Files
main/Office Defender

Office Defender For Endpoint Integration Awesome

Microsoft Defender for Endpoint has an API that we can interact with to pull alerts and events through Wazuh. The python scripts will pull events from the supported Defender for Endpoint API queries. These can be tied to a cronjob to pull during set intervals.

MIT License LinkedIn your-own-soc-free-for-life-tier

Endpoint APIs - Access the Microsoft Defender for Endpoint APIs

Need Help?

SOCFortress - LinkedIn - info@socfortress.co

Let SOCFortress Professional Services Take Your Open Source SIEM to the Next Level

Banner