Mensajes de suceso de ejemplo de Microsoft 365 Defender

Utilice estos mensajes de suceso de ejemplo para verificar una integración satisfactoria con IBM QRadar.

Importante:
  • El nombre de Microsoft Windows Defender ATP DSM es ahora Microsoft 365 Defender DSM. El nombre de RPM de DSM permanece como Microsoft Windows Defender ATP en QRadar.
  • Debido a un cambio en la suite de API de Microsoft Defender a partir del 25 de noviembre de 2021, Microsoft ya no permite la incorporación de nuevas integraciones con su API SIEM. Para obtener más información, consulte Deprecating the legacy SIEM API (https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/deprecating-the-legacy-siem-api/ba-p/3139643).

    La API de Streaming se puede utilizar con el protocolo Microsoft Azure Event Hubs para proporcionar reenvío de sucesos y alertas a QRadar. Para obtener más información sobre el servicio y su configuración, consulte Configurar Microsoft 365 Defender para transmitir sucesos de Advanced Hunting a Azure Event Hub (https://docs.micosoft.com/en-us/microsoft-365/security/defender/streaming-api-event-hub?view=o365-worldwide)

Mensajes de ejemplo de Microsoft 365 Defender cuando se utiliza el protocolo Microsoft Azure Event Hubs

Ejemplo 1: El siguiente mensaje de suceso de ejemplo muestra una actualización de tarea planificada satisfactoria.

Importante: Debido a problemas de formato, pegue el formato de mensaje en un editor de texto y, a continuación, elimine los caracteres de retorno de carro o salto de línea.
"{"time":"2021-07-21T00:57:23.0186119Z","tenantId":"abc12345-123a-123a-456b-abcdefg12345","operationName":"Publish","category":"AdvancedHunting-DeviceEvents","properties":{"AccountSid":null,"AccountDomain":null,"AccountName":null,"LogonId":null,"FileName":null,"FolderPath":null,"MD5":null,"SHA1":null,"FileSize":null,"SHA256":null,"ProcessCreationTime":null,"ProcessTokenElevation":null,"RemoteUrl":null,"RegistryKey":null,"RegistryValueName":null,"RegistryValueData":null,"RemoteDeviceName":null,"FileOriginIP":null,"FileOriginUrl":null,"LocalIP":null,"LocalPort":null,"RemoteIP":null,"RemotePort":null,"ProcessId":null,"ProcessCommandLine":null,"AdditionalFields":"{\"TaskName\":\"\\\\Microsoft\\\\Windows\\\\UpdateOrchestrator\\\\Schedule Maintenance Work\"}","ActionType":"ScheduledTaskUpdated","InitiatingProcessVersionInfoCompanyName":null,"InitiatingProcessVersionInfoProductName":null,"InitiatingProcessVersionInfoProductVersion":null,"InitiatingProcessVersionInfoInternalFileName":null,"InitiatingProcessVersionInfoOriginalFileName":null,"InitiatingProcessVersionInfoFileDescription":null,"InitiatingProcessFolderPath":null,"InitiatingProcessFileName":null,"InitiatingProcessFileSize":null,"InitiatingProcessMD5":null,"InitiatingProcessSHA256":null,"InitiatingProcessSHA1":null,"InitiatingProcessLogonId":999,"InitiatingProcessAccountSid":"S-1-5-18","InitiatingProcessAccountDomain":"m365defender","InitiatingProcessAccountName":"client-pc$","InitiatingProcessAccountUpn":null,"InitiatingProcessAccountObjectId":null,"InitiatingProcessCreationTime":null,"InitiatingProcessId":null,"InitiatingProcessCommandLine":null,"InitiatingProcessParentCreationTime":null,"InitiatingProcessParentId":null,"InitiatingProcessParentFileName":null,"DeviceId":"111122223333444455556666777788889999aaaa","AppGuardContainerId":"","MachineGroup":null,"Timestamp":"2021-07-21T00:55:44.2280946Z","DeviceName":"client-pc.example.net","ReportId":60533}}" );
Tabla 1. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Categoría de suceso categoría
ID de suceso ActionType
Hora de dispositivo Indicación de fecha y hora

Ejemplo 2: El siguiente mensaje de suceso de ejemplo muestra una alerta sobre una posible actividad de registro de claves.

{"time":"2021-09-09T00:40:17.7066896Z","tenantId":"abc12345-123a-123a-456b-abcdefg12345","operationName":"Publish","category":"AdvancedHunting-AlertInfo","properties":{"AlertId":"da637667448174310467_1631502683","Timestamp":"2021-09-09T00:39:17.1650944Z","Title":"Possible keylogging activity","ServiceSource":"Microsoft Defender for Endpoint","Category":"Collection","Severity":"High","DetectionSource":"EDR","MachineGroup":null,"AttackTechniques":"[\"Input Capture (T1056)\"]"}}
Tabla 2. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Categoría de suceso categoría
ID de suceso Título
Hora de dispositivo Indicación de fecha y hora

Mensajes de ejemplo de Microsoft 365 Defender cuando se utiliza el protocolo de la API REST de Microsoft Defender for Endpoint SIEM

Ejemplo 1: El siguiente mensaje de suceso de ejemplo muestra actividad sospechosa.

{"AlertTime":"2017-12-27T03:54:41.1914393Z","ComputerDnsName":"<ComputerDnsName>","AlertTitle":"<AlertTitle>","Category":"CommandAndControl","Severity":"<Severity>","AlertId":"<AlertId>","Actor":"<Actor>","LinkToWDATP":"<LinkToWDATP>","IocName":"<IocName>","IocValue":"<IocValue>","CreatorIocName":"<CreatorIocName>","CreatorIocValue":"<CreatorIocValue>","Sha1":"<Sha1>","FileName":"<FileName>","FilePath":"<FilePath>","IpAddress":"192.0.2.0","Url":"<Url>","IoaDefinitionId":"<IoaDefinitionId>","UserName":"qradar1","AlertPart":"<AlertPart>","FullId":"<FullId>","LastProcessedTimeUtc":"2017-12-27T07:16:34.1412283Z","ThreatCategory":"<ThreatCategory>","ThreatFamily":"<ThreatFamily>","ThreatName":"<ThreatName>","RemediationAction":"<RemediationAction>","RemediationIsSuccess":"<RemediationIsSuccess>","Source":"WindowsDefenderAtp","Md5":"<Md5>","Sha256":"<Sha256>","WasExecutingWhileDetected":"<WasExecutingWhileDetected>","UserDomain":"<UserDomain>","LogOnUsers":"<LogOnUsers>","MachineDomain":"<MachineDomain>","MachineName":"<MachineName>","InternalIPv4List":"192.0.2.0;127.0.0.1","InternalIPv6List":"2001:0DB8:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF","FileHash":"<FileHash>","ExternalId":"<ExternalId>","IocUniqueId":"IocUniqueId"}
Tabla 3. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Hora de dispositivo AlertTime
ID de suceso Categoría
IP de origen IpAddress
IP de origen v6 InternalIPv6List
Nombre de usuario UserName

Ejemplo 2: El siguiente mensaje de suceso de ejemplo muestra que se ha detectado un acceso de puerta trasera.

{"AlertTime":"2017-11-22T18:01:32.1887775Z","ComputerDnsName":"<ComputerDnsName>","AlertTitle":"<AlertTitle>","Category":"Backdoor","Severity":"<Severity>","AlertId":"<AlertId","Actor":"<Actor>","LinkToWDATP":"<LinkToWDATP>","IocName":"<IocName>","IocValue":"<IocValue>","CreatorIocName":"<CreatorIocName>","CreatorIocValue":"<CreatorIocValue>","Sha1":"<Sha1>","FileName":"<FileName>","FilePath":"<FilePath>","IpAddress":"192.0.2.0","Url":"<Url>","IoaDefinitionId":"<IoaDefinitionId>","UserName":"qradar1","AlertPart":"<AlertPart>","FullId":"<FullId>","LastProcessedTimeUtc":"2017-11-22T18:01:49.8739015Z","ThreatCategory":"<ThreatCategory>","ThreatFamily":"<ThreatFamily>","ThreatName":"<ThreatName>","RemediationAction":"<RemediationAction>","RemediationIsSuccess":"<RemediationIsSuccess>","Source":"WindowsDefenderAtp","Md5":"<Md5>","Sha256":"<Sha256>","WasExecutingWhileDetected":"<WasExecutingWhileDetected>","UserDomain":"<UserDomain>","LogOnUsers":"<LogOnUsers>","MachineDomain":"<MachineDomain>","MachineName":"<MachineName>","InternalIPv4List":"192.0.2.0;127.0.0.1","InternalIPv6List":"2001:0DB8:FFFF:FFFF:FFFF:FFFF:FFFF:FFFF","FileHash":"<FileHash>","ExternalId":"<ExternalId>","IocUniqueId":"IocUniqueId"}
Tabla 4. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Hora de dispositivo AlertTime
ID de suceso Categoría
IP de origen IpAddress
IP de origen v6 InternalIPv6List
Nombre de usuario UserName

Mensajes de ejemplo de Microsoft 365 Defender cuando se utiliza el protocolo Security API de Microsoft Graph

Ejemplo 1: El siguiente mensaje de evento de ejemplo muestra que se ha observado un movimiento lateral en otro dispositivo muy cerca en el tiempo de un evento de red sospechoso en este dispositivo. Esto podría significar que un atacante está intentando moverse lateralmente entre dispositivos para recopilar datos o elevar los privilegios. Esta alerta se ha desencadenado basándose en una alerta de Microsoft Defender for Endpoint.
{"id":"da637789431774501659_-1621338217","providerAlertId":"da637789431774501659_-1621338217","incidentId":"5","status":"resolved","severity":"medium","classification":null,"determination":null,"serviceSource":"microsoftDefenderForEndpoint","detectionSource":"microsoft365Defender","detectorId":"ab3e5834-3d38-42c5-aaa6-c1cfc6c02882","tenantId":"24d3dca4-61f8-4b86-8e22-612b71d65386","title":"Possible lateral movement","description":"Lateral movement on another device was observed in close time proximity to a suspicious network event on this device. This could mean that an attacker is attempting to move laterally across devices to gather data or elevate privileges. This alert was triggered based on a Microsoft Defender for Endpoint alert.","recommendedActions":"A. Validate the alert.\r\n1. Investigate the process, its behaviors, and the endpoint involved in the original alert for suspicious activity.\r\n2. Check for other suspicious activities in the device timeline.\r\n3. Locate unfamiliar processes in the process tree. Check files for prevalence, their locations, and digital signatures.\r\n4. Submit relevant files for deep analysis and review file behaviors.\r\n5. Identify unusual system activity with system owners.\r\n\r\nB. Scope the incident. Find related device, network addresses, and files in the incident graph.\r\n\r\nC. Contain and mitigate the breach. Stop suspicious processes, isolate affected devices, decommission compromised accounts or reset passwords, block IP addresses and URLs, and install security updates.\r\n\r\nD. Contact your incident response team, or contact Microsoft support for investigation and remediation services.","category":"LateralMovement","assignedTo":"testUser@testUser@example.test","alertWebUrl":"https://security.microsoft.com/alerts/da637789431774501659_-1621338217?tid=24d3dca4-61f8-4b86-8e22-612b71d65386","incidentWebUrl":"https://security.microsoft.com/incidents/5?tid=24d3dca4-61f8-4b86-8e22-612b71d65386","actorDisplayName":null,"threatDisplayName":null,"threatFamilyName":null,"mitreTechniques":["T1570","T1021.002","T1021.003","T1021.004","T1021.006"],"createdDateTime":"2022-01-28T05:06:17.4503018Z","lastUpdateDateTime":"2022-01-28T07:11:29.6933333Z","resolvedDateTime":"2022-01-28T05:21:32.5866667Z","firstActivityDateTime":"2022-01-28T04:53:35.0699463Z","lastActivityDateTime":"2022-01-28T04:53:35.0699463Z","comments":[],"evidence":[{"@odata.type":"#microsoft.graph.security.deviceEvidence","createdDateTime":"2022-01-28T05:06:17.51Z","evidenceRole":"impacted","verdict":"unknown","remediationStatus":"none","remediationStatusDetails":null,"firstSeenDateTime":"2022-01-28T01:15:01.628Z","mdeDeviceId":"12345testmdeDeviceid","azureAdDeviceId":null,"deviceDnsName":"testHost.test","osPlatform":"Windows10","osBuild":17763,"version":"1809","healthStatus":"active","riskScore":"high","rbacGroupId":0,"rbacGroupName":null,"onboardingStatus":"onboarded","defenderAvStatus":"updated","loggedOnUsers":[{"accountName":"testUser","domainName":"MPRTDEV"}]},{"@odata.type":"#microsoft.graph.security.processEvidence","createdDateTime":"2022-01-28T05:06:17.51Z","evidenceRole":"related","verdict":"unknown","remediationStatus":"none","remediationStatusDetails":null,"processId":4,"parentProcessId":0,"processCommandLine":"","processCreationDateTime":"2022-01-28T01:01:49.3539999Z","parentProcessCreationDateTime":null,"detectionStatus":null,"mdeDeviceId":null,"parentProcessImageFile":null,"imageFile":{"sha1":"3791cf139c5f9e5c97e9c091f73e441b6a9bbd30","sha256":"e2f1857de3560a5237ca7ea661fc3688715bbbf6baa483511d49baac4ce1acf9","fileName":"System","filePath":"c:\\windows\\system32\\ntoskrnl.exe","fileSize":null,"filePublisher":null,"signer":null,"issuer":null},"userAccount":{"accountName":"system","domainName":null,"userSid":"S-1-1-1","azureAdUserId":null,"userPrincipalName":null}},{"@odata.type":"#microsoft.graph.security.ipEvidence","createdDateTime":"2022-01-28T05:06:17.51Z","evidenceRole":"related","verdict":"unknown","remediationStatus":"none","remediationStatusDetails":null,"ipAddress":"10.0.0.5"},{"@odata.type":"#microsoft.graph.security.urlEvidence","createdDateTime":"2022-01-28T05:06:17.51Z","evidenceRole":"related","verdict":"unknown","remediationStatus":"none","remediationStatusDetails":null,"url":"mprtdev-win10b"},{"@odata.type":"#microsoft.graph.security.userEvidence","createdDateTime":"2022-01-28T05:06:17.51Z","evidenceRole":"impacted","verdict":"unknown","remediationStatus":"none","remediationStatusDetails":null,"userAccount":{"accountName":null,"domainName":null,"userSid":null,"azureAdUserId":null,"userPrincipalName":null}}]}
Tabla 5. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Hora de dispositivo createdDateTime
ID de suceso Categoría
Categoría de suceso detectionSource
IP de origen ipAddress
Nombre de usuario assignedTo
Ejemplo 2: El siguiente ejemplo de mensaje de evento muestra un Anuncio de Servicio.
{"startDateTime":"2025-03-05T23:57:40Z","endDateTime":"2026-02-02T08:00:00Z","lastModifiedDateTime":"2025-07-24T13:40:22.29Z","title":"(Updated) Microsoft Entra: Browser access will be enabled by default for all Android users","id":"X00000001","category":"planForChange","severity":"normal","tags":["Updated message","Feature update","User impact","Admin impact","Retirement"],"isMajorChange":true,"actionRequiredByDateTime":null,"services":["Microsoft Entra"],"hasAttachments":false,"viewPoint":null,"details":[{"name":"Summary","value":"Microsoft Entra will enable browser access by default for all Android users, retiring the \"Enable Browser Access\" feature in Microsoft Authenticator and Company Portal apps. This hardware-bound device registration change requires no admin action and will roll out automatically worldwide. Organizations not using Android can ignore this update."}],"body":{"contentType":"html","content":"<p>Updated July 24, 2025: We have updated the timeline. Thank you for your patience.</p><p>If your organization does not support Android devices, you can safely ignore this message.\n</p><p>As part of our overall security hardening efforts, we will migrate Microsoft Entra ID device registration to be hardware-bound. Since the device identity will be hardware-bound, we will retire the ability for users to enable a feature called <i>Enable Browser Access </i>(EBA) in the Microsoft Authenticator app and the Microsoft Company Portal app for Android. After this retirement, browser access will automatically be enabled as part of device registration.\n</p><p>[When this will happen:]\n</p><p>General Availability (Worldwide): We will communicate via Message center when we are ready to proceed.</p><p>[What you need to do to prepare:]\n</p><p>No action or preparation is required from admins or users regarding this change. The change will occur automatically.\n</p><p>The <i>Enable Browser Access</i> feature will retire from the Company Portal and Authenticator apps for Android:\n</p><p><img src=\"https://example.com/file/ccp/en-us/5adf2eac-6eb7-45b5-933d-334324a1dc12\" style=\"width: 300px;\" alt=\"user controls\">\n</p><p>This change was first announced in <a href=\"https://example.com/blog/example/whats-new-in-microsoft-entra---september-2024/4253153\" target=\"_blank\">What's new in Microsoft Entra - September 2024 | Microsoft Community Hub</a> (September 2024).\n</p><p>This rollout will happen automatically by the specified date with no admin action required before the rollout. Review your current configuration to determine the impact for your organization. You may want to notify your users about this change and update any relevant documentation.</p>"}}

2

Tabla 6. Campos resaltados en el Microsoft 365 Defender
QRadar Nombre del campo de Nombre de campo de carga útil resaltado
Hora de dispositivo startDateTime
ID de suceso categoría
Categoría de suceso ServiceAnnouncement