Share via

Help Needed: KQL Script to Count Vulnerabilities Over a Time Period

Anonymous
2024-02-12T01:38:32+00:00

Hi everyone,

I'm looking for assistance with a KQL script to count vulnerabilities in Microsoft Defender over a specific time period. I've tried the following script, but I'm encountering some issues:

DeviceTvmSoftwareVulnerabilities

| where Timestamp >= datetime(2024-01-01) and Timestamp < datetime(2024-02-01)

| summarize VulnerabilityCount = count() by DeviceId, VulnerabilityTitle

However, I'm getting errors regarding the "Timestamp" column.

Additionally, I've noticed that the reports in Microsoft Defender do not include a specific report to show the total number of vulnerabilities over a period of time. If anyone has any insights or suggestions on how to generate this report, I would greatly appreciate it.

Thank you in advance for your assistance!

Best regards,

*****Moved from <Microsoft 365 and Office / Unknown / Windows

Microsoft 365 and Office | Install, redeem, activate | For business | Other

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Anonymous
    2024-02-20T20:18:22+00:00

    Any answers here? This has to be the worst metrics from any vuln scanner ever! How to get this "Exposure Score" over say 6 months?

    DeviceTvmSoftwareVulnerabilities doesn't have a time* field. Where is a link for how to get KPI's for MDE Vulns and Defender for Cloud

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  2. Anonymous
    2024-02-12T14:04:18+00:00

    Dear Sergio Vargas3,

    Good day! Thank you for posting to Microsoft Community. We are happy to assist you.

    I do understand your query here but, as your query related to Microsoft Defender and since Microsoft has specific support channel resource for certain different support scope and attributes, we are belong to Microsoft Forum Community mainly focused on Micrsoft 365 Exchange online only. Therefore, we provide some limited knowledge about some aspects of Microsoft Defender related scenarios. For your concern, we have a dedicated team with special expertise in Microsoft Defender queries, so would you mind to connect and place your query on our dedicated Microsoft Defender for Cloud - Microsoft Q&A? We believe they will give you accurate and efficient solution for your concern.

    Thank you for your precious time and understanding. For other concerns, please do not hesitate to add your post in the Microsoft Community Team.  

    Stay safe and healthy. Have a nice day!

    Sincerely,

    Libeamlak | Microsoft Community Moderator

    Was this answer helpful?

    1 person found this answer helpful.
    0 comments No comments
  3. Deleted

    This answer has been deleted due to a violation of our Code of Conduct. The answer was manually reported or identified through automated detection before action was taken. Please refer to our Code of Conduct for more information.


    Comments have been turned off. Learn more