Microsoft Defender for Cloud

Security alerts reference

Searchable reference of documented and observed Microsoft Defender for Cloud security alerts maintained by pisinger.github.io. This list reflects only the alerts Microsoft documents publicly plus real alerts observed in the maintainer's own Azure lab - it does not represent the full set of alerts and detections the platform provides. Data sourced from Microsoft Learn. Disclaimer & sources.

📡 JSON 🎯 MITRE
Loading data...
0 visible alerts
0 total alerts
0 deprecated
0 Defender plans

Disclaimer & sources

This is a searchable reference of documented Microsoft Defender for Cloud security alerts. The alerts shown here are only those Microsoft publicly documents on Microsoft Learn. This list is not exhaustive — the platform may generate additional alerts and detections that are not documented here.

For example, some recently added alerts powered by Microsoft Defender Threat Intelligence and Microsoft Defender for Endpoint (MDE) may be undocumented. This applies to several Defender plans, including App Service which is backed by MDE detections.

Data is scraped from official Microsoft Learn documentation. Alerts marked as "archive" were sourced from deprecated/archived pages and may no longer be actively documented by Microsoft. Some of these archive alerts may themselves be deprecated — they are included for reference but may no longer be generated by Defender for Cloud.

Defender for Containers (archive) alerts are sourced from an offline snapshot of the former containers alert reference page. These alert types are no longer actively documented because Microsoft is transitioning to MDE-based alert correlation for container security. However, these alerts may still be detected even though they are no longer listed in the official documentation.

Defender for App Service (archive) alerts are sourced from an offline snapshot of the former App Service alert reference page. The current Microsoft Learn page no longer documents these alerts. However, they may still be detected by Defender for Cloud, particularly as App Service is backed by MDE-based detections.

Defender for DNS alerts are part of Defender for Servers P2 and are only available when the Defender for Servers P2 plan is enabled.

Observed alerts are real alerts detected in the maintainer's own Azure lab environment. These alerts are grounded from actual detections — they may not be officially documented on Microsoft Learn but are real alerts generated by Microsoft Defender for Cloud. They are included here for reference alongside the documented alerts.

Severity indicators

Sources

Non-official reference maintained by pisinger.github.io.