You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

在Microsoft高级狩猎中监控未授权USB:获取序列号问题求助

解决USB设备序列号查询的报错问题

问题原因

报错提示SerialNumber字段无法解析,核心原因有两点:

  • 你关联的DeviceInfo表中的SerialNumber是终端设备(如电脑)的序列号,并非USB外设的序列号;
  • DeviceEvents的UsbDriveMounted/UsbDriveUnmounted事件本身不会直接输出USB设备序列号,该信息嵌套在事件的AdditionalFields或Payload这类结构化字段中。

修改后的查询方案

方案1:解析DeviceEvents嵌套字段获取USB序列号

针对UsbDriveMounted/UsbDriveUnmounted事件,解析事件中的结构化字段提取序列号:

DeviceEvents
| where ActionType in ("UsbDriveMounted", "UsbDriveUnmounted")
// 解析AdditionalFields为JSON结构,提取USB设备序列号
| extend UsbDeviceDetails = parse_json(AdditionalFields)
| project Timestamp, DeviceId, DeviceName, ActionType, FileName, FolderPath, SerialNumber = tostring(UsbDeviceDetails.SerialNumber)
// 关联DeviceInfo补充设备信息(若不需要可省略此join步骤)
| join kind=inner DeviceInfo on DeviceId
// 移除join后产生的重复字段
| project-away DeviceId1, DeviceName1
| sort by Timestamp desc

方案2:适配架构更新后的事件类型

若文档提及的UsbDriveMount/UsbDriveUnmount是当前环境实际产生的事件类型,可切换ActionType并解析字段:

DeviceEvents
| where ActionType in ("UsbDriveMount", "UsbDriveUnmount")
| extend UsbDeviceDetails = parse_json(AdditionalFields)
| project Timestamp, DeviceId, DeviceName, ActionType, FileName, FolderPath, SerialNumber = tostring(UsbDeviceDetails.SerialNumber)
| join kind=inner DeviceInfo on DeviceId
| project-away DeviceId1, DeviceName1
| sort by Timestamp desc

额外验证步骤

  1. 先运行以下查询,确认当前环境存在的USB相关事件类型:
DeviceEvents | where ActionType contains "Usb" | distinct ActionType
  1. 若AdditionalFields中无序列号,尝试替换为Payload字段解析:parse_json(Payload)

内容的提问来源于stack exchange,提问作者ShekelsBot

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.23 22:40:53