Defender XDR advanced hunting tables are grouped by security domain. Endpoint examples include DeviceProcessEvents, DeviceNetworkEvents, DeviceFileEvents, DeviceLogonEvents, and DeviceRegistryEvents. Email examples include EmailEvents, EmailAttachmentInfo, EmailUrlInfo, and UrlClickEvents.
CloudAppEvents covers cloud application activity; identity tables cover sign-ins and directory behavior; AlertInfo and AlertEvidence connect detections to evidence. In the unified portal, these can be correlated with Sentinel workspace tables through advanced hunting according to onboarding and retention.
Official lessonDefender XDR advanced hunting schemas