Defender-DeviceTvmSoftwareVulnerabilities

ActionTypeTitleSampleRule
anySoftware vulnerabilities on devicesYY

any: Software vulnerabilities on devices

#
Table
DeviceTvmSoftwareVulnerabilities

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
DeviceId1 detection ruleKusto
VulnerabilitySeverityLevel1 detection ruleKusto

Example Event #

{
  "AadDeviceId": "db412646-80ba-4176-935f-7450b35979ee",
  "CveId": "CVE-2026-48092",
  "CveTags@odata.type": "#Collection(String)",
  "DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "DeviceName": "jd-win11-22h2-1.ludus.domain",
  "OSArchitecture": "x64",
  "OSPlatform": "Windows11",
  "OSVersion": "10.0.22621.6060",
  "SoftwareName": "7-zip",
  "SoftwareVendor": "7-zip",
  "SoftwareVersion": "25.01.0.0",
  "VulnerabilitySeverityLevel": "Medium"
}

Detection Patterns #

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
ActionType (kusto rule field)containsinboundconnection1 rulekusto
CommandLine (kusto rule field)contains.webp1 rulekusto
RemoteIPType (kusto rule field)eqPublic1 rulekusto
type (kusto rule field)eqDeviceInventoryId1 rulekusto

References #