Defender-UrlClickEvents
| ActionType | Title | Sample | Rule | ||||||||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| any | URL click activity | N | Y | ||||||||||||||||
Click| Click allowed | N | N | Click | Click blocked | N | N | Click | Click blocked by tenant policy | N | N | Url | URL error page | N | N | Url | URL scan in progress | N | N | |
any: URL click activity
#Detection Fields #
Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.
| Name | Rules | Vendors |
|---|---|---|
ThreatTypes | 1 detection rule | Kusto |
Common Indicators #
Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
Url (kusto rule field) | eq | ClickedUrls | 2 rules | kusto |
Url (kusto rule field) | is_not_null | | 1 rule | kusto |
IndicatorType (kusto rule field) | eq | url | 1 rule | kusto |
Type (kusto rule field) | eq | url | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1189, T1566T1071T1071