Defender-DisruptionAndResponseEvents
any: Attack disruption and predictive shielding activity
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
Example Event #
{
"ActionType": "ContainedUserLogonBlocked",
"AuthenticationProtocol": "Kerberos",
"DataSource": "Microsoft Defender for Endpoint",
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1",
"DomainName": "ludus.domain",
"InitiatingProcessId": 0,
"InitiatingProcessId@odata.type": "#Int64",
"IpAddress": "10.2.10.11",
"LogonType": "Network",
"PolicyName": "ContainUser",
"Port": 55040,
"ReportId": 17767,
"ReportId@odata.type": "#Int64",
"ReportType": "Prevented",
"SourceDeviceName": "-",
"SourceUserDomainName": "LUDUS.DOMAIN",
"SourceUserName": "domainadmin",
"SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"TargetDeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"TargetDeviceName": "jd-win11-22h2-1",
"TargetDomainName": "ludus.domain",
"Timestamp": "2026-07-26T01:09:53.5900591Z"
}
ContainedRestrictedUserSmbFileOpenBlocked: Contained restricted user SMB file open blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
ContainedUserLogonBlocked: Contained user logon blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
Example Event #
{
"ActionType": "ContainedUserLogonBlocked",
"AuthenticationProtocol": "Kerberos",
"DataSource": "Microsoft Defender for Endpoint",
"DeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"DeviceName": "jd-win11-22h2-1",
"DomainName": "ludus.domain",
"InitiatingProcessId": 0,
"InitiatingProcessId@odata.type": "#Int64",
"IpAddress": "10.2.10.11",
"LogonType": "Network",
"PolicyName": "ContainUser",
"Port": 55040,
"ReportId": 17767,
"ReportId@odata.type": "#Int64",
"ReportType": "Prevented",
"SourceDeviceName": "-",
"SourceUserDomainName": "LUDUS.DOMAIN",
"SourceUserName": "domainadmin",
"SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"TargetDeviceId": "99ffb4eafd9c8fb310527d15d666a58ab4661114",
"TargetDeviceName": "jd-win11-22h2-1",
"TargetDomainName": "ludus.domain",
"Timestamp": "2026-07-26T01:09:53.5900591Z"
}
ContainedUserLogonBlockedByDomainController: Contained user logon blocked by domain controller
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
ContainedUserRemoteDesktopSessionDisconnected: Contained user remote desktop session disconnected
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
ContainedUserRemoteDesktopSessionStopped: Contained user remote desktop session stopped
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
ContainedUserRpcAccessBlocked: Contained user RPC access blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
Example Event #
{
"ActionType": "ContainedUserRpcAccessBlocked",
"AuthenticationProtocol": "Unknown",
"DataSource": "Microsoft Defender for Endpoint",
"DeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
"DeviceName": "jd-dc01-2022",
"DomainName": "ludus.domain",
"InitiatingProcessFileName": "lsass.exe",
"InitiatingProcessId": 1268,
"InitiatingProcessId@odata.type": "#Int64",
"InterfaceFriendlyName": "Directory Replication Service (DRS)",
"InterfaceUuid": "e3514235-4b06-11d1-ab04-00c04fc2dcd2",
"LogonId": 467309262,
"LogonId@odata.type": "#Int64",
"PolicyName": "ContainUser",
"ReportId": 307127,
"ReportId@odata.type": "#Int64",
"ReportType": "Prevented",
"Service": "RPC",
"SourceIpAddress": "::1",
"SourcePort": 55181,
"SourceUserDomainName": "ludus",
"SourceUserName": "domainadmin",
"SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"TargetDeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
"TargetDeviceName": "jd-dc01-2022",
"TargetDomainName": "ludus.domain",
"Timestamp": "2026-07-26T01:16:28.9498116Z"
}
ContainedUserSmbFileOpenBlocked: Contained user SMB file open blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
Example Event #
{
"ActionType": "ContainedUserSmbFileOpenBlocked",
"DataSource": "Microsoft Defender for Endpoint",
"DeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
"DeviceName": "jd-dc01-2022",
"DomainName": "ludus.domain",
"FileName": "\\Device\\HarddiskVolume1\\Windows\\SYSVOL\\sysvol\\ludus.domain\\Policies\\{7741B396-B5B8-4AD4-ABD2-654E62F72C1B}",
"InitiatingProcessFileName": "ntoskrnl.exe",
"InitiatingProcessId": 4,
"InitiatingProcessId@odata.type": "#Int64",
"PolicyName": "ContainUser",
"ReportId": 307643,
"ReportId@odata.type": "#Int64",
"ReportType": "Blocked",
"Service": "SMB",
"ShareName": "SYSVOL",
"SourceIpAddress": "::1",
"SourcePort": 55220,
"SourceUserSid": "S-1-5-21-1006758700-2167138679-1475694448-1105",
"TargetDeviceId": "ec2cc6b53848cc3454a79df3684465dee27fec8c",
"TargetDeviceName": "jd-dc01-2022",
"TargetDomainName": "ludus.domain",
"Timestamp": "2026-07-26T01:17:27.0174029Z"
}
ContainedUserSmbFileOpenBlockedAggregation: Contained user SMB file open blocked (aggregated)
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
ContainedUserSmbSessionStopped: Contained user SMB session stopped
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
GroupPolicyAccessBlocked: Group policy access blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
GroupPolicyHardeningPolicyApplied: Group policy hardening policy applied
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
GroupPolicyHardeningPolicyRemoved: Group policy hardening policy removed
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
SafeBootBlocked: Safe boot blocked
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
SafeBootGuardPolicyApplied: Safe boot guard policy applied
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |
SafeBootGuardPolicyRemoved: Safe boot guard policy removed
#Fields #
| Name | Description |
|---|---|
Timestamp | |
ActionType | |
DeviceId | |
DeviceName | |
SourceDeviceId | |
SourceDeviceName | |
TargetDeviceId | |
TargetDeviceName | |
InitiatingProcessFileName | |
SourceUserSid | |
SourceUserName | |
SourceUserDomainName | |
SourceIpAddress | |
IpAddress | |
LogonType | Logon type code (2=Interactive, 3=Network, 4=Batch, 5=Service, 7=Unlock, 8=NetworkCleartext, 9=NewCredentials, 10=RemoteInteractive, 11=CachedInteractive). |
AuthenticationProtocol | |
Service | |
FileName | |
PolicyName | |
ReportType |