Defender-DeviceImageLoadEvents
2 events across 2 channels
| Event ID | Title | Channel |
|---|---|---|
| 9006000 | Image load (any) | DeviceImageLoadEvents |
| 9006001 | Image loaded | ImageLoaded |
Event ID 9006000 — Image load (any)
#Description
Image load (any)
Fields #
| Name | Description |
|---|---|
DeviceId | — |
Timestamp | — |
ActionType | — |
FileName | — |
FolderPath | — |
SHA256 | — |
InitiatingProcessFileName | — |
Detection Patterns #
Defense Evasion: Regsvr32
1 rule
Kusto Query Language
Execution: User Execution
1 rule
Kusto Query Language
References #
- Microsoft Defender XDR — advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceimageloadevents-table
Event ID 9006001 — Image loaded
Description
Image loaded
Fields #
| Name | Description |
|---|---|
DeviceId | — |
Timestamp | — |
FileName | — |
FolderPath | — |
SHA256 | — |
InitiatingProcessFileName | — |
References #
- Microsoft Defender XDR — advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceimageloadevents-table