Defender-DeviceProcessEvents
| ActionType | Title | Sample | Rule | ||||
|---|---|---|---|---|---|---|---|
| any | Process activity | Y | Y | ||||
Process| Process created | Y | Y | Open | Process handle opened | N | N | |
any: Process activity
#Fields #
| Name | Description | Rules |
|---|---|---|
DeviceId | ||
DeviceName | ||
Timestamp | ||
ActionType | ||
FileName | 22 detection rules | |
FolderPath | ||
SHA1 | ||
SHA256 | 1 detection rule | |
MD5 | ||
ProcessId | ||
ProcessCommandLine | ||
AccountName | ||
AccountDomain | ||
InitiatingProcessFileName | 14 detection rules | |
InitiatingProcessFolderPath | ||
InitiatingProcessSHA256 | ||
InitiatingProcessCommandLine | ||
InitiatingProcessAccountName | ||
InitiatingProcessAccountDomain | ||
InitiatingProcessParentFileName | 2 detection rules |
Example Event #
{
"AccountDomain": "nt authority",
"AccountName": "network service",
"AccountSid": "S-1-5-20",
"ActionType": "ProcessCreated",
"CreatedProcessSessionId": 0,
"CreatedProcessSessionId@odata.type": "#Int64",
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1.ludus.domain",
"FileName": "MpCmdRun.exe",
"FileSize": 1893920,
"FileSize@odata.type": "#Int64",
"FolderPath": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.26060.3008-0\\MpCmdRun.exe",
"InitiatingProcessAccountDomain": "nt authority",
"InitiatingProcessAccountName": "system",
"InitiatingProcessAccountSid": "S-1-5-18",
"InitiatingProcessCommandLine": "\"MsMpEng.exe\"",
"InitiatingProcessCreationTime": "2026-08-01T00:56:40.6829454Z",
"InitiatingProcessFileName": "msmpeng.exe",
"InitiatingProcessFileSize": 290704,
"InitiatingProcessFileSize@odata.type": "#Int64",
"InitiatingProcessFolderPath": "c:\\programdata\\microsoft\\windows defender\\platform\\4.18.26060.3008-0\\msmpeng.exe",
"InitiatingProcessId": 4580,
"InitiatingProcessId@odata.type": "#Int64",
"InitiatingProcessIntegrityLevel": "System",
"InitiatingProcessLogonId": 0,
"InitiatingProcessLogonId@odata.type": "#Int64",
"InitiatingProcessMD5": "bfa930edc3aea262d3a74e71263f6e41",
"InitiatingProcessParentCreationTime": "2026-08-01T00:56:34.7240107Z",
"InitiatingProcessParentFileName": "services.exe",
"InitiatingProcessParentId": 1084,
"InitiatingProcessParentId@odata.type": "#Int64",
"InitiatingProcessSHA1": "d94df701fb5f2e89d902e8bcef19b8d52a12b65a",
"InitiatingProcessSHA256": "35979bf35eea166dd17d81b50ceae41043e4ae1082f4ed25383adffd9d88de4a",
"InitiatingProcessSessionId": 0,
"InitiatingProcessSessionId@odata.type": "#Int64",
"InitiatingProcessSignatureStatus": "Valid",
"InitiatingProcessSignerType": "OsVendor",
"InitiatingProcessTokenElevation": "TokenElevationTypeDefault",
"InitiatingProcessUniqueId": "9851624184873058",
"InitiatingProcessVersionInfoCompanyName": "Microsoft Corporation",
"InitiatingProcessVersionInfoFileDescription": "Antimalware Service Executable",
"InitiatingProcessVersionInfoInternalFileName": "MsMpEng.exe",
"InitiatingProcessVersionInfoOriginalFileName": "MsMpEng.exe",
"InitiatingProcessVersionInfoProductName": "Microsoft® Windows® Operating System",
"InitiatingProcessVersionInfoProductVersion": "4.18.26060.3008",
"IsInitiatingProcessRemoteSession": 0,
"IsInitiatingProcessRemoteSession@odata.type": "#SByte",
"IsProcessRemoteSession": 0,
"IsProcessRemoteSession@odata.type": "#SByte",
"LogonId": 996,
"LogonId@odata.type": "#Int64",
"MD5": "50748135411ab2227a961757d96fb456",
"ProcessCommandLine": "\"MpCmdRun.exe\" GetDeviceTicket -AccessKey 3474F9D5-96F4-6236-8080-E8299426B055 ",
"ProcessCreationTime": "2026-08-01T09:19:44.5639533Z",
"ProcessId": 10356,
"ProcessId@odata.type": "#Int64",
"ProcessIntegrityLevel": "System",
"ProcessTokenElevation": "TokenElevationTypeDefault",
"ProcessUniqueId": "9851624184879170",
"ProcessVersionInfoCompanyName": "Microsoft Corporation",
"ProcessVersionInfoFileDescription": "Microsoft Malware Protection Command Line Utility",
"ProcessVersionInfoInternalFileName": "MpCmdRun",
"ProcessVersionInfoOriginalFileName": "MpCmdRun.exe",
"ProcessVersionInfoProductName": "Microsoft® Windows® Operating System",
"ProcessVersionInfoProductVersion": "4.18.26060.3008",
"ReportId": 14402,
"ReportId@odata.type": "#Int64",
"SHA1": "b92bf73d510217422e180fd7a09dafe6410f90e0",
"SHA256": "556d0de327089f436d461486b953a97dbd26c458c2c4f01d59d6d4217025cf26",
"Timestamp": "2026-08-01T09:19:44.570542Z"
}
Detection Patterns #
Lateral Movement: SMB/Windows Admin Shares
Lateral Movement: Windows Remote Management
1 rule
Show All Detection Patterns
Execution: Exploitation for Client Execution
Persistence: Windows Service
1 rule
Persistence: Compromise Host Software Binary
1 rule
Stealth: Create Process with Token
Lateral Movement: Remote Desktop Protocol
1 rule
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
file_name (kusto rule field) | eq | powershell.exe | 3 rules | kusto |
file_name (kusto rule field) | in | cmd.exe | 4 rules | kusto |
file_name (kusto rule field) | in | at.exe | 3 rules | kusto |
file_name (kusto rule field) | in | bitsadmin.exe | 3 rules | kusto |
file_name (kusto rule field) | in | certutil.exe | 3 rules | kusto |
file_name (kusto rule field) | in | cmstp.exe | 3 rules | kusto |
file_name (kusto rule field) | in | cscript.exe | 3 rules | kusto |
file_name (kusto rule field) | in | installutil.exe | 3 rules | kusto |
file_name (kusto rule field) | in | mavinject.exe | 3 rules | kusto |
file_name (kusto rule field) | in | msbuild.exe | 3 rules | kusto |
file_name (kusto rule field) | in | mshta.exe | 3 rules | kusto |
file_name (kusto rule field) | in | msiexec.exe | 3 rules | kusto |
ActionType (kusto rule field) | eq | InboundConnectionAccepted | 3 rules | kusto |
ActionType (kusto rule field) | eq | processcreated | 3 rules | kusto |
IntegrityLevel (kusto rule field) | eq | High | 3 rules | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
Refer to our M365 blog for details on use during the Solorigate attack: https://www.microsoft.com/security/blog/2021/01/20/deep-dive-into-the-solorigate-second-stage-activation-from-sunburst-to-teardrop-and-raindrop/T1204T1003, T1569
ProcessCreated: Process created
#Fields #
| Name | Description |
|---|---|
DeviceId | |
Timestamp | |
FileName | |
FolderPath | |
SHA256 | |
ProcessCommandLine | |
AccountName | |
InitiatingProcessFileName | |
InitiatingProcessCommandLine |
Example Event #
{
"AccountDomain": "nt authority",
"AccountName": "network service",
"AccountSid": "S-1-5-20",
"ActionType": "ProcessCreated",
"CreatedProcessSessionId": 0,
"CreatedProcessSessionId@odata.type": "#Int64",
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1.ludus.domain",
"FileName": "MpCmdRun.exe",
"FileSize": 1893920,
"FileSize@odata.type": "#Int64",
"FolderPath": "C:\\ProgramData\\Microsoft\\Windows Defender\\Platform\\4.18.26060.3008-0\\MpCmdRun.exe",
"InitiatingProcessAccountDomain": "nt authority",
"InitiatingProcessAccountName": "system",
"InitiatingProcessAccountSid": "S-1-5-18",
"InitiatingProcessCommandLine": "\"MsMpEng.exe\"",
"InitiatingProcessCreationTime": "2026-08-01T00:56:40.6829454Z",
"InitiatingProcessFileName": "msmpeng.exe",
"InitiatingProcessFileSize": 290704,
"InitiatingProcessFileSize@odata.type": "#Int64",
"InitiatingProcessFolderPath": "c:\\programdata\\microsoft\\windows defender\\platform\\4.18.26060.3008-0\\msmpeng.exe",
"InitiatingProcessId": 4580,
"InitiatingProcessId@odata.type": "#Int64",
"InitiatingProcessIntegrityLevel": "System",
"InitiatingProcessLogonId": 0,
"InitiatingProcessLogonId@odata.type": "#Int64",
"InitiatingProcessMD5": "bfa930edc3aea262d3a74e71263f6e41",
"InitiatingProcessParentCreationTime": "2026-08-01T00:56:34.7240107Z",
"InitiatingProcessParentFileName": "services.exe",
"InitiatingProcessParentId": 1084,
"InitiatingProcessParentId@odata.type": "#Int64",
"InitiatingProcessSHA1": "d94df701fb5f2e89d902e8bcef19b8d52a12b65a",
"InitiatingProcessSHA256": "35979bf35eea166dd17d81b50ceae41043e4ae1082f4ed25383adffd9d88de4a",
"InitiatingProcessSessionId": 0,
"InitiatingProcessSessionId@odata.type": "#Int64",
"InitiatingProcessSignatureStatus": "Valid",
"InitiatingProcessSignerType": "OsVendor",
"InitiatingProcessTokenElevation": "TokenElevationTypeDefault",
"InitiatingProcessUniqueId": "9851624184873058",
"InitiatingProcessVersionInfoCompanyName": "Microsoft Corporation",
"InitiatingProcessVersionInfoFileDescription": "Antimalware Service Executable",
"InitiatingProcessVersionInfoInternalFileName": "MsMpEng.exe",
"InitiatingProcessVersionInfoOriginalFileName": "MsMpEng.exe",
"InitiatingProcessVersionInfoProductName": "Microsoft® Windows® Operating System",
"InitiatingProcessVersionInfoProductVersion": "4.18.26060.3008",
"IsInitiatingProcessRemoteSession": 0,
"IsInitiatingProcessRemoteSession@odata.type": "#SByte",
"IsProcessRemoteSession": 0,
"IsProcessRemoteSession@odata.type": "#SByte",
"LogonId": 996,
"LogonId@odata.type": "#Int64",
"MD5": "50748135411ab2227a961757d96fb456",
"ProcessCommandLine": "\"MpCmdRun.exe\" GetDeviceTicket -AccessKey 3474F9D5-96F4-6236-8080-E8299426B055 ",
"ProcessCreationTime": "2026-08-01T09:19:44.5639533Z",
"ProcessId": 10356,
"ProcessId@odata.type": "#Int64",
"ProcessIntegrityLevel": "System",
"ProcessTokenElevation": "TokenElevationTypeDefault",
"ProcessUniqueId": "9851624184879170",
"ProcessVersionInfoCompanyName": "Microsoft Corporation",
"ProcessVersionInfoFileDescription": "Microsoft Malware Protection Command Line Utility",
"ProcessVersionInfoInternalFileName": "MpCmdRun",
"ProcessVersionInfoOriginalFileName": "MpCmdRun.exe",
"ProcessVersionInfoProductName": "Microsoft® Windows® Operating System",
"ProcessVersionInfoProductVersion": "4.18.26060.3008",
"ReportId": 14402,
"ReportId@odata.type": "#Int64",
"SHA1": "b92bf73d510217422e180fd7a09dafe6410f90e0",
"SHA256": "556d0de327089f436d461486b953a97dbd26c458c2c4f01d59d6d4217025cf26",
"Timestamp": "2026-08-01T09:19:44.570542Z"
}
Detection Patterns #
1 rule
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ActionType (kusto rule field) | eq | processcreated | 6 rules | kusto |
ActionType (kusto rule field) | eq | ProcessCreated | 2 rules | kusto |
ActionType (kusto rule field) | eq | ConnectionSuccess | 1 rule | kusto |
ActionType (kusto rule field) | eq | FileRenamed | 1 rule | kusto |
ActionType (kusto rule field) | eq | ListeningConnectionCreated | 1 rule | kusto |
ActionType (kusto rule field) | eq | NamedPipeEvent | 1 rule | kusto |
GlobalPrevalence (kusto rule field) | is_null | | 1 rule | kusto |
GlobalPrevalence (kusto rule field) | lt | 200 | 2 rules | kusto |
GlobalPrevalence (kusto rule field) | lt | 100 | 1 rule | kusto |
GlobalPrevalence (kusto rule field) | lt | 250 | 1 rule | kusto |
sha1 (kusto rule field) | is_not_null | | 2 rules | kusto |
DestinationPort (kusto rule field) | in | 389 | 1 rule | kusto |
DestinationPort (kusto rule field) | in | 636 | 1 rule | kusto |
IsCertificateValid (kusto rule field) | ne | 1 | 1 rule | kusto |
OriginalFileName (kusto rule field) | eq | browsercore.exe | 1 rule | kusto |
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #
T1036, T1036.003T1053, T1053.005