Microsoft Defender for EDR integration
Integration with the Microsoft Defender for EDR allows Cyber Threat Intelligence (CTI) analysts to automatically push malicious or suspicious IP addresses, domains, file hashes, and URLs to Microsoft Defender for continuous monitoring and real-time alerting.
- Register and configure the Microsoft Defender in the Microsoft Azure portal
Register the Microsoft Defender EDR in the Microsoft Azure portal and grant the read and write access to the application. - Install and configure Microsoft Defender for EDR Integration
Install and configure the Microsoft Defender for EDR integration from the ServiceNow Store. - System properties for Microsoft Defender EDR
The following details the system properties for Microsoft Defender EDR. - Send observables to EDR
Send observables to the EDR security tool.
Parent Topic:TISC Security Tools integrations