Skip to content

Latest commit

 

History

History
65 lines (57 loc) · 1.88 KB

security-registryvalueevidence.md

File metadata and controls

65 lines (57 loc) · 1.88 KB
title description ms.date author ms.localizationpriority ms.subservice doc_type
registryValueEvidence resource type
A registry value that is reported in the alert as evidence.
09/09/2021
BenAlfasi
medium
security
resourcePageType

registryValueEvidence resource type

Namespace: microsoft.graph.security

[!INCLUDE beta-disclaimer]

A registry value that is reported in the alert as evidence.

Inherits from alertEvidence.

Properties

Property Type Description
mdeDeviceId String A unique identifier assigned to a device by Microsoft Defender for Endpoint.
registryHive String Registry hive of the key that the recorded action was applied to.
registryKey String Registry key that the recorded action was applied to.
registryValue String Data of the registry value that the recorded action was applied to.
registryValueName String Name of the registry value that the recorded action was applied to.
registryValueType String Data type, such as binary or string, of the registry value that the recorded action was applied to.

Relationships

None.

JSON representation

The following is a JSON representation of the resource.

{
  "@odata.type": "#microsoft.graph.security.registryValueEvidence",
  "createdDateTime": "String (timestamp)",
  "verdict": "String",
  "remediationStatus": "String",
  "remediationStatusDetails": "String",
  "roles": [
    "String"
  ],
  "detailedRoles": [
    "String"
  ],
  "tags": [
    "String"
  ],
  "mdeDeviceId": "String",
  "registryKey": "String",
  "registryHive": "String",
  "registryValue": "String",
  "registryValueName": "String",
  "registryValueType": "String"
}