A security administrator wants to create a custom detection rule in Microsoft Defender XDR that alerts when a device initiates an outbound TCP connection to a known malicious IP address on a non-standard port (e.g., port 4444). Which advanced hunting table should be queried to find these network connections?
DeviceNetworkEvents is the advanced hunting table in Microsoft Defender XDR that records each network connection event on monitored endpoints, including LocalIP, RemoteIP, LocalPort, RemotePort, Protocol, and ActionType (e.g., ConnectionAttempt, ConnectionSuccess). For a custom detection rule that needs to flag suspicious outbound connectivity, this table is the authoritative source because every row represents an actual device-initiated or accepted network connection with the exact destination endpoint needed for threshold or indicator matching.
Why this answer
DeviceNetworkEvents is the correct table because it specifically captures network connection events, including outbound TCP connections to IP addresses and ports. This table contains fields like RemoteIP, RemotePort, and Protocol, making it ideal for detecting connections to known malicious IPs on non-standard ports such as 4444.
Exam trap
The trap here is that candidates may confuse DeviceProcessEvents with network events because processes often initiate network connections, but DeviceProcessEvents does not contain network-level details like remote IP or port, leading to an incorrect choice.
How to eliminate wrong answers
Option B is wrong because DeviceProcessEvents logs process creation and execution events, not network connections; it lacks network-specific fields like RemoteIP or RemotePort. Option C is wrong because EmailEvents tracks email-related activities (delivery, phishing, etc.) and has no network connection data. Option D is wrong because IdentityLogonEvents records authentication and logon events for user identities, not device-level network traffic.