Event Details High
Event Summary
Event ID
5
Risk Score
Status
ActiveTimestamp
Security Source
Microsoft Defender ATP (EDR)
Risk Category
Suspicious Login
User Information
Mitigations
No mitigations have been applied to this event.
Event Details
| Success | True |
|---|---|
| Alert Id | MS45678901 |
| Location | Kiev, Ukraine |
| Login Ip | 45.67.89.123 |
| Device Type | Unknown |
| Auth Protocol | NTLM |
| Previous Login Location | Seattle, USA |
| Time Since Last Login Hours | 6 |
Raw JSON Data
{
"alert_id": "MS45678901",
"auth_protocol": "NTLM",
"device_type": "Unknown",
"location": "Kiev, Ukraine",
"login_ip": "45.67.89.123",
"previous_login_location": "Seattle, USA",
"success": true,
"time_since_last_login_hours": 6
}