Filter
Exclude
Time range
-
Near
Just published some code samples for applying MDE tags in bulk, specifically MDE-Management when dealing with non-persistent VDI and ServerCore You will need to register a service principal and grant it Machine.ReadWrite.All on the WindowsDefenderATP API github.com/nathanmcnulty/nat…
3
7
51
5,320
That is my preferred method because it's easier to implement, but we could also invoke PowerShell scripts remotely or through Intune/Group Policy Another option I really like is Live Response. Did you know you can write to the device timeline? It's in the WindowsDefenderATP API.
1
10
1,710
Fun story - there are 3 different APIs you can hunt against WindowsDefenderATP 'api.securitycenter.microsoft…' Microsoft Threat Protection 'api.security.microsoft.com' Graph API 'graph.microsoft.com' None worked :( So I thought maybe I could fire an alert and get data off the API
1
1
2
今までMDEのAPIってWindowsDefenderATP APIだったけどMicrosoft Graphから利用できるようになるのね techcommunity.microsoft.com/…

1
14
This is cool stuff. In #WindowsDefenderATP you can see the data classification label. It's based on the most sensitive information found on the device, based on Microsoft Information Protection (#MIP). Nice :-)
1
2
24 Jun 2020
Microsoft: Windows Defender ATP für Linux ist da #WindowsDefenderATP glm.io/149273?t

2
5
#WindowsDefenderATP Live response özelliğini aktif ederek cihazlar üzerinde canlı olara derinlemesine analizler yapabilirsiniz. docs.microsoft.com/tr-tr/win…
2
2
#WindowsDefenderATP ile File hashes,IP addresses,URLs/Domains bazında bloklamalar yaparak kullanıcılarınızın daha güvenli çalışmasını sağlayabilirsiniz.
2
9
#WindowsDefenderATP ile cihazlarınızda bulunan Software inventory çıkarırken bu yazılımlardan dolayı kaynaklanan zafiyetleri görüntüleyebilirsiniz.
1
2
11
Want to see how security queries become shorter and readable? Check out uncoder.io/ - Translate queries from many sources to #KQL (#AzureSentinel, #WindowsDefenderATP #PoweredByADX) Try the products and see how fast they are too! Thanks @rodtrent for the pointer

4
8
Need a #ZeroTrust Reference Architecture? Check out this one showing how @Microsoft technology enables this strategy/access model. Slide 14 of CISO Workshop Module 3 @ajohnsocyber @MalwareJake @_sarahyo @RavivTamir @JohnLaTwC #Cybersecurity docs.microsoft.com/en-us/mic…
5
8
kkmookhey: msftsecurity: #MachineLearning helps #WindowsDefenderATP detect new and emerging threats. #infosec #cybersecurity #email #scam #tech
3
Our latest book hitting the shelves this week. Cover artwork is being done by @SuperCristal1 and it is going to be awesome. #windowsdefenderatp #server2019 @JohnONeillSr @SifuSun @ecabot and myself are your humble authors. #mvpbuzz @mvpaward #mvppower @WSV_GUY
3
5
In this #demo, learn how @WindowsATP helps you investigate attacks by collecting #investigation package from infected machines. youtu.be/cFMSiguvGZE #CyberSecurity #security #WindowsATP #WindowsDefenderATP #Microsoft365 #MicrosoftATP #MDATP #WDATP

3
...and then a user clicks and downloads malware and/or a rootkit #gameover unless you are using things like #WindowsDefenderATP #EdgeBrowserIsolation #ApplicationGuard #AzureATP and #Office365ATP #M365Security
I think the backdoor issue's been solved 🤔
2
Kicking off the #MDATP partner training in the Land of Oz. #windowsdefenderatp
1
23