Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRMedium
A security analyst is investigating an incident where a user's cloud application account was compromised. The attacker performed several suspicious actions, including downloading a large volume of sensitive data and then logging in from an unusual geographic location using the compromised credentials. The analyst needs to create a custom detection rule in Microsoft Defender XDR to identify similar future incidents, specifically focusing on data exfiltration followed by suspicious login patterns. Which two Advanced Hunting tables are MOST relevant for this scenario?
- ADeviceProcessEvents and EmailEvents
- BAlertInfo and FileProfile
- CIdentityQueryEvents and DeviceNetworkEvents
- DCloudAppEvents and IdentityLogonEvents
Show answer & explanationAnswer & explanation
Correct answer: D. CloudAppEvents and IdentityLogonEvents
The scenario describes actions within a cloud application (data download) and identity-related suspicious logins. CloudAppEvents captures activities from cloud applications, including data transfers, while IdentityLogonEvents tracks user login activities, including source IP and location, making them the most relevant tables.
Why the other options are wrong
- A. DeviceProcessEvents tracks endpoint processes, and EmailEvents tracks email activities; neither directly addresses cloud app data exfiltration or identity logins from unusual locations.
- B. AlertInfo provides general alert metadata, and FileProfile gives information about files; neither captures the transactional details of cloud app actions or identity logins.
- C. IdentityQueryEvents tracks LDAP/AD queries, and DeviceNetworkEvents tracks network connections from devices; neither fully covers cloud app activities or general identity logins.
Advanced Hunting Tables (Cloud App & Identity)
Specific tables in Microsoft Defender XDR's Advanced Hunting schema that store detailed activity logs from Microsoft Defender for Cloud Apps and Microsoft Defender for Identity, respectively.
- CloudAppEvents: Records actions in monitored cloud apps (e.g., file access, downloads, logins).
- IdentityLogonEvents: Records authentication events from Active Directory (on-prem and Azure AD).
Memory trick: Cloud activities and Identity logins tell the story of a compromised user.