logo
search
Others

How to Find the Last Detected Date in Defender Vulnerability Management

Guest WriterGuest Writer Oct 1, 2026 869 views

Question details

The user needs to clarify the meaning of vulnerability timestamps (such as First Detected and Updated On) and determine how to find the most recent detection date in Microsoft Defender Vulnerability Management.

How to Find the Last Detected Date in Microsoft Defender Vulnerability Management
Product
Microsoft Defender Vulnerability Management
Device & OS
not provided
Scenario
Reviewing security reports to determine the exact latest date a specific vulnerability was detected by the system scanner.
Observed behavior
The dashboard displays Published On, First Detected, and Updated On dates, causing confusion over which field accurately represents the latest vulnerability detection scan.
Before you start

Ensure you have the necessary Security Reader or Security Administrator permissions in the Microsoft 365 Defender portal to access vulnerability inventory and device scan records.

Solution 1Recommended

Analyze Defender Timestamp Fields

Understand how Microsoft Defender categorizes its vulnerability dates to interpret the latest detection activity.

Microsoft Defender Vulnerability Management tracks vulnerabilities using three primary time fields. To understand recent scan activity, you must interpret how the system updates these specific columns.

While 'Published On' refers to the global CVE release date and 'First Detected' marks the initial discovery on your network, the 'Updated On' field is generally the closest indicator of recent status changes or subsequent scan confirmations.

1
Access Vulnerability Management

Log in to the Microsoft 365 Defender portal and navigate to 'Vulnerability management' > 'Weaknesses' in the left-hand navigation menu.

2
Review the 'Updated On' Column

Locate the specific CVE (Common Vulnerabilities and Exposures) record. Look at the 'Updated On' column, which reflects the last time the vulnerability's status or details were modified by a scanner update.

3
Check Device Timeline

For more granular data, click on a specific exposed device, navigate to the 'Timeline' tab, and filter by 'Vulnerability' to see the precise timestamp of the last scanner detection event for that machine.

Analyze Defender Timestamp Fields
Data Refresh Rates: Defender scanners run continuously in the background. However, dashboard data may take several hours to reflect the absolute latest scan timestamps.
Free Microsoft Office alternative

Manage Your Security Reports with WPS Office

While you manage your organization's security with Microsoft Defender, you may also need a lightweight, cost-effective solution for handling exported vulnerability reports and daily business documents. WPS Office is a powerful, free alternative to Microsoft Office.

  1. 1. Download WPS Office: Visit the official WPS website and download the free installation package for your operating system.
  2. 2. Install the Software: Run the installer and follow the on-screen prompts to set up WPS Office on your device.
  3. 3. Open Your Reports: Launch WPS Spreadsheet to instantly open, format, and analyze CSV vulnerability exports with advanced filtering tools.
Seamlessly compatible with Microsoft Excel, Word, and PowerPoint formats.Easily open and analyze large CSV vulnerability reports exported from Defender.Lightweight architecture ensures it consumes minimal system resources.Familiar user interface makes team migration and onboarding effortless.Built-in PDF editing tools for creating secure security audit reports.
microsoft office alternative - wps office

Frequently Asked Questions

What is the difference between 'Published On' and 'First Detected'?

'Published On' refers to the date the vulnerability (CVE) was publicly disclosed by security researchers worldwide. 'First Detected' indicates the exact date and time the vulnerability was initially found on a device within your specific organizational network.

Can I export vulnerability detection dates for reporting?

Yes. In the Microsoft 365 Defender portal, you can select your vulnerabilities or exposed devices list and click the 'Export' button. This generates a CSV file containing all timestamps, which you can easily analyze using spreadsheet software like WPS Spreadsheet.

Why does the 'Updated On' date change even if no patch was applied?

The 'Updated On' field can change if the backend threat intelligence receives new metadata regarding the CVE (such as a change in the CVSS score) or if a routine background scan simply re-verifies the ongoing presence of the vulnerability.