Joined to AlertInfo through AlertId, this advanced hunting table lists the entities linked with each alert, for example files, IP addresses, URLs, users and devices.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AlertEvidence in context, with comparison tables and the common traps.
Terms in this definition
- AlertInfo
Holds one row per alert from onboarded Sentinel workspaces and the Defender products, giving the alert's severity, category and title, its detection source and mapped MITRE ATT&CK techniques. Combine it with AlertEvidence using AlertId when you need the related entities.
- Advanced hunting
Threat-hunting feature of the Microsoft Defender portal that runs KQL over 30 days of raw Defender XDR data, plus onboarded Sentinel data, and supports custom detections. It finds activity after it happens rather than blocking it.
- Event
Table in Log Analytics where entries from Windows event logs are kept.