Defender-DeviceImageLoadEvents

ActionTypeTitleSampleRule
anyImage loadYY
ImageLoadedImage loadedYY

any: Image load

#
Table
DeviceImageLoadEvents

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
FileName5 detection rulesKusto
InitiatingProcessFileName5 detection rulesKusto
SHA2563 detection rulesKusto
DeviceId1 detection ruleKusto
FolderPath1 detection ruleKusto
InitiatingProcessIntegrityLevel1 detection ruleKusto
InitiatingProcessParentFileName1 detection ruleKusto
InitiatingProcessSHA2561 detection ruleKusto
SHA11 detection ruleKusto

Example Event #

{
  "ActionType": "ImageLoaded",
  "DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "DeviceName": "jd-win11-22h2-1.ludus.domain",
  "FileName": "rpcMessages.dll",
  "FileSize": 163328,
  "FileSize@odata.type": "#Int64",
  "FolderPath": "C:\\Windows\\System32\\rpcMessages.dll",
  "InitiatingProcessAccountDomain": "ludus",
  "InitiatingProcessAccountName": "domainadmin",
  "InitiatingProcessAccountObjectId": "11111111-1111-1111-1111-111111111111",
  "InitiatingProcessAccountSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "InitiatingProcessAccountUpn": "adminuser@example.onmicrosoft.com",
  "InitiatingProcessCommandLine": "\"OneDriveStandaloneUpdater.exe\" /reporting",
  "InitiatingProcessCreationTime": "2026-08-01T09:03:46.8776437Z",
  "InitiatingProcessFileName": "onedrivestandaloneupdater.exe",
  "InitiatingProcessFileSize": 4407184,
  "InitiatingProcessFileSize@odata.type": "#Int64",
  "InitiatingProcessFolderPath": "c:\\program files\\microsoft onedrive\\onedrivestandaloneupdater.exe",
  "InitiatingProcessId": 4116,
  "InitiatingProcessId@odata.type": "#Int64",
  "InitiatingProcessIntegrityLevel": "High",
  "InitiatingProcessMD5": "13cc6a05bbf6439da45411defeaffa47",
  "InitiatingProcessParentCreationTime": "2026-08-01T00:56:39.5027656Z",
  "InitiatingProcessParentFileName": "svchost.exe",
  "InitiatingProcessParentId": 2036,
  "InitiatingProcessParentId@odata.type": "#Int64",
  "InitiatingProcessSHA1": "37d0ab300eb137e6eb344571611f000932bc6497",
  "InitiatingProcessSHA256": "e147a6284cc158ffcee9f473ace8645c03edea779df49cfcf3c7353783f53f70",
  "InitiatingProcessSessionId": 1,
  "InitiatingProcessSessionId@odata.type": "#Int64",
  "InitiatingProcessTokenElevation": "TokenElevationTypeDefault",
  "InitiatingProcessUniqueId": "9851624184879088",
  "InitiatingProcessVersionInfoCompanyName": "Microsoft Corporation",
  "InitiatingProcessVersionInfoFileDescription": "Standalone Updater",
  "InitiatingProcessVersionInfoInternalFileName": "OneDriveStandaloneUpdater.exe",
  "InitiatingProcessVersionInfoOriginalFileName": "OneDriveStandaloneUpdater.exe",
  "InitiatingProcessVersionInfoProductName": "Microsoft OneDrive",
  "InitiatingProcessVersionInfoProductVersion": "26.123.0628.0001",
  "IsInitiatingProcessRemoteSession": 0,
  "IsInitiatingProcessRemoteSession@odata.type": "#SByte",
  "MD5": "5337bc2acac97c53dcb5c86ddc56eeba",
  "ReportId": 14353,
  "ReportId@odata.type": "#Int64",
  "SHA1": "5e0439d5b27a45b43412bad6447ba02f475acca0",
  "SHA256": "c0c58f88dc59107aa9053cef00ec8e7c15c2be96cf11c564903853f6ea83be93",
  "Timestamp": "2026-08-01T09:03:49.1457309Z"
}

Detection Patterns #

Show All Detection Patterns

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Hashes[0] (kusto rule field)eqsha2563 ruleskusto
ClientIP (kusto rule field)eqIPList2 ruleskusto
DestinationIP (kusto rule field)eqIPList2 ruleskusto
GlobalPrevalence (kusto rule field)lt1002 ruleskusto
GlobalPrevalence (kusto rule field)lt2002 ruleskusto
Hashes[1] (kusto rule field)containssha256hashes2 ruleskusto
IPAddresses (kusto rule field)eqIPList2 ruleskusto
InitiatingProcessSHA256 (kusto rule field)eqsha256hashes2 ruleskusto
Message (kusto rule field)containsiplist2 ruleskusto
SourceIP (kusto rule field)eqIPList2 ruleskusto
dest_ip (kusto rule field)eqIPList2 ruleskusto
sha256 (kusto rule field)containssha256hashes2 ruleskusto
src_ip (kusto rule field)eqIPList2 ruleskusto
ActionType (kusto rule field)eqInboundConnectionAccepted1 rulekusto
ActionType (kusto rule field)inFileCreated1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

ImageLoaded: Image loaded

#
Table
DeviceImageLoadEvents

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
ActionType1 detection ruleKusto

Example Event #

{
  "ActionType": "ImageLoaded",
  "DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "DeviceName": "jd-win11-22h2-1.ludus.domain",
  "FileName": "rpcMessages.dll",
  "FileSize": 163328,
  "FileSize@odata.type": "#Int64",
  "FolderPath": "C:\\Windows\\System32\\rpcMessages.dll",
  "InitiatingProcessAccountDomain": "ludus",
  "InitiatingProcessAccountName": "domainadmin",
  "InitiatingProcessAccountObjectId": "11111111-1111-1111-1111-111111111111",
  "InitiatingProcessAccountSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "InitiatingProcessAccountUpn": "adminuser@example.onmicrosoft.com",
  "InitiatingProcessCommandLine": "\"OneDriveStandaloneUpdater.exe\" /reporting",
  "InitiatingProcessCreationTime": "2026-08-01T09:03:46.8776437Z",
  "InitiatingProcessFileName": "onedrivestandaloneupdater.exe",
  "InitiatingProcessFileSize": 4407184,
  "InitiatingProcessFileSize@odata.type": "#Int64",
  "InitiatingProcessFolderPath": "c:\\program files\\microsoft onedrive\\onedrivestandaloneupdater.exe",
  "InitiatingProcessId": 4116,
  "InitiatingProcessId@odata.type": "#Int64",
  "InitiatingProcessIntegrityLevel": "High",
  "InitiatingProcessMD5": "13cc6a05bbf6439da45411defeaffa47",
  "InitiatingProcessParentCreationTime": "2026-08-01T00:56:39.5027656Z",
  "InitiatingProcessParentFileName": "svchost.exe",
  "InitiatingProcessParentId": 2036,
  "InitiatingProcessParentId@odata.type": "#Int64",
  "InitiatingProcessSHA1": "37d0ab300eb137e6eb344571611f000932bc6497",
  "InitiatingProcessSHA256": "e147a6284cc158ffcee9f473ace8645c03edea779df49cfcf3c7353783f53f70",
  "InitiatingProcessSessionId": 1,
  "InitiatingProcessSessionId@odata.type": "#Int64",
  "InitiatingProcessTokenElevation": "TokenElevationTypeDefault",
  "InitiatingProcessUniqueId": "9851624184879088",
  "InitiatingProcessVersionInfoCompanyName": "Microsoft Corporation",
  "InitiatingProcessVersionInfoFileDescription": "Standalone Updater",
  "InitiatingProcessVersionInfoInternalFileName": "OneDriveStandaloneUpdater.exe",
  "InitiatingProcessVersionInfoOriginalFileName": "OneDriveStandaloneUpdater.exe",
  "InitiatingProcessVersionInfoProductName": "Microsoft OneDrive",
  "InitiatingProcessVersionInfoProductVersion": "26.123.0628.0001",
  "IsInitiatingProcessRemoteSession": 0,
  "IsInitiatingProcessRemoteSession@odata.type": "#SByte",
  "MD5": "5337bc2acac97c53dcb5c86ddc56eeba",
  "ReportId": 14353,
  "ReportId@odata.type": "#Int64",
  "SHA1": "5e0439d5b27a45b43412bad6447ba02f475acca0",
  "SHA256": "c0c58f88dc59107aa9053cef00ec8e7c15c2be96cf11c564903853f6ea83be93",
  "Timestamp": "2026-08-01T09:03:49.1457309Z"
}

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
GlobalPrevalence (kusto rule field)lt1002 ruleskusto
GlobalPrevalence (kusto rule field)lt2001 rulekusto
GlobalPrevalence (kusto rule field)lt5001 rulekusto
InitiatingProcessSHA1 (kusto rule field)is_not_null1 rulekusto
Signer (kusto rule field)is_null1 rulekusto

References #