Microsoft Defender for Endpoint (v1.20.45)

Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection (ATP)) is a unified platform for preventative protection, post-breach detection, automated investigation, and response.

Author
Cortex XSOAR
Support
xsoar
URL
https://www.paloaltonetworks.com/cortex
Default data source
Microsoft Defender Advanced Threat Protection
Categories
Endpoint

Automation Rules (1)

Correlation rules (1)

Incident fields (2)

Integrations (2)

Modeling rules (1)

Parsing rules (1)

Playbooks (16)

Scripts (6)

XSIAM Dashboards (1)

README

Use Microsoft Defender for Endpoint (previously Microsoft Defender Advanced Threat Protection (ATP)) to deliver industry-leading endpoint security for Windows, macOS, Linux, Android, iOS, and network devices. It helps to rapidly stop attacks, scale your security resources, and evolve your defenses. Microsoft Defender for Endpoint is an enterprise endpoint security platform designed to help enterprise networks prevent, detect, investigate, and respond to advanced threats.

Integration capabilities

Microsoft Defender for Endpoint allows you to perform preventative protection, post-breach detection, automated investigation, and response.
Microsoft Defender for Endpoint delivers continuous asset visibility, intelligent risk-based assessments, and built-in remediation tools to help your security and IT teams prioritize and address critical vulnerabilities and misconfigurations across your organization.

What does this pack do?

Content Pack components

Authentication

For more details about the authentication used for components in this content pack, see Microsoft Integrations - Authentication.

Endpoint URL

Environment Type Endpoint URL
Worldwide https://api.securitycenter.microsoft.com
Us Geo Proximity https://api.securitycenter.microsoft.com
Eu Geo Proximity https://api-eu.securitycenter.microsoft.com
UK Geo Proximity https://api-uk.securitycenter.microsoft.com
Us GCC https://api-gcc.securitycenter.microsoft.us
Us GCC-High https://api-gcc.securitycenter.microsoft.us
DoD https://api-gov.securitycenter.microsoft.us

To find the appropriate Endpoint URI, use the following resources:

Log ingestion

Note: In order to parse the timestamp correctly, make sure that the timestamp field is in UTC time zone (timestamp ends with “Z”).
The supported time format are yyyy-MM-ddThh:mm:%E3S (2021-12-08 10:00:00.123Z) or yyyy-MM-ddThh:mm:ss (2021-07-01T10:00:00Z). The relevant field is “lastEventTime”.

Licence information

Available for E3, E5, and standalone licenses.