Skip to content

Commit

Permalink
Merge pull request #2019 from MicrosoftDocs/main
Browse files Browse the repository at this point in the history
Published main to live, Tuesday 5:00 PM IST, 11/26
  • Loading branch information
padmagit77 authored Nov 26, 2024
2 parents adb118a + 167a4fd commit 13fa797
Showing 1 changed file with 3 additions and 6 deletions.
9 changes: 3 additions & 6 deletions defender-xdr/investigate-respond-container-threats.md
Original file line number Diff line number Diff line change
Expand Up @@ -18,7 +18,8 @@ search.appverid:
- MET150
ms.date: 11/18/2024
appliesto:
- Microsoft Defender XDR
- ✅ <a href="https://learn.microsoft.com/defender-xdr/microsoft-365-defender" target="_blank">Microsoft Defender XDR</a>
- <a href="https://learn.microsoft.com/unified-secops-platform/" target="_blank">Microsoft's unified security operations platform</a>
---
# Investigate and respond to container threats in the Microsoft Defender portal

Expand Down Expand Up @@ -99,11 +100,7 @@ To determine the full scope of a container attack, you can deepen your investiga

In the [Advanced hunting](advanced-hunting-overview.md) page, you can extend your search for container-related activities using the **CloudProcessEvents** and **CloudAuditEvents** tables.

:::image type="content" source="/defender/media/defender-containers/adv-hunting-cloud-small.png" alt-text="Highlighting the advanced hunting tables related to cloud events." lightbox="/defender/media/defender-containers/adv-hunting-cloud.png":::

The **CloudProcessEvents** table contains information about process events in multi-cloud hosted environments such as Azure Kubernetes Service, Amazon Elastic Kubernetes Service, and Google Kubernetes Engine.

The **CloudAuditEvents table** contains cloud audit events from cloud platforms protected by Microsoft Defender for Cloud. It also contains Kubeaudit logs, which holds information about Kubernetes-related events.
The [CloudProcessEvents](advanced-hunting-cloudprocessevents-table.md) table contains information about process events in multi-cloud hosted environments such as Azure Kubernetes Service, Amazon Elastic Kubernetes Service, and Google Kubernetes Engine. On the other hand, the [CloudAuditEvents](advanced-hunting-cloudauditevents-table.md) table contains cloud audit events from cloud platforms protected by Microsoft Defender for Cloud. It also contains Kubeaudit logs, which holds information about Kubernetes-related events.

## See also

Expand Down

0 comments on commit 13fa797

Please sign in to comment.