Defender-DeviceNetworkEvents

8 events across 8 channels

Event IDTitleChannel
9004000Network activity (any)DeviceNetworkEvents
9004001Connection succeededConnectionSuccess
9004002Connection failedConnectionFailed
9004003Inbound connection acceptedInboundConnectionAccepted
9004004Listening connection createdListeningConnectionCreated
9004005Connection requestConnectionRequest
9004006DNS connection inspectedDnsConnectionInspected
9004007DNS query / responseDnsQueryResponse

Event ID 9004000 — Network activity (any)

#
Provider
Defender-DeviceNetworkEvents
Channel
DeviceNetworkEvents

Description

Network activity (any)

Fields #

NameDescription
DeviceId
Timestamp
ActionType
RemoteIP
RemotePort
RemoteUrl
LocalIP
LocalPort
Protocol
InitiatingProcessFileName
InitiatingProcessCommandLine

Detection Rules #

View all rules referencing this event →

Kusto Query Language # view in reference

  • Zinc Actor IOCs files - October 2022 source high: 'Identifies a match across filename and commandline IOC's related to an actor tracked by Microsoft as Zinc. Reference: https://www.microsoft.com/security/blog/2022/09/29/zinc-weaponizing-open-source-software/'

References #

Event ID 9004001 — Connection succeeded

#
Provider
Defender-DeviceNetworkEvents
Channel
ConnectionSuccess

Description

Connection succeeded

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
RemoteUrl
Protocol
InitiatingProcessFileName

Detection Patterns #

References #

Event ID 9004002 — Connection failed

Provider
Defender-DeviceNetworkEvents
Channel
ConnectionFailed

Description

Connection failed

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
Protocol
InitiatingProcessFileName

References #

Event ID 9004003 — Inbound connection accepted

Provider
Defender-DeviceNetworkEvents
Channel
InboundConnectionAccepted

Description

Inbound connection accepted

Fields #

NameDescription
DeviceId
Timestamp
LocalIP
LocalPort
RemoteIP
Protocol

References #

Event ID 9004004 — Listening connection created

Provider
Defender-DeviceNetworkEvents
Channel
ListeningConnectionCreated

Description

Listening connection created

Fields #

NameDescription
DeviceId
Timestamp
LocalIP
LocalPort
Protocol
InitiatingProcessFileName

References #

Event ID 9004005 — Connection request

Provider
Defender-DeviceNetworkEvents
Channel
ConnectionRequest

Description

Connection request

Fields #

NameDescription
DeviceId
Timestamp
RemoteIP
RemotePort
Protocol

References #

Event ID 9004006 — DNS connection inspected

Provider
Defender-DeviceNetworkEvents
Channel
DnsConnectionInspected

Description

DNS connection inspected

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
RemoteIP
Protocol

References #

Event ID 9004007 — DNS query / response

Provider
Defender-DeviceNetworkEvents
Channel
DnsQueryResponse

Description

DNS query / response

Fields #

NameDescription
DeviceId
Timestamp
RemoteUrl
RemoteIP

References #