{"id":22240,"date":"2020-10-01T17:28:59","date_gmt":"2020-10-01T16:28:59","guid":{"rendered":"https:\/\/aidanfinn.com\/?p=22240"},"modified":"2020-10-08T10:13:26","modified_gmt":"2020-10-08T09:13:26","slug":"monitoring-alerting-for-windows-defender-in-azure-vms","status":"publish","type":"post","link":"https:\/\/aidanfinn.com\/?p=22240","title":{"rendered":"Monitoring &#038; Alerting for Windows Defender in Azure VMs"},"content":{"rendered":"<p>In this post, I will explain how one can monitor Windows Defender and create incidents for it with Azure VMs.<\/p>\n<h2>Background<\/h2>\n<p>Windows Defender is built into Windows Server 2016 and Windows Server 2019. It&#8217;s free and pretty decent. But it surprises me how many of my customers (all) choose Defender over third-parties for their Azure VMs &#8230; with no coaching\/encouragement from me or my colleagues. There is an integration with the control plane using the antimalwareagent extension. But the level of management is poor-none. There is a Log Analytics solution, but solutions are deprecated and, last time I checked, it required the workspace to be in per-node pricing mode. So I needed something different to operationalise Windows Defender with Azure VMs.<\/p>\n<h2>Data<\/h2>\n<p>At work, we always deploy the Log Analytics extension with all VMs &#8211; along with the antimalware extension and a bunch of others. We also enable data collection in Azure Security Center. We use a single Log Analytics workspace to enable the correlation of data and easy reporting\/management.<\/p>\n<p>I recently found out that a table in Log Analytics called ProtectionStatus contains a &#8220;heartbeat&#8221; record for Windows Defender. Approximately every hour, a record is stored in this table for every VM running Windows Defender. In there, you&#8217;ll find some columns such as:<\/p>\n<ul>\n<li><strong>DeviceName<\/strong>: The computer name<\/li>\n<li><strong>ThreatStatusRank<\/strong>: A code indicating the health of the device according to defender:\n<ul>\n<li>150: Health<\/li>\n<li>470: Unknown (no extension\/Defender)<\/li>\n<li>350: Quarantined malware<\/li>\n<li>550: Active malware<\/li>\n<\/ul>\n<\/li>\n<li><strong>ThreatStatus<\/strong>: A description for the above code<\/li>\n<li><strong>ThreatStatusDetails<\/strong>: A longer description<\/li>\n<li>And more &#8230;<\/li>\n<\/ul>\n<p>So you can see that you can search this table for malware infection records. First thing, though, is to filter out the machines\/records reporting that there is no Defender (Linux machines, for example):<\/p>\n<pre class=\"lang:default decode:true\">let all_windows_vms =\r\nHeartbeat\r\n| where TimeGenerated &gt; now(-7d)\r\n| where OSType == 'Windows'\r\n| summarize makeset(Resource);\r\nProtectionStatus\r\n| where Resource in (all_windows_vms)\r\n| sort by TimeGenerated desc<\/pre>\n<p>The above will find all active Windows VMs that have been reporting to Log Analytics via the extension heartbeat. Then we&#8217;ll store that data in a set, and search that set. Now we can extend that search, for example finding all machines with a non-healthy state (150):<\/p>\n<pre class=\"lang:default decode:true \">let all_windows_vms = Heartbeat\r\n| where TimeGenerated &gt; now(-7d)\r\n| where OSType == 'Windows'\r\n| summarize makeset(Resource);\r\nProtectionStatus\r\n| where Resource in (all_windows_vms)\r\n| where ThreatStatusRank &lt;&gt; 150\r\n| sort by TimeGenerated desc<\/pre>\n<h2>Testing<\/h2>\n<p>All the tech content here will be useless without data. So you&#8217;ll need some data! Search for the Eicar test string\/file and start &#8220;infecting&#8221; machines &#8211; be sure to let people know if there are people monitoring the environment first.<\/p>\n<h2>Security Center<\/h2>\n<p>Security Center will record incidents for you:<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-22248\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents.png\" alt=\"\" width=\"550\" height=\"170\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents.png 2205w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-300x93.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-1024x317.png 1024w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-768x238.png 768w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-1536x475.png 1536w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-2048x633.png 2048w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/SecurityCenterIncidents-600x186.png 600w\" sizes=\"auto, (max-width: 550px) 85vw, 550px\" \/><\/a><\/p>\n<p>You will get email alerts if you have configured notifications in the subscription&#8217;s Security Center settings. Make sure the threshold is set to LOW.<\/p>\n<p>If you want an alternative form of alert then you can use a Log Analytics alert (Scheduled Query Alert resource type) based on the below basic query:<\/p>\n<pre class=\"lang:default decode:true \">SecurityAlert \r\n| where TimeGenerated &gt; now(-5m)\r\n| where VendorName == 'Microsoft Antimalware'<\/pre>\n<p>The above query will search for Windows Defender alerts stored in Log Analytics (by Security Center) in the last 5 minutes. If the threshold is freater than 0 then you can trigger an Azure Monitor Action Group to tell whomever or start whatever task you want.<\/p>\n<h2>Workbooks<\/h2>\n<p>Armed with the ability to query the ProtectionStatus table, you can create your own visualisations for easy reporting on Windows Defender across many machines.<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-22252\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook.png\" alt=\"\" width=\"550\" height=\"135\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook.png 2286w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-300x74.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-1024x251.png 1024w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-768x188.png 768w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-1536x377.png 1536w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-2048x503.png 2048w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/WindowsDefenderWorkbook-600x147.png 600w\" sizes=\"auto, (max-width: 550px) 85vw, 550px\" \/><\/a><\/p>\n<p>&nbsp;<\/p>\n<p>The pie chart is made using this query:<\/p>\n<pre class=\"lang:default decode:true \">let all_windows_vms =\r\nHeartbeat\r\n| where TimeGenerated &gt; now(-7d)\r\n| where OSType == 'Windows'\r\n| summarize makeset(Resource);\r\nProtectionStatus\r\n| where TimeGenerated &gt; now(-7d)\r\n| where Resource in (all_windows_vms)\r\n| where ThreatStatusRank &lt;&gt; '150'\r\n| summarize count(Threat) by Threat<\/pre>\n<p>With some reading and practice, you can make a really fancy workbook.<\/p>\n<h2>Azure Sentinel<\/h2>\n<p><em>I have enabled the Entity Behavior preview.<\/em><\/p>\n<p>Azure Sentinel is supposed to be the central place to monitor all security events, hunt for issues, and where to start investigations &#8211; that latter thanks to the new Entity Behavior feature. Azure Sentinel is powered by Log Analytics &#8211; if you have data in there then you can query that data, correlate it, and do some clever things.<\/p>\n<p>We have a query that can search for malware incidents reported by Windows Defender. What we will do is create a new Analytic Rule that will run every 5 minutes using 5 minutes of data. If the results exceed 0 (threshold greater than 0) then we will create an incident.<\/p>\n<pre class=\"lang:default decode:true \">let all_windows_vms =\r\nHeartbeat\r\n| where TimeGenerated &gt; now(-7d)\r\n| where OSType == 'Windows'\r\n| summarize makeset(Resource);\r\nProtectionStatus\r\n| where TimeGenerated &gt; now(-5m)\r\n| where Resource in (all_windows_vms)\r\n| where ThreatStatus &lt;&gt; 'No threats detected' or ThreatStatusRank &lt;&gt; '150' or Threat &lt;&gt; ''\r\n| sort by Resource asc\r\n| extend HostCustomEntity = Computer<\/pre>\n<p>The last line is used to identity an entity. Optionally, we can associate a logic app for an automated response. Once that first malware detection is found:<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-22257\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents.png\" alt=\"\" width=\"550\" height=\"178\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents.png 1782w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents-300x97.png 300w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents-1024x332.png 1024w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents-768x249.png 768w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents-1536x497.png 1536w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidents-600x194.png 600w\" sizes=\"auto, (max-width: 550px) 85vw, 550px\" \/><\/a><\/p>\n<p>You can do the usual operational stuff with these incidents. Note that this data is recorded and your effectiveness as a security organisation is visible in the Security Efficiency Workbook in Azure Sentinel &#8211; even the watchers are watched! If you open an incident you can click investigate which opens a new Investigation screen that leverages the Entity Behavior data. In my case, the computer is the entity.<\/p>\n<p><a href=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidentInvestigation.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-22260\" src=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidentInvestigation.png\" alt=\"\" width=\"439\" height=\"566\" srcset=\"https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidentInvestigation.png 439w, https:\/\/aidanfinn.com\/wp-content\/uploads\/2020\/10\/AzureSentinelWindowsDefenderIncidentInvestigation-233x300.png 233w\" sizes=\"auto, (max-width: 439px) 85vw, 439px\" \/><\/a><\/p>\n<p>The break-out dialogs allow me to query Log Analytics to learn more about the machine and its state at the time and the state of Windows Defender. For example, I can see who was logged into the machine at that time and what processes were running. Pretty nice, eh?<\/p>\n<p>&nbsp;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this post, I will explain how one can monitor Windows Defender and create incidents for it with Azure VMs. Background Windows Defender is built into Windows Server 2016 and Windows Server 2019. It&#8217;s free and pretty decent. But it surprises me how many of my customers (all) choose Defender over third-parties for their Azure &hellip; <a href=\"https:\/\/aidanfinn.com\/?p=22240\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Monitoring &#038; Alerting for Windows Defender in Azure VMs&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":21619,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"om_disable_all_campaigns":false,"_monsterinsights_skip_tracking":false,"_uf_show_specific_survey":0,"_uf_disable_surveys":false,"_wpcom_ai_launchpad_first_post":false,"footnotes":""},"categories":[5],"tags":[466,170,426,346,465,467,423,259,464],"class_list":["post-22240","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-azure","tag-analytic-rules","tag-azure","tag-azure-monitor-logs","tag-azure-security-center","tag-azure-sentinel","tag-entity-behavior","tag-log-analytics","tag-windows-defender","tag-workbooks"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"AFinn\"\/>\n\t<meta name=\"google-site-verification\" content=\"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/aidanfinn.com\/?p=22240\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_GB\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\" \/>\n\t\t<meta property=\"og:type\" content=\"activity\" \/>\n\t\t<meta property=\"og:title\" content=\"Managing Windows Defender in Azure | Aidan Finn, IT Pro\" \/>\n\t\t<meta property=\"og:description\" content=\"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/aidanfinn.com\/?p=22240\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary\" \/>\n\t\t<meta name=\"twitter:site\" content=\"@joe_elway\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Managing Windows Defender in Azure | Aidan Finn, IT Pro\" \/>\n\t\t<meta name=\"twitter:description\" content=\"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.\" \/>\n\t\t<meta name=\"twitter:creator\" content=\"@joe_elway\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#article\",\"name\":\"Managing Windows Defender in Azure | Aidan Finn, IT Pro\",\"headline\":\"Monitoring &#038; Alerting for Windows Defender in Azure VMs\",\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/AzureExpressRoutePeering.png\",\"width\":1224,\"height\":682},\"datePublished\":\"2020-10-01T17:28:59+01:00\",\"dateModified\":\"2020-10-08T10:13:26+01:00\",\"inLanguage\":\"en-GB\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#webpage\"},\"articleSection\":\"Azure, Analytic Rules, Azure, Azure Monitor Logs, Azure Security Center, Azure Sentinel, Entity Behavior, Log Analytics, Windows Defender, Workbooks\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/aidanfinn.com\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"position\":2,\"name\":\"Azure\",\"item\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#listItem\",\"name\":\"Monitoring &#038; Alerting for Windows Defender in Azure VMs\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#listItem\",\"position\":3,\"name\":\"Monitoring &#038; Alerting for Windows Defender in Azure VMs\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?cat=5#listItem\",\"name\":\"Azure\"}}]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#personImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1\",\"name\":\"AFinn\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"AFinn\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#webpage\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240\",\"name\":\"Managing Windows Defender in Azure | Aidan Finn, IT Pro\",\"description\":\"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.\",\"inLanguage\":\"en-GB\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?author=1#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/wp-content\\\/uploads\\\/2019\\\/09\\\/AzureExpressRoutePeering.png\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240\\\/#mainImage\",\"width\":1224,\"height\":682},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/?p=22240#mainImage\"},\"datePublished\":\"2020-10-01T17:28:59+01:00\",\"dateModified\":\"2020-10-08T10:13:26+01:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#website\",\"url\":\"https:\\\/\\\/aidanfinn.com\\\/\",\"name\":\"Aidan Finn, IT Pro\",\"description\":\"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...\",\"inLanguage\":\"en-GB\",\"publisher\":{\"@id\":\"https:\\\/\\\/aidanfinn.com\\\/#person\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"Managing Windows Defender in Azure | Aidan Finn, IT Pro","description":"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.","canonical_url":"https:\/\/aidanfinn.com\/?p=22240","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"TDKjbi2McB2eLIfL6KwPB3aQqv5E-mbcb2QYIcovGaI","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/aidanfinn.com\/?p=22240#article","name":"Managing Windows Defender in Azure | Aidan Finn, IT Pro","headline":"Monitoring &#038; Alerting for Windows Defender in Azure VMs","author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"publisher":{"@id":"https:\/\/aidanfinn.com\/#person"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2019\/09\/AzureExpressRoutePeering.png","width":1224,"height":682},"datePublished":"2020-10-01T17:28:59+01:00","dateModified":"2020-10-08T10:13:26+01:00","inLanguage":"en-GB","mainEntityOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=22240#webpage"},"isPartOf":{"@id":"https:\/\/aidanfinn.com\/?p=22240#webpage"},"articleSection":"Azure, Analytic Rules, Azure, Azure Monitor Logs, Azure Security Center, Azure Sentinel, Entity Behavior, Log Analytics, Windows Defender, Workbooks"},{"@type":"BreadcrumbList","@id":"https:\/\/aidanfinn.com\/?p=22240#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/aidanfinn.com#listItem","position":1,"name":"Home","item":"https:\/\/aidanfinn.com","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","position":2,"name":"Azure","item":"https:\/\/aidanfinn.com\/?cat=5","nextItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22240#listItem","name":"Monitoring &#038; Alerting for Windows Defender in Azure VMs"},"previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?p=22240#listItem","position":3,"name":"Monitoring &#038; Alerting for Windows Defender in Azure VMs","previousItem":{"@type":"ListItem","@id":"https:\/\/aidanfinn.com\/?cat=5#listItem","name":"Azure"}}]},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/#person","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22240#personImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"Person","@id":"https:\/\/aidanfinn.com\/?author=1#author","url":"https:\/\/aidanfinn.com\/?author=1","name":"AFinn","image":{"@type":"ImageObject","@id":"https:\/\/aidanfinn.com\/?p=22240#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/65fde4aa9f2ab1cf1514ae320a37ec682d9398ce5791d3c2dd1e8670a71ceea0?s=96&d=mm&r=g","width":96,"height":96,"caption":"AFinn"}},{"@type":"WebPage","@id":"https:\/\/aidanfinn.com\/?p=22240#webpage","url":"https:\/\/aidanfinn.com\/?p=22240","name":"Managing Windows Defender in Azure | Aidan Finn, IT Pro","description":"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.","inLanguage":"en-GB","isPartOf":{"@id":"https:\/\/aidanfinn.com\/#website"},"breadcrumb":{"@id":"https:\/\/aidanfinn.com\/?p=22240#breadcrumblist"},"author":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"creator":{"@id":"https:\/\/aidanfinn.com\/?author=1#author"},"image":{"@type":"ImageObject","url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2019\/09\/AzureExpressRoutePeering.png","@id":"https:\/\/aidanfinn.com\/?p=22240\/#mainImage","width":1224,"height":682},"primaryImageOfPage":{"@id":"https:\/\/aidanfinn.com\/?p=22240#mainImage"},"datePublished":"2020-10-01T17:28:59+01:00","dateModified":"2020-10-08T10:13:26+01:00"},{"@type":"WebSite","@id":"https:\/\/aidanfinn.com\/#website","url":"https:\/\/aidanfinn.com\/","name":"Aidan Finn, IT Pro","description":"A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","inLanguage":"en-GB","publisher":{"@id":"https:\/\/aidanfinn.com\/#person"}}]},"og:locale":"en_GB","og:site_name":"Aidan Finn, IT Pro - A blog covering Azure, Hyper-V, Windows Server, desktop, systems management, deployment, and so on ...","og:type":"activity","og:title":"Managing Windows Defender in Azure | Aidan Finn, IT Pro","og:description":"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.","og:url":"https:\/\/aidanfinn.com\/?p=22240","twitter:card":"summary","twitter:site":"@joe_elway","twitter:title":"Managing Windows Defender in Azure | Aidan Finn, IT Pro","twitter:description":"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.","twitter:creator":"@joe_elway"},"aioseo_meta_data":{"post_id":"22240","title":"Managing Windows Defender in Azure | #site_title","description":"This post will explain a way to monitor, report on, and alert for Windows Defender in Azure VMs using Log Analytics, Security Center, and Azure Sentinel.","keywords":[{"label":"Azure","value":"Azure"},{"label":"Windows Defender","value":"Windows Defender"},{"label":"Log Analytics","value":"Log Analytics"},{"label":"Azure Monitor Logs","value":"Azure Monitor Logs"},{"label":"Azure Security Center","value":"Azure Security Center"},{"label":"Workbooks","value":"Workbooks"},{"label":"Azure Sentinel","value":"Azure Sentinel"},{"label":"Analytic Rules","value":"Analytic Rules"},{"label":"Entity Behavior","value":"Entity Behavior"},{"label":"Investigation","value":"Investigation"},{"label":"Malware","value":"Malware"},{"label":"Virus","value":"Virus"}],"keyphrases":null,"primary_term":null,"canonical_url":"","og_title":"","og_description":"","og_object_type":"activity","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":"","og_article_tags":"","twitter_use_og":false,"twitter_card":"summary","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"ai":null,"created":"2020-12-21 03:53:23","updated":"2025-06-04 17:33:02","seo_analyzer_scan_date":null,"focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/aidanfinn.com\/?cat=5\" title=\"Azure\">Azure<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tMonitoring &amp; Alerting for Windows Defender in Azure VMs\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/aidanfinn.com"},{"label":"Azure","link":"https:\/\/aidanfinn.com\/?cat=5"},{"label":"Monitoring &#038; Alerting for Windows Defender in Azure VMs","link":"https:\/\/aidanfinn.com\/?p=22240"}],"amp_enabled":true,"jetpack_featured_media_url":"https:\/\/aidanfinn.com\/wp-content\/uploads\/2019\/09\/AzureExpressRoutePeering.png","_links":{"self":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22240","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=22240"}],"version-history":[{"count":18,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22240\/revisions"}],"predecessor-version":[{"id":22262,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/posts\/22240\/revisions\/22262"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=\/wp\/v2\/media\/21619"}],"wp:attachment":[{"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=22240"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=22240"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/aidanfinn.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=22240"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}