title | description | search.appverid | ms.service | ms.subservice | f1.keywords | ms.author | author | ms.localizationpriority | manager | audience | ms.collection | ms.custom | ms.topic | ms.date | |||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
DeviceTvmCertificateInfo table in the advanced hunting schema |
Learn about certificate information for devices in the organization from the DeviceTvmCertificateInfo table in the advanced hunting schema. |
met150 |
defender-xdr |
adv-hunting |
|
v-sgoyagoy |
samanthagy |
medium |
dansimp |
ITPro |
|
|
reference |
11/20/2024 |
[!INCLUDE Microsoft Defender XDR rebranding]
Applies to:
- Microsoft Defender XDR
- Microsoft Defender for Endpoint
Important
Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
The DeviceTvmCertificateInfo
table in the advanced hunting schema contains data from Microsoft Defender Vulnerability Management related to certificate information for devices in the organization. Use this reference to construct queries that return information from the table.
For information on other tables in the advanced hunting schema, see the advanced hunting reference.
Column name | Data type | Description |
---|---|---|
DeviceId |
string |
Unique identifier for the device in the service |
Thumbprint |
string |
Unique identifier for the certificate |
Path |
string |
The location of the certificate |
SerialNumber |
string |
Unique identifier for the certificate within a certificate authority's systems |
IssuedTo |
dynamic |
Entity that a certificate belongs to; can be a device, an individual, or an organization |
IssuedBy |
dynamic |
Entity that verified the information and signed the certificate |
FriendlyName |
string |
Easy-to-understand version of a certificate's title |
SignatureAlgorithm |
string |
Hashing algorithm and encryption algorithm used |
KeySize |
string |
Size of the key used in the signature algorithm |
ExpirationDate |
string |
The date and time beyond which the certificate is no longer valid |
IssueDate |
string |
The earliest date and time when the certificate became valid |
SubjectType |
string |
Indicates if the holder of the certificate is a CA or end entity |
KeyUsage |
string |
The valid cryptographic uses of the certificate's public key |
ExtendedKeyUsage |
string |
Other valid uses for the certificate |
- Overview of Microsoft Defender Vulnerability Management
- Proactively hunt for threats
- Learn the query language
- Use shared queries
- Hunt across devices, emails, apps, and identities
- Understand the schema
- Apply query best practices
[!INCLUDE Microsoft Defender XDR rebranding]