
ThreatQ CDF for Microsoft Defender
Overview
The ThreatQ CDF for Microsoft Defender integration enables the automatic ingestion of incidents, alerts, reports and related context, from your Microsoft Defender portal, into ThreatQ.
The integration provides the following endpoints:
- Microsoft Defender XDR Incidents - ingests incidents, alerts, and related context from Microsoft Defender.
- Microsoft Defender Threat Intelligence Articles - ingests reports, indicators, attack patterns and vulnerabilities.
- Microsoft Defender Threat Intelligence Intel Profiles - ingests adversaries, tools, reports and indicators.
The integration ingests the following system objects:
- Attack Patterns
- Assets
- Asset Attributes
- Events
- Event Attributes
- Indicators
- Indicator Attributes
- Malware
- Reports
- Tags
- Tools
- Vulnerabilities