-
Notifications
You must be signed in to change notification settings - Fork 195
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
[Request] MS Defender for Endpoint, third party response integration #6303
Comments
👀 |
Hi @caitlinbetz @ashokaditya 👋
Thanks! |
➡ Yes, these are the only ones with this release.
➡ The process is similar to Crowstrike and SentinelONe. At a high-level:
Screen capture of the integration setup below to give you a quick view on its setup:
No, but you can create a 9.0 env. in cloud using the latest snapshot. click below to see some instructions. QASource has started testing this feature and in an issue they opened today, they list an env. you can access - maybe use that? See details here. But - if you would like to have your own - once you have the stack env. created, I could just run a script against to set it all up. Just send me the env. URL and login credentials and I'll do that for you. Expand to see instructionEnable feature flags:
Connector Setup
Integration Setup
Setup a SIEM ruleA SIEM rule needs to be setup to promote events ingested from Microsoft Defender for Endpoint to SIEM alerts. Use the following information when creating that rule:
Onboard a new host in Microsoft Defender
You will likely need to login to MS Defender for Endpoint management system to complete the host onboarding process. The following login credentials can used: |
@paul-tavares @natasha-moore-elastic yes, those index patterns look good to me, the only thing I would add is: |
Description
We are releasing our bidirectional capability with Microsoft Defender for Endpoint, which will allow users to execute host isolation / release of a MDE agent through elastic security.
This is similar to the functionality (and docs) we previously added for Sentinel One and Crowdstrike: https://www.elastic.co/guide/en/security/current/response-actions-config.html
Background & resources
Which documentation set does this change impact?
ESS and serverless
ESS release
N/A
Serverless release
January 27, 2025
Feature differences
Feature will be the same in serverless/ESS
ESS release: 8.18
API docs impact
TBD
Prerequisites, privileges, feature flags
ESS & Serverless, Kibana privileges:
Security solution privilege: Host Isolation (ALL)
Actions and Connectors privilege:: EDR Connectors
The text was updated successfully, but these errors were encountered: