Menu

Anything about IT

by Alex Verboon

Primary Menu

Skip to content
  • Home
  • About me
  • Blogpost Index
  • Links
  • Privacy Policy
Search

Tag: Defender ATP

How to accelerate your Microsoft Defender ATP Evaluation

Posted on6 August 20196 August 2019Leave a comment

As with almost any solution, one of the time consuming activities is to get the prerequisites in place until you get things up and running, this is no different with Microsoft Defender Advanced Threat Protection. Although the solution itself is Read More …

Like this:

Like Loading...

CategoriesDefender ATP, Evaluation, Lab, LabsTagsDefender ATP, Evaluation, lab, MDATP

Managing Role Based Access (RBAC) for Microsoft Defender Advanced Threat Protection

Posted on24 May 201924 May 20191 Comment

I spend quite some time during the week travelling to and from customers, to make the best use of travel time, I usually read blogs and tweets or take online trainings to keep myself up to date about whatever interests Read More …

Like this:

Like Loading...

CategoriesDefender ATP, MDATPTagsDefender ATP, MDATP, RBAC

Retrieving Windows Defender Exploit Guard Windows Event logs with PowerShell

Posted on2 May 20195 Comments

Most of the features included in Windows Defender Exploit Guard can be enabled in audit or block mode. The impact can then be analyzed either by looking at the corresponding Windows Event log entries or through advanced hunting queries in Read More …

Like this:

Like Loading...

CategoriesDefender ATP, Exploit GuardTagsAsr, Defender ATP, Eventlog, Exploit Guard, PowerShell

How to Configure Splunk to pull Windows Defender ATP alerts

Posted on28 March 201928 March 2019Leave a comment

Windows Defender ATP provides SIEM integration, allowing you to pull alerts from Windows Defender ATP Security Center into Splunk. The SIEM integration uses the Windows Defender ATP Alerts Rest API. Since I have an actual customer demand for such an Read More …

Like this:

Like Loading...

CategoriesDefender ATP, SplunkTagsDefender ATP, RestAPI, Splunk, wdatp

Check Windows Defender ATP Client Status with PowerShell

Posted on22 February 201922 February 20192 Comments

Here’s a little utility to check the status of Windows Defender ATP on a local or remote client. I basically took some code from the WDATP connectivity verification tool, removed the network connectivity testing part (I might add that later Read More …

Like this:

Like Loading...

CategoriesDefender ATP, PowerShell, UncategorizedTagsDefender ATP, PowerShell, wdatp

Retrieving Windows Defender ATP query API data with PowerShell

Posted on9 January 20189 January 20182 Comments

I am currently working on some automation around Windows Defender, so started to look at the Windows Defender Advanced Threat Protection query API. Note that this API is still in preview. I wrote two functions for this. Connect-WindowsATP is used Read More …

Like this:

Like Loading...

CategoriesDefender ATP, PowerShellTagsAPI, Defender ATP, PowerShell

Post navigation

Newer posts →

Top Posts & Pages

  • How to reapply a Group Policy Preference that is configured to Apply Once
  • Managing Windows 8 Metro Style Apps with DISM
  • Hunting for Local Group Membership changes
  • How to remediate Defender for Endpoint onboarding with ConfigMgr
  • ConfigMgr 2012 Script to retrieve source path locations

 Subscribe in a reader

Follow @alexverboon

Subscribe to Blog via Email

Enter your email address to subscribe to this blog and receive notifications of new posts by email.

Categories

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Token Information

The info portal for tokenization & digital change

Copyright © 2025 Anything about IT. All Rights Reserved. Privacy Policy
Catch Base Pro by Catch Themes
Scroll Up
  • Home
  • About me
  • Blogpost Index
  • Links
  • Privacy Policy
%d