commonfields: id: MicrosoftAtpScIndicatorCreate version: -1 name: MicrosoftAtpScIndicatorCreate script: '' type: python tags: - Utilities comment: A polling wrapper script; creates a new indicator in Microsoft Defender for Endpoint. enabled: true args: - description: The value of the indicator to update. name: indicator_value required: true - description: Indicator Type. name: indicator_type auto: PREDEFINED required: true predefined: - FileSha1 - FileSha256 - FileMd5 - IpAddress - DomainName - Url - auto: PREDEFINED description: The action taken if the indicator is discovered in the organization. name: action required: true predefined: - Audit - Block - BlockAndRemediate - Allowed - Warn - auto: PREDEFINED description: 'The severity of the malicious behavior identified by the data within the indicator, where High is the most severe and Informational is not severe at all.' name: severity predefined: - Informational - Low - Medium - High - description: 'DateTime string indicating when the indicator expires. Format: (