MDE - Search and Compare Process Executions

This playbook is a generic playbook that receives a process name and a command-line argument. It uses the "Microsoft Defender For Endpoint" integration to search for the given process executions and compares the command-line argument from the results to the command-line argument received from the playbook input. Note: Under the "Processes", input the playbook should receive an array that contains the following keys: - value: *process name* - commands: *command-line arguments*

Pack
MicrosoftDefenderAdvancedThreatProtection
Tasks
10

Inputs

Outputs

Commands used