Anything About IT

Learning, Building, Sharing

How to generate a monthly Defender ATP Threat and Vulnerability Report

Microsoft has updated the Advanced Hunting Schema. Here is how to generate a monthly Defender ATP Threat and Vulnerability report.

Windows Defender, More than just Antivirus – Part 2

In this second part I cover ASR, Controlled Folder Access, Exploit Guard, and Network Protection in Windows Defender.

Microsoft Defender ATP Advanced Hunting – Who's logging on with local admin rights?

Use KQL Advanced Hunting in Microsoft Defender ATP to find out who is logging on with local administrator rights.

Managing Role Based Access (RBAC) for Microsoft Defender Advanced Threat Protection

How to manage Role Based Access Control (RBAC) for Microsoft Defender Advanced Threat Protection.

How to Configure Splunk to pull Windows Defender ATP alerts

Windows Defender ATP provides SIEM integration, allowing you to pull alerts from Windows Defender ATP Security Center into Splunk.