You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:编写Microsoft Defender漏洞统计KQL脚本及生成时段统计报告

修复KQL脚本并实现时段漏洞统计

1. 解决Timestamp字段报错问题

DeviceTvmSoftwareVulnerabilities表无Timestamp字段,需使用表中内置的时间字段:

  • LastSeen:漏洞最后被检测到的时间(适合统计时段内活跃的漏洞)
  • FirstSeen:漏洞首次被发现的时间(适合统计时段内新增的漏洞)

修正后的基础统计脚本(按设备+漏洞标题计数)

DeviceTvmSoftwareVulnerabilities
| where LastSeen >= datetime(2024-01-01) and LastSeen < datetime(2024-02-01)
| summarize VulnerabilityCount = count() by DeviceId, VulnerabilityTitle

2. 特定时段漏洞总数统计脚本

环境级去重总数统计

如果需要统计整个环境在目标时段内的唯一漏洞总数(避免同一漏洞在多设备重复计数):

DeviceTvmSoftwareVulnerabilities
| where LastSeen between (datetime(2024-01-01) .. datetime(2024-01-31))
| summarize TotalUniqueVulnerabilities = dcount(VulnerabilityId)

按严重程度拆分统计

如需按漏洞严重程度细分统计结果:

DeviceTvmSoftwareVulnerabilities
| where LastSeen between (datetime(2024-01-01) .. datetime(2024-01-31))
| summarize VulnerabilityCount = dcount(VulnerabilityId) by VulnerabilitySeverityLevel
| sort by VulnerabilityCount desc

3. 替代内置报表的方案

  • 将上述脚本保存为Defender门户「高级搜寻」中的自定义查询,支持手动运行或设置定时任务导出结果
  • 基于自定义查询创建工作簿,添加时间范围筛选器、可视化组件(柱状图/饼图),实现可交互的报表效果

内容的提问来源于stack exchange,提问作者John

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 00:35:00