What problem does it solve?
This Skill streamlines complex security operations by consolidating access to Microsoft Defender XDR, Defender for Endpoint (MDE P2), and Microsoft Sentinel into a single, unified interface, reducing the need to navigate multiple portals.
Core Features & Use Cases
- Unified Threat Hunting: Perform advanced KQL queries across endpoint and SIEM data.
- Incident Management: Investigate, manage, and respond to security incidents.
- Endpoint Response: Execute actions like isolating machines or collecting forensic data.
- Vulnerability Management: Track and manage vulnerabilities across your environment.
- Threat Indicator Management: Manage Indicators of Compromise (IoCs) for proactive defense.
- Sentinel Operations: Manage analytics rules, watchlists, and automation rules.
- Use Case: A security analyst can use this Skill to quickly hunt for suspicious processes across all endpoints, investigate any related incidents, isolate a compromised machine, and block identified malicious IP addresses, all from a single command-line interface.
Quick Start
Use the microsoft-defender skill to list all active high-severity incidents.