Tracking historical IP assignments with Defender for Endpoint logs
ID: 0a0bc84a-b8ae-5373-9bf2-2373f8011901
STIX ID: report--0a0bc84a-b8ae-5373-9bf2-2373f8011901
Feed Name: NVISO Labs
This guide demonstrates how to use Microsoft Defender XDR Advanced Hunting to build a time-resolved view of a device’s IP assignment sessions, enabling investigators to correlate activity across dynamic IPs during incident response. By querying DeviceNetworkInfo and applying KQL operators like mv-expand, partition, prev(), and scan, analysts can generate session identifiers and first/last-seen timestamps per IP, streamlining hunts for lateral movement and contextualizing other telemetry.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
