Microsoft Defender Attribute Reference
Focus
Focus
Device Security

Microsoft Defender Attribute Reference

Table of Contents

Microsoft Defender Attribute Reference

This reference lists the attributes that Device Security collects from Microsoft Defender, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Microsoft Defender XDR, it imports endpoint and vulnerability data to enrich the device inventory. The attributes in this reference cover device records, interface data, and vulnerability findings from the Defender XDR platform.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Machines Devices Attributes

Device Security collects machines devices attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
isAadJoined
microsoft_defender_xdr.isAadJoined
AD Join Status
Is AAD joined
healthStatus
microsoft_defender_xdr.healthStatus
Endpoint Protection
Health status
"Windows Defender"
—
Endpoint Protection Vendor
"Windows Defender"
firstSeen
microsoft_defender_xdr.firstSeen
First Seen
First seen
computerDnsName
microsoft_defender_xdr.computerDnsName
hostname
Computer dns name
lastIpAddress
microsoft_defender_xdr.lastIpAddress
IP Address
Last IP address
lastSeen
microsoft_defender_xdr.lastSeen
Last Activity
Last seen
lastMacAddress
—
MAC; id
Last MAC address
osBuild
microsoft_defender_xdr.osBuild
OS Build Number
OS build
osPlatform
microsoft_defender_xdr.osPlatform
OS Name; raw_os
OS platform
version
microsoft_defender_xdr.version
OS Version
Version
lastExternalIpAddress
microsoft_defender_xdr.lastExternalIpAddress
public_ip_address
Last external IP address
software
microsoft_defender_xdr.software
third_party_learned_installed_software
Software
aadDeviceId
microsoft_defender_xdr.aadDeviceId
—
Aad device ID
agentVersion
microsoft_defender_xdr.agentVersion
—
Agent version
defenderAvStatus
microsoft_defender_xdr.defenderAvStatus
—
Defender av status
deviceValue
microsoft_defender_xdr.deviceValue
—
Device value
exposureLevel
microsoft_defender_xdr.exposureLevel
—
Exposure level
ipAddresses
microsoft_defender_xdr.ipAddresses
—
IP addresses
isExcluded
microsoft_defender_xdr.isExcluded
—
Is excluded
machineTags
microsoft_defender_xdr.machineTags
—
Machine tags
managedBy
microsoft_defender_xdr.managedBy
—
Managed by
managedByStatus
microsoft_defender_xdr.managedByStatus
—
Managed by status
onboardingStatus
microsoft_defender_xdr.onboardingStatus
—
Onboarding status
osVersion
microsoft_defender_xdr.osVersion
—
OS version
rbacGroupId
microsoft_defender_xdr.rbacGroupId
—
Rbac group ID
rbacGroupName
microsoft_defender_xdr.rbacGroupName
—
Rbac group name
riskScore
microsoft_defender_xdr.riskScore
—
Risk score

Machines Interfaces Attributes

Device Security collects machines interfaces attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
lastIpAddress
microsoft_defender_xdr.ipAddress
IP Address
Last IP address
lastMacAddress
microsoft_defender_xdr.macAddress
MAC; id
Last MAC address
ipAddresses
microsoft_defender_xdr.ipAddresses
third_party_learned_network_interfaces
IP addresses

Machines Vulnerabilities Attributes

Device Security collects machines vulnerabilities attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
id
microsoft_defender_xdr.id
cve
Unique identifier
cvssV3
microsoft_defender_xdr.cvssV3
cvss_v3base_score
Cvss v3
description
microsoft_defender_xdr.description
Description
Description
firstDetected
microsoft_defender_xdr.firstDetected
detected_time
First detected
machine_mac
microsoft_defender_xdr.machine_mac
id
MAC address of the machine
severity
microsoft_defender_xdr.severity
risk_level
Severity
cveSupportability
microsoft_defender_xdr.cveSupportability
—
CVE supportability
cvssVector
microsoft_defender_xdr.cvssVector
—
Cvss vector
epss
microsoft_defender_xdr.epss
—
Epss
exploitInKit
microsoft_defender_xdr.exploitInKit
—
Exploit in kit
exploitTypes
microsoft_defender_xdr.exploitTypes
—
Exploit types
exploitVerified
microsoft_defender_xdr.exploitVerified
—
Exploit verified
exposedMachines
microsoft_defender_xdr.exposedMachines
—
Exposed machines
machine_id
microsoft_defender_xdr.machine_id
—
Machine ID
name
microsoft_defender_xdr.name
—
Name of the device
patchFirstAvailable
microsoft_defender_xdr.patchFirstAvailable
—
Patch first available
publicExploit
microsoft_defender_xdr.publicExploit
—
Public exploit
publishedOn
microsoft_defender_xdr.publishedOn
—
Published on
status
microsoft_defender_xdr.status
—
Status of the device
tags
microsoft_defender_xdr.tags
—
Tags
updatedOn
microsoft_defender_xdr.updatedOn
—
Updated on
* Only some attributes map to a Device Security Common Attribute.