Query Details

10 Canonical Permission Edge Contract

Query

No standalone KQL detected in this source

View source on GitHub

About this query

Explanation

This query defines an empty table structure (schema) for storing data related to permissions and access control in a system. The table is called AgentPermissionEdges_CL and is intended to be used as a standardized format for collecting and visualizing permission-related data from various sources like Microsoft Graph, Azure Resource Graph, and others.

Key points of the query:

  • It specifies the columns and their data types that the table should have. These columns include information about the time of data generation, identifiers for edges and entities involved, types of permissions, authorization mechanisms, and other metadata.
  • The table is meant to normalize data from different collectors, ensuring that they all fit into this predefined structure before any visualization or further analysis.
  • It emphasizes the importance of preserving the EdgeClass column and provides guidelines on how to handle certain types of events and inferences, specifically advising against writing certain events as configured or reachableDeterministic.

In simple terms, this query sets up a blueprint for how permission-related data should be organized and stored, ensuring consistency and compatibility across different data sources and systems.