• Last Updated
    Mar 18, 2025
  • Version
    1.3.0
  • Compatibility
    ThreatQ >= v5.10.0
  • ThreatQ CDF for Microsoft Defender

    ThreatQuotient

    Overview

    The ThreatQ CDF for Microsoft Defender integration enables the automatic ingestion of incidents, alerts, reports and related context, from your Microsoft Defender portal, into ThreatQ.

    The integration provides the following endpoints:

    • Microsoft Defender XDR Incidents - ingests incidents, alerts, and related context from Microsoft Defender.
    • Microsoft Defender Threat Intelligence Articles - ingests reports, indicators, attack patterns and vulnerabilities.
    • Microsoft Defender Threat Intelligence Intel Profiles - ingests adversaries, tools, reports and indicators.

    The integration ingests the following system objects:

    • Attack Patterns
    • Assets
      • Asset Attributes
    • Events
      • Event Attributes
    • Indicators
      • Indicator Attributes
    • Malware
    • Reports
    • Tags
    • Tools
    • Vulnerabilities

    Copyright © 2025, ThreatQuotient, Inc. All Rights Reserved. Privacy Policy