Defender-DeviceTvmSoftwareInventory
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Installed software inventory | Y | Y |
any: Installed software inventory
#Fields #
| Name | Description |
|---|---|
DeviceId | |
DeviceName | |
OSPlatform | |
OSVersion | |
OSArchitecture | |
SoftwareVendor | |
SoftwareName | |
SoftwareVersion | |
EndOfSupportStatus | |
EndOfSupportDate | |
ProductCodeCpe | |
MachineGroup |
Example Event #
{
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1.ludus.domain",
"OSArchitecture": "x64",
"OSPlatform": "Windows11",
"OSVersion": "10.0.22621.6060",
"ProductCodeCpe": "Not Available",
"SoftwareName": "qsetup_installation_suite",
"SoftwareVendor": "pantaray",
"SoftwareVersion": "203.0.113.10"
}
Detection Rules #
Full rule details for this event, including ATT&CK technique mappings and native queries →Kusto #