Microsoft Defender Attribute Reference
Focus
Focus
Device Security

Microsoft Defender Attribute Reference

Table of Contents

Microsoft Defender Attribute Reference

This reference lists the attributes that Device Security collects from Microsoft Defender, their names as stored in Device Security, and the Device Security fields they map to.
When Device Security integrates with Microsoft Defender XDR, it imports endpoint and vulnerability data to enrich the device inventory. The attributes in this reference cover device records, interface data, and vulnerability findings from the Defender XDR platform.
The third-party attribute name in Device Security refers to the attribute name as it appears in the Assets Inventory table and in Query Engine. This follows the format of third-party-name.attribute-name. When viewing the attribute name in the Assets Inventory table column selector or on a Device Details page, where the third-party name can be found as a header for the attributes section, then the third-party name is removed from the attribute name.
For example, micrsoft_defender_xdr.macAddress would appear in the Query Builder and in the Assets Inventory table, but under Device DetailsAttributesIntegration Specific AttributesMicrosoft Defender, the attribute would appear as macAddress.

Machines Devices Attributes

Device Security collects machines devices attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
isAadJoined
microsoft_defender_xdr.isAadJoined
AD Join Status
IsAadJoined
healthStatus
microsoft_defender_xdr.healthStatus
Endpoint Protection
HealthStatus
"Windows Defender"
Endpoint Protection Vendor
"Windows Defender"
firstSeen
microsoft_defender_xdr.firstSeen
First Seen
FirstSeen
computerDnsName
microsoft_defender_xdr.computerDnsName
hostname
ComputerDnsName
lastIpAddress
microsoft_defender_xdr.lastIpAddress
IP Address
LastIpAddress
lastSeen
microsoft_defender_xdr.lastSeen
Last Activity
LastSeen
lastMacAddress
MAC; id
LastMacAddress
osBuild
microsoft_defender_xdr.osBuild
OS Build Number
OsBuild
osPlatform
microsoft_defender_xdr.osPlatform
OS Name; raw_os
OsPlatform
version
microsoft_defender_xdr.version
OS Version
Version
lastExternalIpAddress
microsoft_defender_xdr.lastExternalIpAddress
public_ip_address
LastExternalIpAddress
software
microsoft_defender_xdr.software
third_party_learned_installed_software
Software
aadDeviceId
microsoft_defender_xdr.aadDeviceId
AadDeviceId
agentVersion
microsoft_defender_xdr.agentVersion
AgentVersion
defenderAvStatus
microsoft_defender_xdr.defenderAvStatus
DefenderAvStatus
deviceValue
microsoft_defender_xdr.deviceValue
DeviceValue
exposureLevel
microsoft_defender_xdr.exposureLevel
ExposureLevel
ipAddresses
microsoft_defender_xdr.ipAddresses
IpAddresses
isExcluded
microsoft_defender_xdr.isExcluded
IsExcluded
machineTags
microsoft_defender_xdr.machineTags
MachineTags
managedBy
microsoft_defender_xdr.managedBy
ManagedBy
managedByStatus
microsoft_defender_xdr.managedByStatus
ManagedByStatus
onboardingStatus
microsoft_defender_xdr.onboardingStatus
OnboardingStatus
osVersion
microsoft_defender_xdr.osVersion
OsVersion
rbacGroupId
microsoft_defender_xdr.rbacGroupId
RbacGroupId
rbacGroupName
microsoft_defender_xdr.rbacGroupName
RbacGroupName
riskScore
microsoft_defender_xdr.riskScore
RiskScore

Machines Interfaces Attributes

Device Security collects machines interfaces attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
lastIpAddress
microsoft_defender_xdr.ipAddress
IP Address
LastIpAddress
lastMacAddress
microsoft_defender_xdr.macAddress
MAC; id
LastMacAddress
ipAddresses
microsoft_defender_xdr.ipAddresses
third_party_learned_network_interfaces
IpAddresses

Machines Vulnerabilities Attributes

Device Security collects machines vulnerabilities attributes from Microsoft Defender. The following table lists each Microsoft Defender attribute, its name as stored in Device Security, and the Device Security field it maps to (if applicable).
Microsoft Defender Attribute
Device Security Attribute Name
Device Security Common Attribute*
Description
id
microsoft_defender_xdr.id
cve
Id
cvssV3
microsoft_defender_xdr.cvssV3
cvss_v3base_score
CvssV3
description
microsoft_defender_xdr.description
Description
Description
firstDetected
microsoft_defender_xdr.firstDetected
detected_time
FirstDetected
machine_mac
microsoft_defender_xdr.machine_mac
id
MAC address of the machine
severity
microsoft_defender_xdr.severity
risk_level
Severity
cveSupportability
microsoft_defender_xdr.cveSupportability
CveSupportability
cvssVector
microsoft_defender_xdr.cvssVector
CvssVector
epss
microsoft_defender_xdr.epss
Epss
exploitInKit
microsoft_defender_xdr.exploitInKit
ExploitInKit
exploitTypes
microsoft_defender_xdr.exploitTypes
ExploitTypes
exploitVerified
microsoft_defender_xdr.exploitVerified
ExploitVerified
exposedMachines
microsoft_defender_xdr.exposedMachines
ExposedMachines
machine_id
microsoft_defender_xdr.machine_id
Machine ID
name
microsoft_defender_xdr.name
Name of the device
patchFirstAvailable
microsoft_defender_xdr.patchFirstAvailable
PatchFirstAvailable
publicExploit
microsoft_defender_xdr.publicExploit
PublicExploit
publishedOn
microsoft_defender_xdr.publishedOn
PublishedOn
status
microsoft_defender_xdr.status
Status of the device
tags
microsoft_defender_xdr.tags
Tags
updatedOn
microsoft_defender_xdr.updatedOn
UpdatedOn
* Only some attributes map to a Device Security Common Attribute.