Defender-UrlClickEvents

ActionTypeTitleSampleRule
anyURL click activityNY
ClickAllowedClick allowedNN
ClickBlockedClick blockedNN
ClickBlockedByTenantPolicyClick blocked by tenant policyNN
UrlErrorPageURL error pageNN
UrlScanInProgressURL scan in progressNN

any: URL click activity

#
Table
UrlClickEvents

Detection Fields #

Fields referenced by at least one attached detection rule. This view counts distinct rules and is not a complete event schema.

NameRulesVendors
ThreatTypes1 detection ruleKusto

Common Indicators #

Positive field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis. This is separate from Fields accounting, which also includes exclusions and counts distinct attached rules.

FieldKindValueRulesVendors
Url (kusto rule field)eqClickedUrls2 ruleskusto
Url (kusto rule field)is_not_null1 rulekusto
IndicatorType (kusto rule field)equrl1 rulekusto
Type (kusto rule field)equrl1 rulekusto

Detection Rules #

Full rule details for this event, including ATT&CK technique mappings and native queries →

Kusto #

ClickAllowed: Click allowed

#
Table
UrlClickEvents

ClickBlocked: Click blocked

#
Table
UrlClickEvents

ClickBlockedByTenantPolicy: Click blocked by tenant policy

#
Table
UrlClickEvents

UrlErrorPage: URL error page

#
Table
UrlClickEvents

UrlScanInProgress: URL scan in progress

#
Table
UrlClickEvents

References #