azure-defender-security-alert-evidence

Defender alerts can include command lines, files, IPs, identities, evidence, and captured sensitive values.

azurecritical service: azure:defender emits CanReadData

Where it sits

locationMicrosoft.Security/locations/alerts properties.{description,remediationSteps,entities,extendedProperties,resourceIdentifiers}
location kinddata_record
data kindscredential password api_key access_key secret_key oauth_token connection_string sensitive_data pii customer_data
emits edgeCanReadData
serviceDefender for Cloud (azure:defender)

Collection recipe

access moderead_api
operationAlerts - Get Resource Group Level
response pathproperties
encodingjson
params{"resource_id": "\u003cazure-resource-id\u003e"}

Required permissions

Microsoft.Security/locations/alerts/read

References

move · open · esc close