defender-cloud-resources
Lists the asset inventory collected from Microsoft Defender for Cloud, one row per resource, with its finding counts and the Defender plan that covers it.
defender-cloud-resources [profile=VALUE] [subscription=VALUE] [resource-type=VALUE] [resource-group=VALUE] [environment=VALUE] [unhealthy=VALUE] [exposed=VALUE] [keyword=VALUE]
- profile=VALUE
- Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
- subscription=VALUE
- Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
- resource-type=VALUE
- Optional. e.g. microsoft.compute/virtualmachines
- resource-group=VALUE
- Optional. e.g. prod-rg
- environment=VALUE
- Optional. Cloud the resource belongs to: Azure, AWS or GCP. e.g. Azure
- unhealthy=VALUE
- Optional. t to return only resources with at least one unhealthy finding. e.g. t
- exposed=VALUE
- Optional. t to return only internet-reachable resources. e.g. t
- keyword=VALUE
- Optional. Substring of the resource name, type or id. e.g. vm-app-01
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| cloud_account_name | String | Subscription | e.g. Production |
| cloud_resource_name | String | Resource name | e.g. vm-app-01 |
| cloud_resource_type | String | Resource type | e.g. microsoft.compute/virtualmachines |
| cloud_resource_group | String | Resource group | e.g. prod-rg |
| environment | String | Environment | e.g. Azure |
| location | String | Location | e.g. koreacentral |
| resource_kind | String | Kind | Resource subtype where Azure publishes one. e.g. functionapp |
| defender_plan | String | Defender plan | Plan that covers this resource type. e.g. VirtualMachines |
| defender_plan_tier | String | Plan tier | e.g. Standard - Free means the resource is listed but not protected |
| unhealthy_count | Integer | Unhealthy findings | e.g. 7 |
| healthy_count | Integer | Healthy findings | e.g. 12 |
| not_applicable_count | Integer | Not applicable findings | e.g. 2 |
| assessment_count | Integer | Total findings | e.g. 21 |
| cve_count | Integer | CVEs | e.g. 134 |
| max_risk_score | Integer | Highest risk rank | Rank of the worst finding on this resource. e.g. 4.0 |
| is_internet_exposed | Boolean | Internet exposed | e.g. true |
| is_production | Boolean | Production | e.g. true |
| tags | Map | Tags | Azure tags as published, in JSON. e.g. {"env":"prod"} |
| cloud_resource | String | Resource ID | e.g. /subscriptions/.../providers/Microsoft.Compute/virtualMachines/vm-app-01 |
| row_key | String | Row key | SHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6... |
| snapshot_id | String | Snapshot ID | The collection cycle that last wrote this row. e.g. 00000000-0000-0000-... |
| updated | Date | Collected at | e.g. 2026-10-05 00:34:15 |