You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何在Microsoft Defender for Endpoint中使用KQL查询浏览器版本?

在Microsoft Defender for Endpoint中查询过时浏览器的KQL解决方案

你的原查询没结果是因为DeviceEvents表的BrowserEvent类型记录的是浏览器的行为事件(如导航、下载操作),而非设备上已安装的浏览器版本信息,而且这类事件需要开启对应的高级威胁检测规则才会被收集,所以空结果是正常的。

要获取设备上的浏览器版本并筛选过时版本,应该使用以下两个更合适的表:

方法1:用DeviceInfo表快速查看默认浏览器

DeviceInfo表包含设备的基础信息,其中自带默认浏览器的名称和版本字段:

DeviceInfo
| project DeviceName, DeviceId, OSPlatform, BrowserName, BrowserVersion, LastSeen
| where isnotempty(BrowserName)
| order by LastSeen desc

方法2:用SoftwareInventory表获取所有安装的浏览器(推荐)

这个表记录了设备上所有已安装的软件,能全面捕获所有浏览器(包括非默认的),是筛选过时版本的最佳选择:

第一步:查看所有浏览器的安装情况

SoftwareInventory
| where ProductName has_any ("Google Chrome", "Mozilla Firefox", "Microsoft Edge", "Internet Explorer", "Safari")
| project DeviceName, DeviceId, ProductName, ProductVersion, InstallDate, LastUpdated
| order by DeviceName, ProductName

第二步:筛选过时版本

使用parse_version函数将版本字符串转为结构化数据,方便按主版本号判断是否过时(以下版本阈值可根据实际需求调整):

SoftwareInventory
| where ProductName has_any ("Google Chrome", "Mozilla Firefox", "Microsoft Edge", "Internet Explorer")
| extend VersionStruct = parse_version(ProductVersion)
| evaluate bag_unpack(VersionStruct) // 展开版本结构为Major/Minor/Build等字段
| extend IsOutdated = case(
    ProductName contains "Chrome" and Major < 120, true,
    ProductName contains "Edge" and Major < 120, true,
    ProductName contains "Firefox" and Major < 115, true,
    ProductName contains "Internet Explorer" and Major < 11, true,
    false
)
| where IsOutdated == true
| project DeviceName, DeviceId, ProductName, ProductVersion, LastUpdated
| order by ProductName, DeviceName

注意事项

  • 确保设备已联网并向Defender for Endpoint上报数据,离线设备的SoftwareInventory可能未更新
  • 部分浏览器的ProductName可能有变体(如"Chrome"而非"Google Chrome"),可根据实际返回结果调整has_any里的关键词

内容的提问来源于stack exchange,提问作者Daren

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 17:20:03