Vulnerability Statistics Sentinel Workbook
Vulnerability Statistics Logic App Sentinel Workbook
Query
No standalone KQL detected in this source
View source on GitHubAbout this query
Explanation
This query and its associated components are part of a system designed to provide a weekly overview of vulnerabilities across various device categories using Microsoft Defender data. Here's a simplified breakdown:
-
Logic App:
- Schedule: Runs every week.
- Data Collection: Executes an advanced query using Microsoft Graph to gather vulnerability data from devices categorized as Windows servers, Windows clients, Linux, macOS, and network components.
- Metrics: Collects data on total vulnerabilities, unique CVEs (Common Vulnerabilities and Exposures), exploitable CVEs, affected devices, and average CVSS (Common Vulnerability Scoring System) scores.
- Data Ingestion: Sends the gathered data to Azure Monitor using the Log Ingestion API.
- Success Check: Confirms successful data ingestion by checking for a 2xx HTTP response status. If successful, it logs the success; otherwise, it logs the error and marks the run as failed.
- Authentication: Uses Managed Identity for secure access without embedded credentials.
-
Sentinel Workbook:
- Overview: Provides a consolidated view of vulnerability exposure across device categories.
- KPI Tiles and Detail Table: Displays the latest snapshot of key metrics for each category, such as total vulnerabilities, unique CVEs, exploitable CVEs, affected devices, average CVSS score, and average vulnerabilities per device.
- Trend Analysis: Visualizes trends over time for vulnerability volume, average severity, and exploitable CVEs, helping to identify risk areas and prioritize remediation efforts.
Overall, this system automates the collection, analysis, and visualization of vulnerability data to help organizations monitor and manage their security posture effectively.
Details

Benjamin Zulliger
Released: July 13, 2026
Tables
DeviceInfoDeviceTvmSoftwareVulnerabilitiesKBDeviceTvmSoftwareVulnerabilitiesVulnerabilitystatistics_CL
Keywords
Vulnerability Statistics Sentinel WorkbookLogic AppSentinel WorkbookMicrosoft DefenderAdvanced HuntingMicrosoft GraphDevicesWindows ServersWindows ClientsLinuxmacOSNetwork ComponentsSecurity MetricsVulnerabilitiesCVEsCVSSAzure MonitorLog Ingestion APIManaged IdentityTVMKPITrendRiskRemediationDevice CategoriesVulnerability ExposureSnapshotTrend SectionComparisonPrioritization
Operators
letsummarizearg_maxextendcasehas_anystartswithprojectjoinkindondcountdcountifroundtorealnowsortdescwhereinagoascbymaxtointrendertimecharttrimtostringavgtodouble