🎉 ThreatConnect® 7.12 is now available! We love customer feedback. Write a review of ThreatConnect and we'll give you up to $50 as a thank-you gift!

Microsoft Defender for Endpoint Integration User Guide

Prev Next

The Microsoft® Defender for Endpoint integration allows you to ingest alerts into ThreatConnect® and then automate triage and investigative actions across your security stack.

There is a Playbook App and a Service App for this integration, each of which can be found in the ThreatConnect App Catalog under the names Microsoft Defender for Endpoint and Microsoft Defender for Endpoint Service, respectively. The Playbook App provides a powerful set of actions that can be leveraged within a larger security workflow orchestration or even simple automation. Immediate actions can be taken to investigate, stop, and remediate potential threats at the endpoint, based on external threat intelligence.

This guide covers how to install the Microsoft Defender for Endpoint Service App, configure and activate a corresponding Service, and create a Playbook that uses the custom Trigger Service.

 

Your browser does not support PDF.click here to download

 


ThreatConnect® is a registered trademark of ThreatConnect, Inc.
TC Exchangeâ„¢ is a trademark of ThreatConnect, Inc.
Azure® and Microsoft® are registered trademarks of Microsoft Corporation.