defender-cloud-cve-findings
Lists vulnerabilities collected from Microsoft Defender for Cloud, one row per affected resource, so each row names the CVE, the asset that carries it and the version that closes it.
defender-cloud-cve-findings [profile=VALUE] [subscription=VALUE] [cve=VALUE] [severity=VALUE] [resource=VALUE] [software=VALUE] [exposed=VALUE] [locale=VALUE]
- profile=VALUE
- Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
- subscription=VALUE
- Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
- cve=VALUE
- Optional. A single CVE identifier, to list every resource carrying it. e.g. CVE-2023-51385
- severity=VALUE
- Optional. Critical, High, Medium or Low. e.g. Critical
- resource=VALUE
- Optional. Substring of the resource name or ID, to list one machine's vulnerabilities. e.g. vm-app-01
- software=VALUE
- Optional. Substring of the vulnerable package name. e.g. openssl
- exposed=VALUE
- Optional. t to return only internet-reachable resources. e.g. t
- locale=VALUE
- Optional. Language of the recommendation title. Defaults to the console session's language; en returns Azure's original text. e.g. ko
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| cloud_resource_name | String | Resource name | The asset carrying this vulnerability. e.g. vm-app-01 |
| cloud_resource_type | String | Resource type | e.g. Microsoft.Compute/virtualMachines |
| cloud_resource | String | Resource ID | e.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/vm-app-01 |
| cve_id | String | CVE | e.g. CVE-2023-51385 |
| cve_severity | String | Severity | e.g. Critical |
| epss_score | Double | EPSS score | Probability of exploitation in the next 30 days, 0 to 1. Severity says how bad a flaw would be; this says whether anyone is using it. e.g. 0.00278 |
| epss_percentile | Double | EPSS percentile | Where the score sits among all CVEs, which is what makes it readable: 0.00278 is the 18th percentile. e.g. 0.18 |
| cvss3_base | Double | CVSS 3.x | e.g. 9.8 |
| cvss4_base | Double | CVSS 4.0 | Absent on older CVEs, which carry only 3.x. e.g. 8.7 |
| is_in_exploit_kit | Boolean | In exploit kit | e.g. true |
| is_publicly_disclosed | Boolean | Publicly disclosed | e.g. true |
| software_name | String | Package | e.g. openssh-client |
| software_vendor | String | Vendor | e.g. canonical |
| detected_versions | Array | Detected versions | Versions found on this resource. e.g. ["1:8.9p1-3ubuntu0.4"] |
| fix_status | String | Fix status | e.g. FixAvailable |
| fixed_version | String | Fixed version | The version that closes it on this resource, which is the actionable half of the row. e.g. 1:8.9p1-3ubuntu0.13 |
| max_cvss_score | Double | Max CVSS | Highest CVSS Defender reported on the finding this CVE came from. e.g. 9.8 |
| is_internet_exposed | Boolean | Internet exposed | e.g. true |
| published | Date | Published | e.g. 2023-12-19 00:00:00 |
| assessment_id | String | Recommendation ID | e.g. 11111111-1111-1111-1111-111111111111 |
| assessment_name | String | Recommendation | The finding this CVE was reported under. e.g. Update openssh-client |
| row_key | String | Row key | SHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6... |
| snapshot_id | String | Snapshot ID | The collection cycle that last wrote this row. e.g. 00000000-0000-0000-... |
| updated | Date | Collected at | e.g. 2026-10-05 00:34:15 |