如何通过高级狩猎查询(KQL)识别Azure AD证书认证登录及数据来源
关于Azure AD证书认证登录的KQL查询及日志位置
- 可以通过高级狩猎的KQL查询判断用户是否使用证书身份认证登录。
- 这类登录数据会出现在
AAdSignInEventsBeta表中,同时也会在标准日志表SigninLogs里记录。
基础KQL查询示例
AAdSignInEventsBeta | extend CertAuthMethod = AuthenticationDetails[0].authenticationMethod | where CertAuthMethod == "X509Certificate" | project TimeGenerated, UserPrincipalName, IPAddress, CertAuthMethod, AppDisplayName, Status
关键字段说明
AuthenticationDetails.authenticationMethod:当该字段值为X509Certificate时,即可判定对应登录事件使用了证书身份认证。- 可结合
Status字段筛选成功/失败的登录记录,或通过UserPrincipalName、IPAddress缩小查询范围。
提取证书详细信息的进阶查询
如果需要获取证书颁发者、序列号等额外信息,可以解析AdditionalFields字段:
AAdSignInEventsBeta | where AuthenticationDetails has_any ('X509Certificate') | extend CertDetails = parse_json(AdditionalFields) | where isnotempty(CertDetails.CertificateAuthenticationDetails) | project TimeGenerated, UserPrincipalName, IPAddress, CertDetails.CertificateAuthenticationDetails.Issuer, CertDetails.CertificateAuthenticationDetails.SerialNumber
内容的提问来源于stack exchange,提问作者user14913641
相关产品推荐
相关产品推荐

