Defender-DeviceInfo

1 ActionType

ActionTypeTitle
anyDevice inventory snapshot

any: Device inventory snapshot

#
Provider
Defender-DeviceInfo
Channel
DeviceInfo

Description

Device inventory snapshot — Inventory telemetry; no native event equivalent.

Fields #

NameDescription
DeviceId
DeviceName
OSPlatform
OSVersion
OSBuild
OSArchitecture
JoinType
AadDeviceId
IsAzureADJoined

Common Indicators #

Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.

FieldKindValueRulesVendors
ProviderNameeqMDATP7 ruleskusto

Detection Rules #

View all rules referencing this event →

Kusto # view in coverage

Show 4 more (7 total)

References #