Details
| ID | microsoft_365_defender_event_collector_ModelingRule |
|---|---|
| From Version | 6.10.0 |
| Tags | Microsoft 365 Defender |
Schema
microsoft_365_defender_raw
| Field | Type | Array? |
|---|---|---|
alertCreationTime |
string | — |
category |
string | — |
computerDnsName |
string | — |
description |
string | — |
detectionSource |
string | — |
evidence |
string | — |
id |
string | — |
incidentId |
string | — |
lastEventTime |
string | — |
machineId |
string | — |
mitreTechniques |
string | — |
severity |
string | — |
threatFamilyName |
string | — |
threatName |
string | — |
title |
string | — |