Create indicators in Microsoft Defender for Endpoint
Create indicators from associated observables of the security incident using the Microsoft Defender for Endpoint.
시작하기 전에
Role required: sn_si.admin, sn_si.analyst
이 태스크 정보
The Microsoft Defender for Endpoint integration allows observable enrichment for all the observable types that are mapped in the Observable-Indicator mapping module.
Create indicators provide you the ability to set a list of indicators for detection, and for blocking prevention and responses. You can create the indicators from associated observable of the security incident.