Configure Get Related Machines from Defender Capability in Microsoft Defender for Endpoint
Get the list of related machines of specific observables.
Before you begin
Note:
Role required: sn_si.admin or sn_si.analystSupported Observable Types are Domain name, SHA1 hash, and Username.
Procedure
- Navigate to .
- Select the security incident that you want to review with the Microsoft Defender for Endpoint information.
- In the Related links section, select Show IoC.
- Select the Associated Observables related list.
- Select the associated observables.
- From the Actions list, select the Get Related Machines from Defender capability.
- Validate the automation activity and activities section.
- View the data, and validate the Microsoft Defender for Endpoint Related Machines details on the related lists.
- View the automation activities of the execution, and validate them.