Microsoft Defender for Endpoint - Malware Detected

This playbook investigates “Malware detected by Microsoft Defender for Endpoint” by gathering Hash and User information and performing remediation based on the information gathered and received from the enrichment. Used Sub-playbooks: * Enrichment for Verdict To link this playbook to the relevant alerts automatically, we recommend using the following filters when configuring the playbook triggers: Alert Source = Correlation AND Alert Name = Malware detected by Microsoft Defender for Endpoint

Pack
MicrosoftDefenderAdvancedThreatProtection
Tasks
12

Commands used