如何在Microsoft Defender for Endpoint中使用KQL查询浏览器版本?
在Microsoft Defender for Endpoint中查询过时浏览器的KQL解决方案
你的原查询没结果是因为DeviceEvents表的BrowserEvent类型记录的是浏览器的行为事件(如导航、下载操作),而非设备上已安装的浏览器版本信息,而且这类事件需要开启对应的高级威胁检测规则才会被收集,所以空结果是正常的。
要获取设备上的浏览器版本并筛选过时版本,应该使用以下两个更合适的表:
方法1:用DeviceInfo表快速查看默认浏览器
DeviceInfo表包含设备的基础信息,其中自带默认浏览器的名称和版本字段:
DeviceInfo | project DeviceName, DeviceId, OSPlatform, BrowserName, BrowserVersion, LastSeen | where isnotempty(BrowserName) | order by LastSeen desc
方法2:用SoftwareInventory表获取所有安装的浏览器(推荐)
这个表记录了设备上所有已安装的软件,能全面捕获所有浏览器(包括非默认的),是筛选过时版本的最佳选择:
第一步:查看所有浏览器的安装情况
SoftwareInventory | where ProductName has_any ("Google Chrome", "Mozilla Firefox", "Microsoft Edge", "Internet Explorer", "Safari") | project DeviceName, DeviceId, ProductName, ProductVersion, InstallDate, LastUpdated | order by DeviceName, ProductName
第二步:筛选过时版本
使用parse_version函数将版本字符串转为结构化数据,方便按主版本号判断是否过时(以下版本阈值可根据实际需求调整):
SoftwareInventory | where ProductName has_any ("Google Chrome", "Mozilla Firefox", "Microsoft Edge", "Internet Explorer") | extend VersionStruct = parse_version(ProductVersion) | evaluate bag_unpack(VersionStruct) // 展开版本结构为Major/Minor/Build等字段 | extend IsOutdated = case( ProductName contains "Chrome" and Major < 120, true, ProductName contains "Edge" and Major < 120, true, ProductName contains "Firefox" and Major < 115, true, ProductName contains "Internet Explorer" and Major < 11, true, false ) | where IsOutdated == true | project DeviceName, DeviceId, ProductName, ProductVersion, LastUpdated | order by ProductName, DeviceName
注意事项
- 确保设备已联网并向Defender for Endpoint上报数据,离线设备的SoftwareInventory可能未更新
- 部分浏览器的ProductName可能有变体(如"Chrome"而非"Google Chrome"),可根据实际返回结果调整
has_any里的关键词
内容的提问来源于stack exchange,提问作者Daren
相关产品推荐
相关产品推荐

