Holds one row per alert from onboarded Sentinel workspaces and the Defender products, giving the alert's severity, category and title, its detection source and mapped MITRE ATT&CK techniques. Combine it with AlertEvidence using AlertId when you need the related entities.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains AlertInfo in context, with comparison tables and the common traps.
Terms in this definition
- AlertEvidence
Joined to AlertInfo through AlertId, this advanced hunting table lists the entities linked with each alert, for example files, IP addresses, URLs, users and devices.
- RELATED
Fetches a column value from the lookup table, that is the one side of a many-to-one relationship, for whichever row is being evaluated. It therefore needs to run inside an iterator or a calculated column, where row context exists.