Microsoft Advanced Threat Analytics
Deprecated. No available replacement.
- Category
- Forensics & Malware Analysis
- Pack
- MicrosoftAdvancedThreatAnalytics
Configuration parameters
- url — ATA Center URL (e.g. https://atacenter.contoso.com) (required)
- credentials — Username (required)
- isFetch — Fetch incidents
- incidentType — Incident type
- max_fetch — Maximum number of incidents per fetch
- activity_status — Fetch suspicious activity with status
- activity_type — Fetch suspicious activity with type (leave empty to fetch all)
- min_severity — Minimum severity of suspicious activity to fetch (required)
- first_fetch — First fetch time range (<number> <time unit>, e.g., 1 hour, 30 minutes)
- insecure — Trust any certificate (not secure)
- proxy — Use system proxy settings
Commands (4)
- ms-ata-entity-get — Retrieves information of an entity, such as a computer and user.
- ms-ata-monitoring-alerts-list — Retrieves health alerts.
- ms-ata-suspicious-activities-list — Retrieves suspicious activities.
- ms-ata-suspicious-activity-status-set — Sets the status of the suspicious activity.