Microsoft Defender Attribute Reference
This reference lists the attributes that Device Security collects from Microsoft Defender,
their names as stored in Device Security, and the Device Security fields they map to.
The third-party attribute name in Device Security refers to the attribute name
as it appears in the Assets Inventory table and in Query Engine. This follows the format
of third-party-name.attribute-name.
When viewing the attribute name in the Assets Inventory table column selector or on a
Device Details page, where the third-party name can be found as a header for the
attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the
Query Builder and in the Assets Inventory table, but under , the attribute would appear as macAddress.
Machines Devices Attributes
Device Security collects machines devices attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
isAadJoined | microsoft_defender_xdr.isAadJoined | AD Join Status | Is AAD joined |
healthStatus | microsoft_defender_xdr.healthStatus | Endpoint Protection | Health status |
"Windows Defender" | — | Endpoint Protection Vendor | "Windows Defender" |
firstSeen | microsoft_defender_xdr.firstSeen | First Seen | First seen |
computerDnsName | microsoft_defender_xdr.computerDnsName | hostname | Computer dns name |
lastIpAddress | microsoft_defender_xdr.lastIpAddress | IP Address | Last IP address |
lastSeen | microsoft_defender_xdr.lastSeen | Last Activity | Last seen |
lastMacAddress | — | MAC; id | Last MAC address |
osBuild | microsoft_defender_xdr.osBuild | OS Build Number | OS build |
osPlatform | microsoft_defender_xdr.osPlatform | OS Name; raw_os | OS platform |
version | microsoft_defender_xdr.version | OS Version | Version |
lastExternalIpAddress | microsoft_defender_xdr.lastExternalIpAddress | public_ip_address | Last external IP address |
software | microsoft_defender_xdr.software | third_party_learned_installed_software | Software |
aadDeviceId | microsoft_defender_xdr.aadDeviceId | — | Aad device ID |
agentVersion | microsoft_defender_xdr.agentVersion | — | Agent version |
defenderAvStatus | microsoft_defender_xdr.defenderAvStatus | — | Defender av status |
deviceValue | microsoft_defender_xdr.deviceValue | — | Device value |
exposureLevel | microsoft_defender_xdr.exposureLevel | — | Exposure level |
ipAddresses | microsoft_defender_xdr.ipAddresses | — | IP addresses |
isExcluded | microsoft_defender_xdr.isExcluded | — | Is excluded |
machineTags | microsoft_defender_xdr.machineTags | — | Machine tags |
managedBy | microsoft_defender_xdr.managedBy | — | Managed by |
managedByStatus | microsoft_defender_xdr.managedByStatus | — | Managed by status |
onboardingStatus | microsoft_defender_xdr.onboardingStatus | — | Onboarding status |
osVersion | microsoft_defender_xdr.osVersion | — | OS version |
rbacGroupId | microsoft_defender_xdr.rbacGroupId | — | Rbac group ID |
rbacGroupName | microsoft_defender_xdr.rbacGroupName | — | Rbac group name |
riskScore | microsoft_defender_xdr.riskScore | — | Risk score |
Machines Interfaces Attributes
Device Security collects machines interfaces attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
lastIpAddress | microsoft_defender_xdr.ipAddress | IP Address | Last IP address |
lastMacAddress | microsoft_defender_xdr.macAddress | MAC; id | Last MAC address |
ipAddresses | microsoft_defender_xdr.ipAddresses | third_party_learned_network_interfaces | IP addresses |
Machines Vulnerabilities Attributes
Device Security collects machines vulnerabilities attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute | Device Security Attribute Name | Device Security Common Attribute* | Description |
id | microsoft_defender_xdr.id | cve | Unique identifier |
cvssV3 | microsoft_defender_xdr.cvssV3 | cvss_v3base_score | Cvss v3 |
description | microsoft_defender_xdr.description | Description | Description |
firstDetected | microsoft_defender_xdr.firstDetected | detected_time | First detected |
machine_mac | microsoft_defender_xdr.machine_mac | id | MAC address of the machine |
severity | microsoft_defender_xdr.severity | risk_level | Severity |
cveSupportability | microsoft_defender_xdr.cveSupportability | — | CVE supportability |
cvssVector | microsoft_defender_xdr.cvssVector | — | Cvss vector |
epss | microsoft_defender_xdr.epss | — | Epss |
exploitInKit | microsoft_defender_xdr.exploitInKit | — | Exploit in kit |
exploitTypes | microsoft_defender_xdr.exploitTypes | — | Exploit types |
exploitVerified | microsoft_defender_xdr.exploitVerified | — | Exploit verified |
exposedMachines | microsoft_defender_xdr.exposedMachines | — | Exposed machines |
machine_id | microsoft_defender_xdr.machine_id | — | Machine ID |
name | microsoft_defender_xdr.name | — | Name of the device |
patchFirstAvailable | microsoft_defender_xdr.patchFirstAvailable | — | Patch first available |
publicExploit | microsoft_defender_xdr.publicExploit | — | Public exploit |
publishedOn | microsoft_defender_xdr.publishedOn | — | Published on |
status | microsoft_defender_xdr.status | — | Status of the device |
tags | microsoft_defender_xdr.tags | — | Tags |
updatedOn | microsoft_defender_xdr.updatedOn | — | Updated on |
* Only some attributes map to a Device Security Common Attribute.