Microsoft 365 Defender (v4.6.39)
Microsoft Defender XDR (formerly Microsoft 365 Defender) is a unified pre- and post-breach enterprise defense suite that natively coordinates detection, prevention, investigation, and response across endpoints, identities, email, and applications to provide integrated protection against sophisticated attacks.
- Author
- Cortex XSOAR
- Support
- xsoar
- URL
- https://www.paloaltonetworks.com/cortex
- Categories
- Network Security
Incident fields (16)
- Microsoft 365 Defender A
- Microsoft 365 Defender Active
- Microsoft 365 Defender Categories count
- Microsoft 365 Defender Classification
- Microsoft 365 Defender Comments
- Microsoft 365 Defender Devices
- Microsoft 365 Defender Display Name
- Microsoft 365 Defender First activity
- Microsoft 365 Defender ID
- Microsoft 365 Defender Last activity
- Microsoft 365 Defender Mailboxes
- Microsoft 365 Defender Status
- Microsoft 365 Defender Tags
- Microsoft 365 Defender Users
- impacted devices
- impacted entities
Integrations (3)
- Microsoft 365 Defender
- O365 Defender SafeLinks
- O365 Defender SafeLinks - Single User (Deprecated)
Layouts (1)
- Microsoft 365 Defender - Layout
Playbooks (3)
- Microsoft 365 Defender - Emails Indicators Hunt
- Microsoft 365 Defender - Get Email URL Clicks
- Microsoft 365 Defender - Threat Hunting Generic
Scripts (3)
- MS365DefenderAddComment
- MS365DefenderCountIncidentCategories
- MS365DefenderUserListToTable
README
With the Microsoft Defender XDR content pack, you can determine how a threat entered your environment and what part of your organization is affected.
What does this pack do?
- Get the most recent incidents that is a collection of correlated alerts and associated data.
- Enables you to hunt for both known and potential threats.
License information
Available for Office 365 E5, Microsoft 365 E5, and standalone licenses.