Command history, process and code change history are not reported. Only Registry modifications are reported. Deep file analysis results contain the file's activities, behaviors, and artifacts like dropped files, registry changes and IP communication. Reference: https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/respond-file- alerts?view=o365-worldwide