Microsoft Security Operations AnalystMitigate threats using Microsoft Defender XDRHard

A security analyst is investigating an alert from Microsoft Defender for Identity indicating 'Suspicious service creation'. The alert details show a new service named 'UpdaterService' was created on a domain controller. To understand the full context of this activity, including the process that created the service and any subsequent network connections, which Advanced Hunting table in Microsoft Defender XDR should the analyst query first, and then potentially join with other tables?

  1. ADeviceRegistryEvents
  2. BIdentityDirectoryEvents
  3. CDeviceProcessEvents
  4. DIdentityLogonEvents
Show answer & explanation

Correct answer: A. DeviceRegistryEvents

Service creation often involves writing to the registry. The 'DeviceRegistryEvents' table captures registry modifications, including service creation. By querying this table first for the 'UpdaterService', the analyst can identify the process (via 'InitiatingProcessCommandLine' or 'InitiatingProcessFileName') that created it. This process ID can then be used to join with 'DeviceProcessEvents' for parent/child process analysis and 'DeviceNetworkEvents' for network connections.

Why the other options are wrong

  • B. IdentityDirectoryEvents tracks changes to Active Directory objects, not directly service creation on a DC's operating system.
  • C. DeviceProcessEvents tracks process launches, but the *creation* of a service (which is a registry modification) is best captured initially by DeviceRegistryEvents to link to the initiating process.
  • D. IdentityLogonEvents tracks user logon activities, not service creation or process details.

Advanced Hunting: Service Creation (Registry)

Suspicious service creation is often detected by monitoring registry modifications. The `DeviceRegistryEvents` table in Advanced Hunting captures these changes, allowing an analyst to identify the process responsible for creating a new service.

  • Services are defined in the Windows Registry.
  • DeviceRegistryEvents captures additions/modifications.
  • Helps identify the initiating process of service creation.

Memory trick: To find out who built the 'UpdaterService' (a registry thing), check the 'RegistryEvents' first to see who wrote its blueprints.

More Mitigate threats using Microsoft Defender XDR questions