Device Alerts


Description

This query lists all the alerts that have triggered based on a specific UPN in the selected TimeFrame.

Query · kql

let Upn = 'user@test.com';
let TimeFrame = 7d;
AlertEvidence
| where Timestamp > ago(TimeFrame)
| where EntityType in~ ('User', 'Mailbox')
| summarize arg_max(Timestamp, *) by AlertId
| project AlertId, EntityType
| join kind=inner AlertInfo on AlertId
| extend AlertLink = strcat('https://security.microsoft.com/alerts/', AlertId)
| project-reorder Timestamp, EntityType, Title, Category, Severity, DetectionSource, AlertLink
| sort by Timestamp desc
Raw source Device Alerts · KQL
Esc
Published by Bert-JanP/Hunting-Queries-Detection-Rules ↗, licensed under BSD 3-Clause ↗. Reproduced here unmodified.
# Device Alerts

## Query Information

#### Description
This query lists all the alerts that have triggered based on a specific UPN in the selected *TimeFrame*.

## Defender XDR
```KQL
let Upn = 'user@test.com';
let TimeFrame = 7d;
AlertEvidence
| where Timestamp > ago(TimeFrame)
| where EntityType in~ ('User', 'Mailbox')
| summarize arg_max(Timestamp, *) by AlertId
| project AlertId, EntityType
| join kind=inner AlertInfo on AlertId
| extend AlertLink = strcat('https://security.microsoft.com/alerts/', AlertId)
| project-reorder Timestamp, EntityType, Title, Category, Severity, DetectionSource, AlertLink
| sort by Timestamp desc
```

Detection rules belong to the projects that publish them and remain under their own licenses. This site indexes and links to them; it claims no rights in them.