Defender-DisruptionAndResponseEvents

ActionTypeTitleSampleRule
anyAttack disruption and predictive shielding activityYN
ContainedRestrictedUserSmbFileOpenBlockedContained restricted user SMB file open blockedNN
ContainedUserLogonBlockedContained user logon blockedYN
ContainedUserLogonBlockedByDomainControllerContained user logon blocked by domain controllerNN
ContainedUserRemoteDesktopSessionDisconnectedContained user remote desktop session disconnectedNN
ContainedUserRemoteDesktopSessionStoppedContained user remote desktop session stoppedNN
ContainedUserRpcAccessBlockedContained user RPC access blockedYN
ContainedUserSmbFileOpenBlockedContained user SMB file open blockedYN
ContainedUserSmbFileOpenBlockedAggregationContained user SMB file open blocked (aggregated)NN
ContainedUserSmbSessionStoppedContained user SMB session stoppedNN
GroupPolicyAccessBlockedGroup policy access blockedNN
GroupPolicyHardeningPolicyAppliedGroup policy hardening policy appliedNN
GroupPolicyHardeningPolicyRemovedGroup policy hardening policy removedNN
SafeBootBlockedSafe boot blockedNN
SafeBootGuardPolicyAppliedSafe boot guard policy appliedNN
SafeBootGuardPolicyRemovedSafe boot guard policy removedNN

any: Attack disruption and predictive shielding activity

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

Example Event #

{
  "ActionType": "ContainedUserLogonBlocked",
  "AuthenticationProtocol": "Kerberos",
  "DataSource": "Microsoft Defender for Endpoint",
  "DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "DeviceName": "jd-win11-22h2-1",
  "DomainName": "ludus.domain",
  "InitiatingProcessId": 0,
  "InitiatingProcessId@odata.type": "#Int64",
  "IpAddress": "10.2.10.11",
  "LogonType": "Network",
  "PolicyName": "ContainUser",
  "Port": 55040,
  "ReportId": 17767,
  "ReportId@odata.type": "#Int64",
  "ReportType": "Prevented",
  "SourceDeviceName": "-",
  "SourceUserDomainName": "LUDUS.DOMAIN",
  "SourceUserName": "domainadmin",
  "SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "TargetDeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "TargetDeviceName": "jd-win11-22h2-1",
  "TargetDomainName": "ludus.domain",
  "Timestamp": "2026-07-26T01:09:53.5900591Z"
}

ContainedRestrictedUserSmbFileOpenBlocked: Contained restricted user SMB file open blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

ContainedUserLogonBlocked: Contained user logon blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

Example Event #

{
  "ActionType": "ContainedUserLogonBlocked",
  "AuthenticationProtocol": "Kerberos",
  "DataSource": "Microsoft Defender for Endpoint",
  "DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "DeviceName": "jd-win11-22h2-1",
  "DomainName": "ludus.domain",
  "InitiatingProcessId": 0,
  "InitiatingProcessId@odata.type": "#Int64",
  "IpAddress": "10.2.10.11",
  "LogonType": "Network",
  "PolicyName": "ContainUser",
  "Port": 55040,
  "ReportId": 17767,
  "ReportId@odata.type": "#Int64",
  "ReportType": "Prevented",
  "SourceDeviceName": "-",
  "SourceUserDomainName": "LUDUS.DOMAIN",
  "SourceUserName": "domainadmin",
  "SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "TargetDeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
  "TargetDeviceName": "jd-win11-22h2-1",
  "TargetDomainName": "ludus.domain",
  "Timestamp": "2026-07-26T01:09:53.5900591Z"
}

ContainedUserLogonBlockedByDomainController: Contained user logon blocked by domain controller

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

ContainedUserRemoteDesktopSessionDisconnected: Contained user remote desktop session disconnected

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

ContainedUserRemoteDesktopSessionStopped: Contained user remote desktop session stopped

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

ContainedUserRpcAccessBlocked: Contained user RPC access blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

Example Event #

{
  "ActionType": "ContainedUserRpcAccessBlocked",
  "AuthenticationProtocol": "Unknown",
  "DataSource": "Microsoft Defender for Endpoint",
  "DeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
  "DeviceName": "jd-dc01-2022",
  "DomainName": "ludus.domain",
  "InitiatingProcessFileName": "lsass.exe",
  "InitiatingProcessId": 1268,
  "InitiatingProcessId@odata.type": "#Int64",
  "InterfaceFriendlyName": "Directory Replication Service (DRS)",
  "InterfaceUuid": "e3514235-4b06-11d1-ab04-00c04fc2dcd2",
  "LogonId": 467309262,
  "LogonId@odata.type": "#Int64",
  "PolicyName": "ContainUser",
  "ReportId": 307127,
  "ReportId@odata.type": "#Int64",
  "ReportType": "Prevented",
  "Service": "RPC",
  "SourceIpAddress": "::1",
  "SourcePort": 55181,
  "SourceUserDomainName": "ludus",
  "SourceUserName": "domainadmin",
  "SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "TargetDeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
  "TargetDeviceName": "jd-dc01-2022",
  "TargetDomainName": "ludus.domain",
  "Timestamp": "2026-07-26T01:16:28.9498116Z"
}

ContainedUserSmbFileOpenBlocked: Contained user SMB file open blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

Example Event #

{
  "ActionType": "ContainedUserSmbFileOpenBlocked",
  "DataSource": "Microsoft Defender for Endpoint",
  "DeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
  "DeviceName": "jd-dc01-2022",
  "DomainName": "ludus.domain",
  "FileName": "\\Device\\HarddiskVolume1\\Windows\\SYSVOL\\sysvol\\ludus.domain\\Policies\\{7741B396-B5B8-4AD4-ABD2-654E62F72C1B}",
  "InitiatingProcessFileName": "ntoskrnl.exe",
  "InitiatingProcessId": 4,
  "InitiatingProcessId@odata.type": "#Int64",
  "PolicyName": "ContainUser",
  "ReportId": 307643,
  "ReportId@odata.type": "#Int64",
  "ReportType": "Blocked",
  "Service": "SMB",
  "ShareName": "SYSVOL",
  "SourceIpAddress": "::1",
  "SourcePort": 55220,
  "SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
  "TargetDeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
  "TargetDeviceName": "jd-dc01-2022",
  "TargetDomainName": "ludus.domain",
  "Timestamp": "2026-07-26T01:17:27.0174029Z"
}

ContainedUserSmbFileOpenBlockedAggregation: Contained user SMB file open blocked (aggregated)

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

ContainedUserSmbSessionStopped: Contained user SMB session stopped

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

GroupPolicyAccessBlocked: Group policy access blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

GroupPolicyHardeningPolicyApplied: Group policy hardening policy applied

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

GroupPolicyHardeningPolicyRemoved: Group policy hardening policy removed

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

SafeBootBlocked: Safe boot blocked

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

SafeBootGuardPolicyApplied: Safe boot guard policy applied

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

SafeBootGuardPolicyRemoved: Safe boot guard policy removed

#
Table
DisruptionAndResponseEvents

Fields #

NameDescription
Timestamp
ActionType
DeviceId
DeviceName
SourceDeviceId
SourceDeviceName
TargetDeviceId
TargetDeviceName
InitiatingProcessFileName
SourceUserSid
SourceUserName
SourceUserDomainName
SourceIpAddress
IpAddress
LogonTypeLogon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive).
AuthenticationProtocol
Service
FileName
PolicyName
ReportType

References #