Hash' or 'Pass-the-Ticket' attacks.
Why the other options are wrong
- A. DeviceProcessEvents tracks process creation and execution on devices, not identity authentication across devices.
- B. CloudAppEvents tracks activities in cloud applications, not on-premises identity authentication to endpoints.
- C. EmailEvents tracks email activity, which is irrelevant for investigating identity-based lateral movement.
IdentityLogonEvents Table
An advanced hunting table in Microsoft Defender XDR that contains information about authentication activities and logon events across the organization's identities.
- Tracks successful and failed logon attempts.
- Includes details like account name, device, logon type, and authentication protocol.
- Crucial for investigating identity-based attacks and lateral movement.
Memory trick: IdentityLogonEvents watches who logs on where, a digital ID check.