Hi Guys,
Is there an integration for Microsoft Defender XDR available in the SOAR Marketplace?
Hi Guys,
Is there an integration for Microsoft Defender XDR available in the SOAR Marketplace?
Best answer by gsec
Thanks @Ben_T for your response,
Yes, I noticed these integrations are available in the marketplace. However, I was specifically looking for an integration tailored to Microsoft Defender XDR. I couldn’t find one for XDR, so I was wondering if any of the available Defender integrations also cover XDR?
Hey,
you can use ATP and 365 for this or if you have also Azure Sentinel active you could transfer all alerts to Sentinel and then to SOAR that works with analytic rules from Sentinel and the default Rules from Defender ATP / Defender for Endpoint.
Then you just need a playbook that handle the different Detection Source or the Incident from Azure Sentinel.
Regards,
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.