Defender-DeviceImageLoadEvents
2 ActionTypes
| ActionType | Title |
|---|---|
| any | Image load (any) |
| ImageLoaded | Image loaded |
any: Image load (any)
#Description
Image load (any)
Fields #
| Name | Description |
|---|---|
DeviceId | |
Timestamp | |
ActionType | |
FileName | |
FolderPath | |
SHA256 | |
InitiatingProcessFileName |
Detection Patterns #
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
EventType | in | FileCreated | 2 rules | kusto |
EventType | in | FileModified | 2 rules | kusto |
EventType | in | FileRenamed | 1 rule | kusto |
GlobalPrevalence | is_null | | 1 rule | kusto |
GlobalPrevalence | lt | 200 | 2 rules | kusto |
IntegrityLevel | in | High | 1 rule | kusto, splunk |
IntegrityLevel | in | System | 1 rule | kusto, splunk |
RemoteIPType | eq | Public | 1 rule | kusto |
diff | ne | [] | 1 rule | kusto |
parent_process_name | contains | regsvr32.exe | 1 rule | kusto |
parent_process_name | contains | rundll32.exe | 1 rule | kusto |
parent_process_name | in | cscript.exe | 1 rule | elastic, kusto, splunk |
parent_process_name | in | mshta.exe | 1 rule | elastic, kusto |
parent_process_name | in | wscript.exe | 1 rule | elastic, kusto, splunk |
Detection Rules #
View all rules referencing this event →Kusto #
Show 2 more (5 total)
References #
- Microsoft Defender XDR: advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceimageloadevents-table
- xdrinternals: XDR table schema https://xdrinternals.com/docs/microsoftxdr/devices/deviceimageloadevents/
ImageLoaded: Image loaded
#Description
Image loaded
Fields #
| Name | Description |
|---|---|
DeviceId | |
Timestamp | |
FileName | |
FolderPath | |
SHA256 | |
InitiatingProcessFileName |
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
GlobalPrevalence | lt | 100 | 2 rules | kusto |
GlobalPrevalence | lt | 200 | 1 rule | kusto |
EventType | in | FileRenamed | 1 rule | kusto |
Detection Rules #
View all rules referencing this event →Kusto #
References #
- Microsoft Defender XDR: advanced hunting reference https://learn.microsoft.com/en-us/defender-xdr/advanced-hunting-deviceimageloadevents-table
- xdrinternals: XDR table schema https://xdrinternals.com/docs/microsoftxdr/devices/deviceimageloadevents/