Perform a manual sighting search in Microsoft Defender for Endpoint
- UpdatedJul 31, 2025
- 2 minutes to read
- Zurich
- Security Incident Response integrations
Select individual or multiple observables and perform a manual sighting search in Microsoft Defender for Endpoint to determine the prevalence of a threat over time.
Before you begin
Role required: sn_si.admin, sn_si.analyst
About this task
The supported Observable types are the following:
- Domain name
- IP address (V4)
- IP address (V6)
- MD5 hash
- SHA1 hash
- SHA256 hash
Procedure