Defender-DeviceTvmSoftwareVulnerabilities
| ActionType | Title | Sample | Rule |
|---|---|---|---|
| any | Software vulnerabilities on devices | Y | Y |
any: Software vulnerabilities on devices
#Fields #
| Name | Description |
|---|---|
DeviceId | |
DeviceName | |
OSPlatform | |
OSVersion | |
OSArchitecture | |
SoftwareVendor | |
SoftwareName | |
SoftwareVersion | |
CveId | |
VulnerabilitySeverityLevel | |
RecommendedSecurityUpdate | |
RecommendedSecurityUpdateId | |
CveTags | |
CveMitigationStatus | |
AadDeviceId | |
MachineGroup |
Example Event #
{
"AadDeviceId": "db412646-80ba-4176-935f-7450b35979ee",
"CveId": "CVE-2026-48092",
"CveTags@odata.type": "#Collection(String)",
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1.ludus.domain",
"OSArchitecture": "x64",
"OSPlatform": "Windows11",
"OSVersion": "10.0.22621.6060",
"SoftwareName": "7-zip",
"SoftwareVendor": "7-zip",
"SoftwareVersion": "25.01.0.0",
"VulnerabilitySeverityLevel": "Medium"
}
Detection Patterns #
Initial Access: Exploit Public-Facing Application
Defender-DeviceNetworkEvents InboundConnectionAccepted: Inbound connection acceptedORDefender-DeviceTvmSoftwareVulnerabilities any: Software vulnerabilities on devicesORDefender-DeviceTvmSoftwareVulnerabilitiesKB any: Vulnerability knowledge baseORDefender-ExposureGraphNodes any: Exposure graph nodes
Common Indicators #
Field/value combinations most frequently checked by detection rules targeting this event, derived from cross-vendor predicate analysis.
| Field | Kind | Value | Rules | Vendors |
|---|---|---|---|---|
ActionType (kusto rule field) | contains | inboundconnection | 1 rule | kusto |
CommandLine (kusto rule field) | contains | .webp | 1 rule | kusto |
RemoteIPType (kusto rule field) | eq | Public | 1 rule | kusto |
type (kusto rule field) | eq | DeviceInventoryId | 1 rule | kusto |