Defender-DeviceTvmSoftwareInventory
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Installed software inventory | Y | Y |
any: Installed software inventory
#Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
SoftwareName | 2 detection rules | Kusto |
SoftwareVendor | 1 detection rule | Kusto |
Example Event #
{
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1.ludus.domain",
"OSArchitecture": "x64",
"OSPlatform": "Windows11",
"OSVersion": "10.0.22621.6060",
"ProductCodeCpe": "Not Available",
"SoftwareName": "qsetup_installation_suite",
"SoftwareVendor": "pantaray",
"SoftwareVersion": "203.0.113.10"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #