StudyToCert

All certifications / SC-200 / Lessons

Microsoft Certified: Security Operations Analyst Associate SC-200 · Domain 3: Perform threat hunting

Advanced hunting schema: DeviceProcessEvents, DeviceNetworkEvents, DeviceLogonEvents, EmailEvents, EmailUrlInfo, IdentityLogonEvents, CloudAppEvents, AlertInfo and AlertEvidence

▶ Watch the overview video

Last reviewed September 30, 2026 · Leer en español

Advanced hunting in the Defender portal exposes Defender XDR data as tables grouped by source. Knowing which table holds which kind of event, and how tables link, is the difference between a quick hunt and a frustrating one. The schema reference in the portal, on the left side of the advanced hunting page, lists every table and column with descriptions and sample queries. The time column in these tables is Timestamp, and advanced hunting keeps about 30 days of Defender data; for longer history, the data must be in Sentinel or the data lake. Device tables come from Defender for Endpoint. DeviceProcessEvents records process creation: FileName, FolderPath, ProcessCommandLine, the SHA256 hash, the account, and the parent through the InitiatingProcess columns such as InitiatingProcessFileName and InitiatingProcessCommandLine. It is where you hunt for encoded PowerShell, living-off-the-land binaries or Office apps spawning shells. DeviceNetworkEvents records network connections: RemoteIP, RemotePort, RemoteUrl, the ActionType (for example ConnectionSuccess or ConnectionFailed) and the initiating process. DeviceLogonEvents records logons to devices, with AccountName, LogonType (such as Interactive, Network or RemoteInteractive) and ActionType showing success or failure. Other device tables cover files (DeviceFileEvents), registry (DeviceRegistryEvents), images loaded and general events (DeviceEvents). The ActionType column appears in most tables and describes what kind of event each row is, so running summarize count() by ActionType is a good first step with any unfamiliar table.

Free account

Keep reading for free

Create a free StudyToCert account to read the rest of this lesson: 7 more sections, 6 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.

Sign up free Log in

Study SC-200 for free
A week-by-week plan with every lesson, quizzes, checkpoint tests, a practice exam and hands-on labs.
Open the SC-200 study plan