Connect your own Microsoft Defender for Endpoint tenant (Azure AD App Registration) to manage Machines, Alerts, Incidents, custom Indicators, Machine Actions (isolate/scan), Advanced Hunting querie...
What this app can do
18 tools registered
Connect DefenderFree
Connect your own Microsoft Defender for Endpoint tenant by saving its Azure AD tenant/client credentials, after checking they actually work.
Disconnect DefenderFree
Disconnect a Microsoft Defender for Endpoint tenant: deletes the saved Azure AD credentials. Nothing in Defender itself is changed.
List ConnectionsFree
List the connected Microsoft Defender for Endpoint tenants (tenant id + masked Client ID).
List Machines8 tok
List endpoints (machines) in the connected Defender for Endpoint tenant, optionally filtered by an OData $filter.
Get Machine8 tok
Read one endpoint (machine) in full by its Defender machine id.
Isolate Machine16 tok
Network-isolate a machine -- cuts it off from the network except Defender cloud traffic (and optionally Outlook/Skype/Teams for 'Selective'). The core incident-response 'stop the bleeding' action.
Unisolate Machine16 tok
Release a machine from network isolation, restoring normal network access.
Run Av Scan20 tok
Trigger a Windows Defender antivirus scan (Quick or Full) on a machine.
Stop And Quarantine File20 tok
Stop a running process and quarantine its file on a machine, by SHA1 hash. A destructive containment action for confirmed malicious files.
List Alerts8 tok
List Alerts in the connected Defender for Endpoint tenant, optionally filtered by an OData $filter (e.g. "severity eq 'High'").
Get Alert8 tok
Read one Alert in full by its Defender alert id.
Update Alert16 tok
Update an Alert's status, classification, determination, and/or assignment.
List Indicators8 tok
List custom Indicators (IOCs) configured on the connected Defender for Endpoint tenant.
Create Indicator16 tok
Create a custom Indicator (IOC) on the connected Defender for Endpoint tenant to flag or block a hash, IP, domain, or URL fleet-wide.
Delete Indicator16 tok
Delete a custom Indicator (IOC) from the connected Defender for Endpoint tenant.
Run Hunting Query20 tok
Run an Advanced Hunting KQL query against the connected Defender for Endpoint tenant (e.g. "DeviceProcessEvents | take 10"). Read-only investigation.
List Vulnerabilities8 tok
List CVEs (Threat & Vulnerability Management) exposed across the fleet or on one machine.
Audit Estate40 tok
Build one aggregated health report across the connected Defender for Endpoint tenant: machine counts by health/isolation state, open/high-severity alerts, and critical CVE exposure.