Want to experience Microsoft Defender XDR? Learn more about how you can evaluate and pilot Microsoft Defender XDR.

Applies to:

  • Microsoft Defender XDR

The BehaviorInfo table in the advanced hunting schema contains information about alerts from Microsoft Defender for Cloud Apps. Use this reference to construct queries that return information from this table.


Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.

Behaviors are a type of data in Microsoft Defender XDR based on one or more raw events. Behaviors provide contextual insight into events and can, but not necessarily, indicate malicious activity. Read more about behaviors

For information on other tables in the advanced hunting schema, see the advanced hunting reference.

Column name Data type Description
Timestamp datetime Date and time when the event was recorded
BehaviorId string Unique identifier for the behavior
ActionType string Type of behavior
Description string Description of the behavior
Categories list Type of threat indicator or breach activity identified by the behavior
AttackTechniques string MITRE ATT&CK techniques associated with the activity that triggered the alert
ServiceSource string Product or service that identified the behavior
DetectionSource string Detection technology or sensor that identified the notable component or activity
DataSources list Products or services that provided information for the behavior
DeviceId string Unique identifier for the machine in the service
AccountUpn string User principal name (UPN) of the account
AccountObjectId string Unique identifier for the account in Microsoft Entra ID
StartTime datetime Date and time of the first activity related to the behavior
EndTime datetime Date and time of the last activity related to the behavior
AdditionalFields string Additional information about the behavior


Do you want to learn more? Engage with the Microsoft Security community in our Tech Community: Microsoft Defender XDR Tech Community.