You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

求助:获取终端设备最后重启/重置信息的Microsoft Defender KQL脚本

解决Microsoft Defender终端重启/登录信息查询问题

改进版KQL脚本(结合DeviceEvents与DeviceInfo)

你的原脚本仅抓取了重启/关机事件,但未关联最后登录用户信息,且未覆盖所有可能的设备日志情况。以下脚本结合Defender for Endpoint的DeviceEvents和DeviceInfo表,同时获取设备名、最后重启/关机时间及最后登录用户:

// 提取各设备最后一次重启或关机事件
let LastRebootEvents = DeviceEvents
| where ActionType in ("Restarted", "Shutdown")
| summarize 
    LastRebootOrShutdown = max(EventTime),
    LastAction = arg_max(EventTime, ActionType).ActionType
by DeviceName;

// 关联设备信息表获取最后登录用户
DeviceInfo
| project DeviceName, LastLogonUserName, OSVersion
| join kind=leftouter LastRebootEvents on DeviceName
| project DeviceName, LastRebootOrShutdown, LastAction, LastLogonUserName
| sort by LastRebootOrShutdown desc nulls last

备选方案:从注册表日志获取关机时间

如果部分设备未上报重启/关机事件到DeviceEvents,可以通过DeviceRegistryEvents读取系统注册表中的关机时间记录,兼容性更好:

// 从注册表提取最后关机时间(转换为UTC格式)
let LastShutdownRegistry = DeviceRegistryEvents
| where RegistryKey == @"HKLM\System\CurrentControlSet\Control\Windows"
| where RegistryValueName == "ShutdownTime"
| extend ShutdownTime = todatetime(hex_str_to_int(RegistryValueData))
| summarize LastShutdownTime = max(ShutdownTime) by DeviceName;

// 关联最后登录用户信息
DeviceInfo
| project DeviceName, LastLogonUserName, OSBuildNumber
| join kind=leftouter LastShutdownRegistry on DeviceName
| project DeviceName, LastShutdownTime, LastLogonUserName
| sort by LastShutdownTime desc nulls last

关键注意事项

  • 若设备离线或日志采集中断,对应字段会显示null,可添加时间过滤条件(如| where EventTime > ago(30d))缩小范围。
  • LastLogonUserName字段返回格式通常为DOMAIN\Username或本地用户名,需根据组织环境解读。
  • 若需区分重启和关机动作,第一个脚本中的LastAction字段会明确标记事件类型。

非KQL替代方案

如果Defender日志数据不全,可尝试以下方法:

  • 利用Microsoft Intune的设备报表(若组织使用Intune管理终端),直接导出设备重启时间和登录用户信息。
  • 通过GPO配置终端将重启、登录日志转发到SIEM服务器,统一收集分析。
  • 用PowerShell批量查询终端:
    Invoke-Command -ComputerName (Get-Content .\device-list.txt) -ScriptBlock {
        $osInfo = Get-CimInstance Win32_OperatingSystem
        $lastLogon = Get-WmiObject Win32_NetworkLoginProfile | Sort-Object LastLogon -Descending | Select-Object -First 1
        [PSCustomObject]@{
            DeviceName = $env:COMPUTERNAME
            LastBootTime = $osInfo.LastBootUpTime
            LastLogonUser = $lastLogon.Name
        }
    } | Export-Csv .\device-restart-logon-report.csv -NoTypeInformation
    

内容的提问来源于stack exchange,提问作者John

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.30 06:00:06