Microsoft Defender
Microsoft Defender is an advanced threat protection solution that provides comprehensive security across endpoints, networks, and cloud environments.
Microsoft Defender is a comprehensive security solution that provides advanced threat protection across devices, identities, and applications. This connector enables seamless integration with Swimlane Turbine, allowing users to automate security operations such as threat detection, incident response, and vulnerability management. By leveraging Microsoft Defender's capabilities, Swimlane Turbine users can enhance their security posture, streamline workflows, and respond to threats in real-time, all without writing a single line of code.
Prerequisites
Before you can use the Microsoft Defender connector for Turbine, you'll need access to the Microsoft Defender API. This requires the following:
- Delegated Flow Authentication using OAuth 2.0 credentials:
- URL: The endpoint for authentication requests.
- Tenant ID: The unique identifier for your Azure AD tenant.
- Username: The username of the account used for authentication.
- Password: The password associated with the username.
- Client ID: The application ID registered in Azure AD.
- Client Secret: The secret key associated with the client ID.
- OAuth2 Client Credentials:
- URL: The endpoint for token requests.
- Client ID: The application ID registered in Azure AD.
- Client Secret: The secret key associated with the client ID.
- Scope: The permissions required for accessing Microsoft Defender resources.
Authentication Methods
OAuth 2.0 client credentials authentication with these parameters:
- URL: Endpoint for Microsoft Defender API
- Client ID: Application ID registered in Azure AD
- Client Secret: Key generated for the application in Azure AD
- Tenant ID or Token URL: At least one of these parameters is required for authentication:
- Tenant ID: Identifier for the Azure AD tenant
- Token URL: Token URL for Azure AD. Must start with https://login.microsoftonline.com/, followed by the tenant_id, and appended with /oauth2/v2.0/token.
- Scope: Permissions the application requires
Delegated Flow Authentication with these parameters:
- URL: Endpoint for Microsoft Defender API
- Tenant ID: Identifier for the Azure AD tenant
- Username: The username for delegated access
- Password: The password for delegated access
- Client ID: Application ID registered in Azure AD
- Client Secret: Key generated for the application in Azure AD
- Login URL: Login URL. Default value is https://login.microsoftonline.com. (Optional).
- scope: Permissions the app requires. Optional field. (Optional).
Additional Notes about Asset
- Please make sure to pass atleast one of the Tenant ID or Token URL in the inputs for the asset.
Asset and Permissions Setup
In order to set up the asset, you need the following:
- Azure Application Client ID
- Azure Application Client Secret
- Azure Tenant ID
Suggested API permissions
Register an app in Microsoft Entra ID (Azure AD) and add API permissions for Windows Defender ATP. In the portal: Add a permission β APIs my organization uses β search for WindowsDefenderATP or Windows Defender ATP.
- Application permissions β use with OAuth 2.0 client credentials (service-to-service).
- Delegated permissions β use with delegated (user) sign-in; names are the delegated equivalents (for example, Alert.Read instead of Alert.Read.All).
- Grant only what your playbooks need. Microsoft may update requirements; use Microsoft Defender for Endpoint API documentation as the source of truth.
- For delegated auth, the user also needs appropriate roles in the Microsoft Defender portal.
Common bundles (illustrative):
- Read alerts and machine context β Alert.Read.All, Machine.Read.All, plus File.Read.All, Ip.Read.All, Url.Read.All, or User.Read.All if you use file, IP, domain, or user-scoped actions.
- Advanced hunting β AdvancedQuery.Read.All.
- Indicators β Ti.Read.All (read), Ti.ReadWrite.All (create/update/delete/import).
- Incidents (Defender XDR API) β Incident.Read.All / Incident.ReadWrite.All for api/incidents actions.
- Response actions β add Machine.Isolate, Machine.Scan, Machine.StopAndQuarantine, Machine.RestrictExecution, Machine.CollectForensics, Machine.ReadWrite.All (for example offboarding) as needed.
The Required API permissions by actionο»Ώ section lists Entra permission names for each connector action.
Steps to create the Azure app:
- Go to the App Registration page in the Azure portal.
- Click New Registration.
- Enter a name for your new application and choose Accounts in this organizational directory only, then click Register at the bottom.
- Navigate to the API permissions tab on the left navigation menu.
- Select Add a permission.
- Select APIs my organization uses tab or any Permissions relevant tab.
- Search for Windows Defender ATP / WindowsDefenderATP, then add the Application permissions or Delegated permissions from Required API permissions by actionο»Ώ for the connector actions you will run.
- Click the Add permissions button at the bottom of the page.
- Select Grant admin consent for your organization and confirm each permission shows Granted for your directory.
- Navigate to the Certificates & secrets tab and select New client secret.
- Fill out the description and expiration, then click the Add button at the bottom.
- The Value of the secret you just created is the Client Secret needed for the Swimlane asset.
- Navigate to the Overview tab on the left menu.
- The Client ID and Tenant ID needed in the asset are shown on this page.
The Client ID, Tenant ID, and Client Secret described in the steps above are the credentials you need for the asset.
Capabilities
The Microsoft Defender Advanced Threat Protection integration provides the following capabilities:
- Cancel Machine Action
- Create Alert
- Decode Generated Bearer Token
- Delete Indicator by ID
- Export Software Vulnerabilities by Machine
- Export Software Vulnerability Changes by Machine
- Get Alert
- Get Alert Domains
- Get Alert IPs
- Get Alert Machine Information
- Get Alert User Information
- Get Alerts
- Get Domain Related Alerts
- Get Domain Related Machines
- Get Domain Seen Organization ... and so on
Notes
- Use these scopes in the asset as required for the API host and permissions you granted:
- https://api.securitycenter.microsoft.com/.default
- https://security.microsoft.com/mtp/.default
The token must include scopes for every Entra permission your app uses on that host.
- When using a particular action, confirm the required permissions in Microsoft Defender for Endpoint API documentation if anything fails or after Microsoft changes API requirements.
Additional Information about Capabilities
The Microsoft Defender Advanced Threat Protection API allows the user to run queries against their enrolled systems. You can find information about the Advanced Hunting API here.
Additionally, Microsoft has provided example queries here.
Installation Considerations
To utilize this Connector, you must have access to an E5 license of Microsoft Defender ATP. Additionally, you must create a new application in Azure Active Directory:
- Start a new trial of Microsoft Defender ATP or use your existing license to access the API.
- If you have not done so already, please follow the initial setup instructions here.
- Once you have Microsoft Defender ATP deployed, create a new application in Microsoft Entra ID as described in Asset and Permissions Setupο»Ώ.
Application Permissions
Authoritative per-action mappings are in Required API permissions by actionο»Ώ. The table uses Windows Defender ATP (WindowsDefenderATP) Application permission names; for delegated auth, use the usual .Read / .ReadWrite delegated names shown in the second column.
Required API permissions by action
Permissions below are for the Windows Defender ATP API in Microsoft Entra ID. If Microsoft updates an endpointβs requirements, follow their documentation. Where multiple permissions are listed, grant all of them for that action.
Action | Method | API path (relative) | Application permissions | Delegated permissions (typical) |
|---|---|---|---|---|
Cancel Machine Action | POST | /api/machineactions/{machineactionid}/cancel | Machine.ReadWrite.All | Machine.ReadWrite |
Create Alert | POST | /api/alerts/CreateAlertByReference | Alert.ReadWrite.All | Alert.ReadWrite |
Decode Generated Bearer Token | β | (none β decodes token locally) | (none) | (none) |
Delete Indicator by ID | DELETE | /api/indicators/{id} | Ti.ReadWrite.All | Ti.ReadWrite |
Export Software Vulnerabilities by Machine | GET | /api/machines/SoftwareVulnerabilitiesByMachine | Vulnerability.Read.All, Machine.Read.All | Vulnerability.Read, Machine.Read |
Export Software Vulnerability Changes by Machine | GET | /api/machines/SoftwareVulnerabilityChangesByMachine | Vulnerability.Read.All, Machine.Read.All | Vulnerability.Read, Machine.Read |
Get Alert | GET | /api/alerts/{id} | Alert.Read.All | Alert.Read |
Get Alert Domains | GET | /api/{id}/domains | Alert.Read.All | Alert.Read |
Get Alert IPs | GET | /api/{id}/ips | Alert.Read.All | Alert.Read |
Get Alert Machine Information | GET | /api/alerts/{id}/machine | Alert.Read.All, Machine.Read.All | Alert.Read, Machine.Read |
Get Alert User Information | GET | /api/alerts/{id}/user | Alert.Read.All, User.Read.All | Alert.Read, User.Read |
Get Alerts | GET | /api/alerts | Alert.Read.All | Alert.Read |
Get Domain Related Alerts | GET | /api/domains/{domain}/alerts | Url.Read.All, Alert.Read.All | Url.Read, Alert.Read |
Get Domain Related Machines | GET | /api/domains/{domain}/machines | Url.Read.All, Machine.Read.All | Url.Read, Machine.Read |
Get Domain Seen Organization | GET | /api/domains/{domain} | Url.Read.All | Url.Read |
Get Domain Statistics | GET | /api/domains/{domain}/stats | Url.Read.All | Url.Read |
Get File Information | GET | /api/files/{id} | File.Read.All | File.Read.All |
Get File Related Alerts | GET | /api/files/{id}/alerts | File.Read.All, Alert.Read.All | File.Read.All, Alert.Read |
Get File Related Machines | GET | /api/files/{id}/machine | File.Read.All, Machine.Read.All | File.Read.All, Machine.Read |
Get File Statistics | GET | /api/files/{id}/stats | File.Read.All | File.Read.All |
Get Incident | GET | api/incidents/{id} | Incident.Read.All | Incident.Read |
Get Incidents List | GET | api/incidents | Incident.Read.All | Incident.Read |
Get Indicators | GET | /api/indicators | Ti.Read.All | Ti.Read |
Get Investigation | GET | /api/investigations/{id} | Alert.Read.All | Alert.Read |
Get Investigation Collection Package | GET | /api/machineactions/{id}/getPackageUri | Machine.CollectForensics, Machine.Read.All | Machine.CollectForensics, Machine.Read |
Get IP Related Alerts | GET | /api/ips/{ip}/alerts | Ip.Read.All, Alert.Read.All | Ip.Read, Alert.Read |
Get IP Related Machines | GET | /api/ips/{ip}/machines | Ip.Read.All, Machine.Read.All | Ip.Read, Machine.Read |
Get IP Seen Organization | GET | /api/ips/{ip} | Ip.Read.All | Ip.Read |
Get IP Statistics | GET | /api/ips/{ip}/stats | Ip.Read.All | Ip.Read |
Get Machine | GET | /api/machines/{id} | Machine.Read.All | Machine.Read |
Get Machine Action | GET | /api/machineactions/{id} | Machine.Read.All | Machine.Read |
Get Machine Logon Users | GET | /api/machines/{id}/logonusers | Machine.Read.All, User.Read.All | Machine.Read, User.Read |
Get Machine Related Alerts | GET | /api/machines/{id}/alerts | Machine.Read.All, Alert.Read.All | Machine.Read, Alert.Read |
Get Machines | GET | /api/machines | Machine.Read.All | Machine.Read |
Get User Related Alerts | GET | /api/users/{id}/alerts | User.Read.All, Alert.Read.All | User.Read, Alert.Read |
Get User Related Machines | GET | /api/users/{id}/machines | User.Read.All, Machine.Read.All | User.Read, Machine.Read |
Get Vulnerability by ID | GET | /api/vulnerabilities/{vulnerability_id} | Vulnerability.Read.All | Vulnerability.Read |
Import Indicators | POST | api/indicators/import | Ti.ReadWrite.All | Ti.ReadWrite |
Invoke Collection Investigation Package | POST | /api/machines/{id}/collectInvestigationPackage | Machine.CollectForensics | Machine.CollectForensics |
Isolate Machine | POST | /api/machines/{id}/isolate | Machine.Isolate | Machine.Isolate |
List All Remediation Activities | GET | /api/remediationtasks | Alert.Read.All | Alert.Read |
List Devices by Vulnerability | GET | /api/vulnerabilities/{vulnerability_id}/machineReferences | Vulnerability.Read.All, Machine.Read.All | Vulnerability.Read, Machine.Read |
List Vulnerabilities | GET | /api/vulnerabilities | Vulnerability.Read.All | Vulnerability.Read |
List Vulnerabilities by Machine and Software | GET | /api/vulnerabilities/machinesVulnerabilities | Vulnerability.Read.All | Vulnerability.Read |
Offboard Machine | POST | /api/machines/{id}/offboard | Machine.ReadWrite.All | Machine.ReadWrite |
Query Advanced Hunting | POST | /api/advancedhunting/run | AdvancedQuery.Read.All | AdvancedQuery.Read |
Remove App Restriction | POST | /api/machines/{id}/unrestrictCodeExecution | Machine.RestrictExecution | Machine.RestrictExecution |
Reset User Password | POST | /users/{id}/authentication/methods/{passwordMethodId}/resetPassword (Microsoft Graph) | (application not supported) | UserAuthenticationMethod.ReadWrite.All |
Restrict App Execution | POST | /api/machines/{id}/restrictCodeExecution | Machine.RestrictExecution | Machine.RestrictExecution |
Revoke User Sign-In Sessions | POST | /users/{id}/revokeSignInSessions (Microsoft Graph) | User.RevokeSessions.All | User.RevokeSessions.All |
Run Antivirus Scan | POST | /api/machines/{id}/runAntiVirusScan | Machine.Scan | Machine.Scan |
Run Query | POST | /api/advancedqueries/run | AdvancedQuery.Read.All | AdvancedQuery.Read |
Start Investigation | POST | /api/machines/{id}/startInvestigation | Alert.ReadWrite.All | Alert.ReadWrite |
Stop and Quarantine File | POST | /api/machines/{id}/StopAndQuarantineFile | Machine.StopAndQuarantine | Machine.StopAndQuarantine |
Submit Indicator | POST | /api/indicators | Ti.ReadWrite.All | Ti.ReadWrite |
UnIsolate Machine | POST | /api/machines/{id}/unisolate | Machine.Isolate | Machine.Isolate |
Update Alert | PATCH | /api/alerts/{id} | Alert.ReadWrite.All | Alert.ReadWrite |
Update Incident by ID | PATCH | api/incidents/{id} | Incident.ReadWrite.All | Incident.ReadWrite |
Get Indicators: If Ti.Read.All is not available or insufficient in your tenant, use Ti.ReadWrite.All / Ti.ReadWrite.
Get Investigation: Confirm against Microsoft if your tenant requires an additional investigation-specific scope.
Configurations
Microsoft Defender Password Grant (Delegated Auth)
Authenticates on behalf of a user using oauth 2.0 credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
login_url | ο»Ώ | string | Optional |
tenant_id | ο»Ώ | string | Required |
oauth_un | The username for authentication | string | Required |
oauth_pwd | The password for authentication | string | Required |
oauth_cl_id | The client ID | string | Required |
oauth_cl_secret | The client secret. | string | Required |
scope | Permission scopes for this action. | array | Optional |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
Microsoft Defender Oauth 2.0 Client Credentials
Authenticates using oauth 2.0 client credentials
Configuration Parameters
Parameter | Description | Type | Required |
|---|---|---|---|
url | A URL to the target host. | string | Required |
tenant_id | The Tenant ID. | string | Optional |
token_url | Must start with https://login.microsoftonline.com/ and then continue with the tenant_id, and then be prepended with /oauth2/v2.0/token | string | Optional |
client_id | The client ID | string | Required |
client_secret | The client secret. | string | Required |
scope | List of permission scopes for this action. | array | Required |
verify_ssl | Verify SSL certificate | boolean | Optional |
http_proxy | A proxy to route requests through. | string | Optional |
ca_cert | A Base64 encoded CA certificate to use for SSL verification | string | Optional |
Actions
Cancel Machine Action
Cancel a pending machine action in Microsoft Defender using the provided 'machineactionid'.
Endpoint
- URL: /api/machineactions/{{machineactionid}}/cancel
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.machineactionid | string | Required | The machine action ID. |
Comment | string | Optional | Comment to associate with the cancellation action. |
Input Example
{"json_body":{"Comment":"Machine action was canceled by automation"},"path_parameters":{"machineactionid":"988cc94e-7a8f-4b28-ab65-54970c5d5018"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
type | string | Type of the resource |
scope | string | Output field: scope |
requestor | string | Output field: requestor |
externalID | string | Unique identifier |
requestSource | string | Output field: requestSource |
commands | array | Output field: commands |
cancellationRequestor | string | Output field: cancellationRequestor |
requestorComment | string | Output field: requestorComment |
cancellationComment | string | Output field: cancellationComment |
status | string | Status value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
cancellationDateTimeUtc | string | Output field: cancellationDateTimeUtc |
creationDateTimeUtc | string | Output field: creationDateTimeUtc |
lastUpdateDateTimeUtc | string | Output field: lastUpdateDateTimeUtc |
title | string | Output field: title |
relatedFileInfo | string | Output field: relatedFileInfo |
Output Example
{"status_code":200,"response_headers":{"Date":"Fri, 07 Feb 2025 10:57:23 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","mise-correlation-id":"8d39c870-35e0-4d26-aa40-b15aa1b5c79a","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"id":"5382f7ea-7557-4ab7-9782-d50480024a...
Create Alert
Generate a new alert in Microsoft Defender using details like machine ID, severity, and event time for threat identification.
Endpoint
- URL: /api/alerts/CreateAlertByReference
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
machineId | string | Optional | Id of the device on which the event was identified. |
severity | string | Optional | Severity of the alert. |
title | string | Optional | Title for the alert. |
description | string | Optional | Description of the alert. |
recommendedAction | string | Optional | Security officer needs to take this action when analyzing the alert. |
eventTime | string | Optional | The precise time of the event as string, as obtained from advanced hunting. |
reportId | string | Optional | The reportId of the event, as obtained from advanced hunting. |
category | string | Optional | Category of the alert. |
Input Example
{"json_body":{"machineId":"1e5bc9d7e413ddd7902c2932e418702b84d0cc07","severity":"Low","title":"Low-reputation arbitrary code executed by signed executable","description":"Binaries signed by Microsoft can be used to run low-reputation arbitrary code. This technique hides the execution of malicious code within a trusted process. As a result, the trusted process might exhibit suspicious behaviors, such as opening a listening port or connecting to a command-and-control (C&C) server.","recommendedAction":"nothing","eventTime":"2018-08-03T16:45:21.7115183Z","reportId":"20776","category":"Exploit"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
incidentId | number | Unique identifier |
investigationId | object | Unique identifier |
assignedTo | object | Output field: assignedTo |
severity | string | Output field: severity |
status | string | Status value |
classification | object | Output field: classification |
determination | object | Output field: determination |
investigationState | string | Output field: investigationState |
detectionSource | string | Output field: detectionSource |
detectorId | string | Unique identifier |
category | string | Output field: category |
threatFamilyName | object | Name of the resource |
title | string | Output field: title |
description | string | Output field: description |
alertCreationTime | string | Time value |
firstEventTime | string | Time value |
lastEventTime | string | Time value |
lastUpdateTime | string | Time value |
resolvedTime | object | Time value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
rbacGroupName | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Transfer-Encoding":"chunked","Content-Type":"application/json","Content-Encoding":"gzip","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000","Date":"Tue, 30 Apr 2024 10:36:47 GMT"},"reason":"OK","json_body":{"id":"da637472900382838869_1364969609","incidentId":1126093,"investigationId":null,"assignedTo":null,"severity":"Low","status":"New","classification":null,"determination":null,"investigationState":"Queued","detectionSource":"Windows...
Decode Generated Bearer Token
Decode a JWT token to reveal the contents of Microsoft Defender bearer tokens for integration purposes.
Endpoint
- Method: GET
Output
Parameter | Type | Description |
|---|---|---|
data | object | Response data |
data.aud | string | Response data |
data.iss | string | Response data |
data.iat | number | Response data |
data.nbf | number | Response data |
data.exp | number | Response data |
data.aio | string | Response data |
data.appid | string | Response data |
data.appidacr | string | Response data |
data.idp | string | Response data |
data.oid | string | Response data |
data.rh | string | Response data |
data.sub | string | Response data |
data.tenant_region_scope | string | Response data |
data.tid | string | Response data |
data.uti | string | Response data |
data.ver | string | Response data |
Output Example
{"data":{"aud":"00000002-0000-0000-c000-000000000000","iss":"https://sts.windows.net/f5d73c4c-bb3d-421b-8bee-424916a4acca/","iat":1711522981,"nbf":1711522981,"exp":1711526881,"aio":"E2NgYNBqzq9y5r7iP+fO4k0fVva1AQA=","appid":"c806de2d-6f0a-4fcf-91b9-fc285ee6da31","appidacr":"1","idp":"https://sts.windows.net/f5d73c4c-bb3d-421b-8bee-424916a4acca/","oid":"84e31d9d-b042-4ced-8437-7c17db9ee8b4","rh":"0.AS0ATDzX9T27G0KL7kJJFqSsygIAAAAAAAAAwAAAAAAAAAAtAAA.","sub":"84e31d9d-b042-4ced-8437-7c17db9ee8b4",...
Delete Indicator by ID
Remove a specified security indicator from Microsoft Defender using the unique ID provided in path parameters.
Endpoint
- URL: /api/indicators/{{id}}
- Method: DELETE
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Delete Indicator by ID action |
Input Example
{"path_parameters":{"id":"995"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 30 May 2024 10:21:38 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","response_text":""}
Export Software Vulnerabilities by Machine
Retrieve a comprehensive snapshot of software vulnerabilities, including device, OS, and software details for each onboarded machine in Microsoft Defender. Ideal for seeding SIEM, CMDB, or asset-vulnerability mapping.
Endpoint
- URL: /api/machines/SoftwareVulnerabilitiesByMachine
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.pageSize | number | Optional | Number of results per page returned by the export endpoint. Defaults to 50,000 and supports up to 200,000. Follow the @odata.nextLink in the response to retrieve subsequent pages. |
Input Example
{"parameters":{"pageSize":50000}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.DeviceId | string | Unique Defender device identifier. Use this as the stable primary key when joining vulnerability data with machine inventory. |
value.DeviceName | string | Hostname reported by Defender at the time of export. |
value.OSPlatform | string | Value for the parameter |
value.SoftwareVendor | string | Value for the parameter |
value.SoftwareName | string | Name of the resource |
value.SoftwareVersion | string | Value for the parameter |
value.CveId | string | Unique identifier |
value.Severity | string | Defender severity rating (Low, Medium, High, Critical). |
value.CvssScore | number | Value for the parameter |
value.RecommendedSecurityUpdate | string | KB number or remediation reference for the vulnerability, when available. |
value.RecommendedSecurityUpdateId | string | Unique identifier |
@odata.nextLink | string | Continuation URL for the next page of results. Follow it until it is no longer present in the response. |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 19 May 2026 10:15:00 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Collection(microsoft.wind......
Export Software Vulnerability Changes by Machine
Retrieve incremental software vulnerability changes per device from Microsoft Defender since a given timestamp for ongoing SIEM, SOAR, or CMDB sync.
Endpoint
- URL: /api/machines/SoftwareVulnerabilityChangesByMachine
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.sinceTime | string | Required | ISO 8601 UTC timestamp marking the lower bound of the change window. Required. Maximum lookback is 14 days; for older windows perform a new full baseline export instead. |
parameters.pageSize | number | Optional | Number of results per page returned by the export endpoint. Defaults to 50,000 and supports up to 200,000. Follow the @odata.nextLink in the response to retrieve subsequent pages. |
Input Example
{"parameters":{"sinceTime":"2026-05-19T00:00:00Z","pageSize":50000}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.EventTime | string | Timestamp when Defender recorded the vulnerability change. |
value.Action | string | Type of change. Common values are VulnerabilityFound, VulnerabilityResolved and VulnerabilityUpdated. |
value.DeviceId | string | Unique Defender device identifier. Use this as the stable primary key when joining vulnerability change data with machine inventory. |
value.DeviceName | string | Name of the resource |
value.OSPlatform | string | Value for the parameter |
value.SoftwareVendor | string | Value for the parameter |
value.SoftwareName | string | Name of the resource |
value.SoftwareVersion | string | Value for the parameter |
value.CveId | string | Unique identifier |
value.Severity | string | Value for the parameter |
value.CvssScore | number | Value for the parameter |
value.RecommendedSecurityUpdate | string | Value for the parameter |
value.RecommendedSecurityUpdateId | string | Unique identifier |
@odata.nextLink | string | Continuation URL for the next page of results. Follow it until it is no longer present in the response. |
Output Example
{"status_code":200,"response_headers":{"Date":"Wed, 20 May 2026 08:13:00 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Collection(microsoft.wind......
Get Alert
Retrieve detailed information for a specified alert in Microsoft Defender using the unique alert ID.
Endpoint
- URL: /api/alerts/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Alert action |
Input Example
{"path_parameters":{"id":"ar638180599315648136_73827727"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
incidentId | number | Unique identifier |
investigationId | number | Unique identifier |
assignedTo | string | Output field: assignedTo |
severity | string | Output field: severity |
status | string | Status value |
classification | object | Output field: classification |
determination | object | Output field: determination |
investigationState | string | Output field: investigationState |
detectionSource | string | Output field: detectionSource |
detectorId | string | Unique identifier |
category | string | Output field: category |
threatFamilyName | object | Name of the resource |
title | string | Output field: title |
description | string | Output field: description |
alertCreationTime | string | Time value |
firstEventTime | string | Time value |
lastEventTime | string | Time value |
lastUpdateTime | string | Time value |
resolvedTime | string | Time value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 13:05:30 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Alerts/$entity","id":"ar6381...
Get Alert Domains
Retrieve domain information associated with a specific Microsoft Defender alert using the unique alert ID.
Endpoint
- URL: /api/{{id}}/domains
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Alert Domains action |
Input Example
{"path_parameters":{"id":"ar638180599315648136_73827727"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 13:08:46 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get Alert IPs
Retrieve IP addresses linked to a specific Microsoft Defender alert using the provided alert ID.
Endpoint
- URL: /api/{{id}}/ips
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Alert IPs action |
Input Example
{"path_parameters":{"id":"ar638180599315648136_73827727"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 13:11:16 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get Alert Machine Information
Retrieve detailed machine information associated with a specific Microsoft Defender alert using the unique alert ID.
Endpoint
- URL: /api/alerts/{{id}}/machine
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Alert Machine Information action |
Input Example
{"path_parameters":{"id":"ar638180599315648136_73827727"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
mergedIntoMachineId | object | Unique identifier |
isPotentialDuplication | boolean | Output field: isPotentialDuplication |
isExcluded | boolean | Output field: isExcluded |
exclusionReason | object | Response reason phrase |
computerDnsName | string | Name of the resource |
firstSeen | string | Output field: firstSeen |
lastSeen | string | Output field: lastSeen |
osPlatform | string | Output field: osPlatform |
osVersion | object | Output field: osVersion |
osProcessor | string | Output field: osProcessor |
version | string | Output field: version |
lastIpAddress | string | Output field: lastIpAddress |
lastExternalIpAddress | string | Output field: lastExternalIpAddress |
agentVersion | string | Output field: agentVersion |
osBuild | number | Output field: osBuild |
healthStatus | string | Status value |
deviceValue | string | Value for the parameter |
rbacGroupId | number | Unique identifier |
rbacGroupName | object | Name of the resource |
riskScore | string | Score value |
exposureLevel | string | Output field: exposureLevel |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 13:16:32 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Machines/$entity","id":"556b...
Get Alert User Information
Retrieve detailed user information associated with a specific Microsoft Defender alert using the unique alert ID.
Endpoint
- URL: /api/alerts/{{id}}/user
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Alert User Information action |
Input Example
{"path_parameters":{"id":"ar638180599315648136_73827727"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.target | string | Error message if any |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 13:19:32 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","json_body":{"error":{"code":"ResourceNotFound","message":"There is no User related to alert ar638180599315648136_73827727","target":"|f712eef2-447d37a1beaf6d2b."}}}
Get Alerts
Retrieve a comprehensive list of alerts from Microsoft Defender to identify potential security threats.
Endpoint
- URL: /api/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Parameters for the Get Alerts action |
parameters.$select | string | Optional | Parameters for the Get Alerts action |
parameters.$orderby | string | Optional | Parameters for the Get Alerts action |
parameters.$top | number | Optional | Parameters for the Get Alerts action |
parameters.$skip | number | Optional | Parameters for the Get Alerts action |
parameters.$count | boolean | Optional | Parameters for the Get Alerts action |
parameters.$expand | string | Optional | Parameters for the Get Alerts action |
Input Example
{"parameters":{"$filter":"type eq 'Microsoft.Compute/virtualMachines' and name eq 'myVM'","$select":"PROPERTY1,PROPERTY2","$orderby":"PROPERTY_NAME asc","$top":10,"$skip":0,"$count":true,"$expand":"RELATED_ENTITY_NAME"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.incidentId | number | Unique identifier |
value.investigationId | object | Unique identifier |
value.assignedTo | object | Value for the parameter |
value.severity | string | Value for the parameter |
value.status | string | Status value |
value.classification | object | Value for the parameter |
value.determination | object | Value for the parameter |
value.investigationState | string | Value for the parameter |
value.detectionSource | string | Value for the parameter |
value.detectorId | string | Unique identifier |
value.category | string | Value for the parameter |
value.threatFamilyName | object | Name of the resource |
value.title | string | Value for the parameter |
value.description | string | Value for the parameter |
value.alertCreationTime | string | Value for the parameter |
value.firstEventTime | string | Value for the parameter |
value.lastEventTime | string | Value for the parameter |
value.lastUpdateTime | string | Value for the parameter |
value.resolvedTime | object | Value for the parameter |
value.machineId | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 12:52:40 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Alerts","value":[{"id":"ar63...
Get Domain Related Alerts
Retrieve Microsoft Defender alerts specific to a domain using the 'domain' path parameter for targeted results.
Endpoint
- URL: /api/domains/{{domain}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain | string | Required | Parameters for the Get Domain Related Alerts action |
Input Example
{"path_parameters":{"domain":"google.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.file_name | string | Name of the resource |
value.file | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:30:41 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Alerts","value":[]}}
Get Domain Related Machines
Retrieve a list of machines associated with a specified domain in Microsoft Defender. Requires 'domain' as a path parameter.
Endpoint
- URL: /api/domains/{{domain}}/machines
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain | string | Required | Parameters for the Get Domain Related Machines action |
Input Example
{"path_parameters":{"domain":"google.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.mergedIntoMachineId | object | Unique identifier |
value.isPotentialDuplication | boolean | Value for the parameter |
value.isExcluded | boolean | Value for the parameter |
value.exclusionReason | object | Value for the parameter |
value.computerDnsName | string | Name of the resource |
value.firstSeen | string | Value for the parameter |
value.lastSeen | string | Value for the parameter |
value.osPlatform | string | Value for the parameter |
value.osVersion | object | Value for the parameter |
value.osProcessor | string | Value for the parameter |
value.version | string | Value for the parameter |
value.lastIpAddress | string | Value for the parameter |
value.lastExternalIpAddress | string | Value for the parameter |
value.agentVersion | string | Value for the parameter |
value.osBuild | number | Value for the parameter |
value.healthStatus | string | Status value |
value.deviceValue | string | Value for the parameter |
value.rbacGroupId | number | Unique identifier |
value.rbacGroupName | object | Name of the resource |
value.riskScore | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:32:36 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Machines","value":[{}]}}
Get Domain Seen Organization
Determine if Microsoft Defender has observed a specific domain within the organization. Requires 'domain' as a path parameter.
Endpoint
- URL: /api/domains/{{domain}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain | string | Required | Parameters for the Get Domain Seen Organization action |
Input Example
{"path_parameters":{"domain":"facebook.net"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 18:12:16 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get Domain Statistics
Retrieve statistical data for a specified domain from Microsoft Defender using the 'domain' path parameter.
Endpoint
- URL: /api/domains/{{domain}}/stats
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.domain | string | Required | Parameters for the Get Domain Statistics action |
Input Example
{"path_parameters":{"domain":"google.com"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
host | string | Output field: host |
orgPrevalence | string | Output field: orgPrevalence |
orgFirstSeen | string | Output field: orgFirstSeen |
orgLastSeen | string | Output field: orgLastSeen |
organizationPrevalence | number | Output field: organizationPrevalence |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:35:52 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#microsoft.windowsDefender......
Get File Information
Retrieve detailed information for a specific file in Microsoft Defender using the unique file identifier provided as a path parameter.
Endpoint
- URL: /api/files/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get File Information action |
Input Example
{"path_parameters":{"id":"6532ec91d513acc05f43ee0aa3002599729fd3e1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
sha1 | string | Output field: sha1 |
sha256 | string | Output field: sha256 |
md5 | string | Output field: md5 |
globalPrevalence | number | Output field: globalPrevalence |
globalFirstObserved | string | Output field: globalFirstObserved |
globalLastObserved | string | Output field: globalLastObserved |
size | number | Output field: size |
fileType | object | Type of the resource |
isPeFile | boolean | Output field: isPeFile |
filePublisher | object | Output field: filePublisher |
fileProductName | object | Name of the resource |
signer | object | Output field: signer |
issuer | object | Output field: issuer |
signerHash | object | Output field: signerHash |
isValidCertificate | object | Unique identifier |
determinationType | string | Type of the resource |
determinationValue | object | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:37:52 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Files/$entity","sha1":"6532e...
Get File Related Alerts
Retrieve Microsoft Defender alerts associated with a file using its unique identifier provided in the path parameters.
Endpoint
- URL: /api/files/{{id}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get File Related Alerts action |
Input Example
{"path_parameters":{"id":"6532ec91d513acc05f43ee0aa3002599729fd3e1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.file_name | string | Name of the resource |
value.file | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:39:45 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Alerts","value":[]}}
Get File Related Machines
Retrieve machines linked to a file's unique ID in Microsoft Defender to assess network impact. Requires the file's ID as a path parameter.
Endpoint
- URL: /api/files/{{id}}/machine
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get File Related Machines action |
Input Example
{"path_parameters":{"id":"6532ec91d513acc05f43ee0aa3002599729fd3e1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 17:41:29 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get File Statistics
Retrieve detailed statistics for a specific file in Microsoft Defender using the file's unique identifier.
Endpoint
- URL: /api/files/{{id}}/stats
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get File Statistics action |
Input Example
{"path_parameters":{"id":"6532ec91d513acc05f43ee0aa3002599729fd3e1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
sha1 | string | Output field: sha1 |
orgPrevalence | string | Output field: orgPrevalence |
organizationPrevalence | number | Output field: organizationPrevalence |
orgFirstSeen | object | Output field: orgFirstSeen |
orgLastSeen | object | Output field: orgLastSeen |
globalPrevalence | string | Output field: globalPrevalence |
globallyPrevalence | number | Output field: globallyPrevalence |
globalFirstObserved | string | Output field: globalFirstObserved |
globalLastObserved | string | Output field: globalLastObserved |
topFileNames | array | Name of the resource |
topFileNames.file_name | string | Name of the resource |
topFileNames.file | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:42:51 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#microsoft.windowsDefender......
Get Incident
Retrieve a specific Microsoft Defender incident by its unique ID provided as a path parameter.
Endpoint
- URL: api/incidents/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Incident ID |
Input Example
{"path_parameters":{"id":437}}
Output
Parameter | Type | Description |
|---|---|---|
@odata.context | string | Response data |
incidentId | number | Unique identifier |
incidentUri | string | Unique identifier |
redirectIncidentId | object | Unique identifier |
incidentName | string | Unique identifier |
createdTime | string | Time value |
lastUpdateTime | string | Time value |
assignedTo | object | Output field: assignedTo |
classification | string | Output field: classification |
determination | string | Output field: determination |
status | string | Status value |
severity | string | Output field: severity |
tags | array | Output field: tags |
tags.file_name | string | Name of the resource |
tags.file | string | Output field: tags.file |
comments | array | Output field: comments |
comments.file_name | string | Name of the resource |
comments.file | string | Output field: comments.file |
alerts | array | Output field: alerts |
alerts.alertId | string | Unique identifier |
alerts.providerAlertId | string | Unique identifier |
alerts.incidentId | number | Unique identifier |
alerts.serviceSource | string | Output field: alerts.serviceSource |
alerts.creationTime | string | Time value |
alerts.lastUpdatedTime | string | Time value |
Output Example
{"@odata.context":"https://api.security.microsoft.com/api/$metadata#Incidents/$entity","incidentId":437,"incidentUri":"https://security.microsoft.com/incidents/437?tid=f5d73c4c-bb3d-421b-8bee-424916a...","redirectIncidentId":null,"incidentName":"Unfamiliar sign-in properties involving one user","createdTime":"2023-05-10T09:33:15.32Z","lastUpdateTime":"2023-05-10T09:33:15.53Z","assignedTo":null,"classification":"Unknown","determination":"NotAvailable","status":"Active","severity":"High","tags":[]...
Get Incidents List
Retrieve and sort a list of incidents from Microsoft Defender to enhance cybersecurity response efforts.
Endpoint
- URL: api/incidents
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Filters results on the lastUpdateTime, createdTime, status, and assignedTo properties. For guidance on using filter, see https://learn.microsoft.com/en-us/graph/filter-query-parameter . |
parameters.$top | number | Optional | Sets the page size of results. |
parameters.$skip | number | Optional | Indexes into a result set. Also used by some actions to implement paging and can be used together with top to manually page results. |
Input Example
{"parameters":{"$filter":"string","$top":123,"$skip":123}}
Output
Parameter | Type | Description |
|---|---|---|
@odata.context | string | Response data |
value | array | Value for the parameter |
value.incidentId | number | Unique identifier |
value.incidentUri | string | Unique identifier |
value.redirectIncidentId | number | Unique identifier |
value.incidentName | string | Unique identifier |
value.createdTime | string | Value for the parameter |
value.lastUpdateTime | string | Value for the parameter |
value.assignedTo | object | Value for the parameter |
value.classification | string | Value for the parameter |
value.determination | string | Value for the parameter |
value.status | string | Status value |
value.severity | string | Value for the parameter |
value.tags | array | Value for the parameter |
value.tags.file_name | string | Name of the resource |
value.tags.file | string | Value for the parameter |
value.comments | array | Value for the parameter |
value.comments.file_name | string | Name of the resource |
value.comments.file | string | Value for the parameter |
value.alerts | array | Value for the parameter |
value.alerts.file_name | string | Name of the resource |
value.alerts.file | string | Value for the parameter |
@odata.nextLink | string | Response data |
Output Example
{"@odata.context":"https://api.security.microsoft.com/api/$metadata#Incidents","value":[{"incidentId":437,"incidentUri":"https://security.microsoft.com/incidents/437?tid=f5d73c4c-bb3d-421b-8bee-424916a4acca","redirectIncidentId":null,"incidentName":"Unfamiliar sign-in properties involving one user","createdTime":"2023-05-10T09:33:15.32Z","lastUpdateTime":"2023-05-10T09:33:15.53Z","assignedTo":null,"classification":"Unknown","determination":"NotAvailable","status":"Active","severity":"High","tags...
Get Indicators
Retrieve threat indicators from Microsoft Defender for pinpointing and analyzing malicious activities.
Endpoint
- URL: /api/indicators
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Parameters for the Get Indicators action |
parameters.$select | string | Optional | Parameters for the Get Indicators action |
parameters.$orderby | string | Optional | Parameters for the Get Indicators action |
parameters.$top | number | Optional | Parameters for the Get Indicators action |
parameters.$skip | number | Optional | Parameters for the Get Indicators action |
parameters.$count | boolean | Optional | Parameters for the Get Indicators action |
parameters.$expand | string | Optional | Parameters for the Get Indicators action |
Input Example
{"parameters":{"$filter":"type eq 'Microsoft.Compute/virtualMachines' and name eq 'myVM'","$select":"PROPERTY1,PROPERTY2","$orderby":"PROPERTY_NAME asc","$top":10,"$skip":0,"$count":true,"$expand":"RELATED_ENTITY_NAME"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.indicatorValue | string | Value for the parameter |
value.indicatorType | string | Type of the resource |
value.action | string | Value for the parameter |
value.createdBy | string | Value for the parameter |
value.severity | string | Value for the parameter |
value.category | number | Value for the parameter |
value.application | object | Value for the parameter |
value.educateUrl | object | URL endpoint for the request |
value.bypassDurationHours | object | Value for the parameter |
value.title | string | Value for the parameter |
value.description | string | Value for the parameter |
value.recommendedActions | object | Value for the parameter |
value.creationTimeDateTimeUtc | string | Value for the parameter |
value.expirationTime | object | Value for the parameter |
value.lastUpdateTime | string | Value for the parameter |
value.lastUpdatedBy | string | Value for the parameter |
value.rbacGroupNames | array | Name of the resource |
value.rbacGroupNames.file_name | string | Name of the resource |
value.rbacGroupNames.file | string | Name of the resource |
value.rbacGroupIds | array | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 18:25:48 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Indicators","value":[{"id":"...
Get Investigation
Retrieve a specific Microsoft Defender investigation using an ID, applicable to both investigation and alert IDs.
Endpoint
- URL: /api/investigations/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The Investigation ID. |
Input Example
{"path_parameters":{"id":"63017"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
startTime | string | Time value |
endTime | string | Time value |
state | string | Output field: state |
cancelledBy | string | Output field: cancelledBy |
statusDetails | string | Status value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
triggeringAlertId | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Fri, 07 Feb 2025 06:30:27 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","mise-correlation-id":"08ce5338-e4be-4eab-a417-d0a5cf40bfac","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"id":"63004","startTime":"2020-01-06T13:...
Get Investigation Collection Package
Retrieve a Microsoft Defender investigation package for an entity using the unique ID provided in path parameters.
Endpoint
- URL: /api/machineactions/{{id}}/getPackageUri
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Investigation Collection Package action |
Input Example
{"path_parameters":{"id":"5b1c0caf-14fe-41e1-83bf-118b1a9e391d"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.target | string | Error message if any |
Output Example
{"status_code":400,"response_headers":{"Date":"Thu, 04 May 2023 17:45:50 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Bad Request","json_body":{"error":{"code":"InvalidInput","message":"Provided Guid is not a valid id for a CollectInvestigationPackage action","target":"|76dce355-471ae6d819782413."}}}
Get IP Related Alerts
Retrieve alerts related to a specified IP address from Microsoft Defender. The IP is required as a path parameter.
Endpoint
- URL: /api/ips/{{ip}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Related Alerts action |
Input Example
{"path_parameters":{"ip":"192.168.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.file_name | string | Name of the resource |
value.file | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:46:57 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#AlertEntitySetName","value":...
Get IP Related Machines
Retrieve a list of machines associated with a specified IP address in Microsoft Defender. Requires the 'ip' path parameter.
Endpoint
- URL: /api/ips/{{ip}}/machines
- Method: get
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Related Machines action |
Input Example
{"path_parameters":{"ip":"192.168.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 17:50:09 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get IP Seen Organization
Determine if an IP address has been observed by Microsoft Defender within the organization. Requires an IP path parameter.
Endpoint
- URL: /api/ips/{{ip}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Seen Organization action |
Input Example
{"path_parameters":{"ip":"192.168.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":404,"response_headers":{"Date":"Thu, 04 May 2023 18:11:35 GMT","Content-Length":"0","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Not Found","response_text":""}
Get IP Statistics
Retrieve statistical data for a specified IP address from Microsoft Defender. This action requires the IP as a path parameter.
Endpoint
- URL: /api/ips/{{ip}}/stats
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.ip | string | Required | Parameters for the Get IP Statistics action |
Input Example
{"path_parameters":{"ip":"192.168.1.1"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
ipAddress | string | Output field: ipAddress |
orgPrevalence | string | Output field: orgPrevalence |
organizationPrevalence | number | Output field: organizationPrevalence |
orgFirstSeen | object | Output field: orgFirstSeen |
orgLastSeen | object | Output field: orgLastSeen |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:49:46 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#microsoft.windowsDefender......
Get Machine
Retrieve details for a specified machine from Microsoft Defender using the provided machine ID.
Endpoint
- URL: /api/machines/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Machine action |
Input Example
{"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
mergedIntoMachineId | object | Unique identifier |
isPotentialDuplication | boolean | Output field: isPotentialDuplication |
isExcluded | boolean | Output field: isExcluded |
exclusionReason | object | Response reason phrase |
computerDnsName | string | Name of the resource |
firstSeen | string | Output field: firstSeen |
lastSeen | string | Output field: lastSeen |
osPlatform | string | Output field: osPlatform |
osVersion | object | Output field: osVersion |
osProcessor | string | Output field: osProcessor |
version | string | Output field: version |
lastIpAddress | string | Output field: lastIpAddress |
lastExternalIpAddress | string | Output field: lastExternalIpAddress |
agentVersion | string | Output field: agentVersion |
osBuild | number | Output field: osBuild |
healthStatus | string | Status value |
deviceValue | string | Value for the parameter |
rbacGroupId | number | Unique identifier |
rbacGroupName | object | Name of the resource |
riskScore | string | Score value |
exposureLevel | string | Output field: exposureLevel |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:56:56 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Machines/$entity","id":"556b...
Get Machine Action
Retrieve details of a specific machine action in Microsoft Defender using the unique action ID provided as a path parameter.
Endpoint
- URL: /api/machineactions/{{id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Machine Action action |
Input Example
{"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.target | string | Error message if any |
Output Example
{"status_code":400,"response_headers":{"Date":"Thu, 04 May 2023 17:56:32 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Bad Request","json_body":{"error":{"code":"BadRequest","message":"The key value (556b3952acb0bff29816d267822305781cc183ec) from request is not val...","target":"|b1838e63-40a6640ddd2719ac."}}}
Get Machine Logon Users
Retrieve a list of users who have logged onto a specific machine using the machine ID in Microsoft Defender.
Endpoint
- URL: /api/machines/{{id}}/logonusers
- Method: get
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Machine Logon Users action |
Input Example
{"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.accountName | string | Name of the resource |
value.accountDomain | string | Value for the parameter |
value.accountSid | object | Unique identifier |
value.firstSeen | string | Value for the parameter |
value.lastSeen | string | Value for the parameter |
value.mostPrevalentMachineId | object | Unique identifier |
value.leastPrevalentMachineId | object | Unique identifier |
value.logonTypes | string | Type of the resource |
value.logOnMachinesCount | object | Value for the parameter |
value.isDomainAdmin | boolean | Value for the parameter |
value.isOnlyNetworkUser | object | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:56:11 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Users","value":[{}]}}
Get Machine Related Alerts
Retrieve Microsoft Defender alerts associated with a specific machine using its unique ID.
Endpoint
- URL: /api/machines/{{id}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Get Machine Related Alerts action |
Input Example
{"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.incidentId | number | Unique identifier |
value.investigationId | object | Unique identifier |
value.assignedTo | object | Value for the parameter |
value.severity | string | Value for the parameter |
value.status | string | Status value |
value.classification | object | Value for the parameter |
value.determination | object | Value for the parameter |
value.investigationState | string | Value for the parameter |
value.detectionSource | string | Value for the parameter |
value.detectorId | string | Unique identifier |
value.category | string | Value for the parameter |
value.threatFamilyName | object | Name of the resource |
value.title | string | Value for the parameter |
value.description | string | Value for the parameter |
value.alertCreationTime | string | Value for the parameter |
value.firstEventTime | string | Value for the parameter |
value.lastEventTime | string | Value for the parameter |
value.lastUpdateTime | string | Value for the parameter |
value.resolvedTime | object | Value for the parameter |
value.machineId | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 17:55:47 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Alerts","value":[{"id":"ar63...
Get Machines
Retrieve a list of machines registered with Microsoft Defender, detailing ID, computer name, and OS information.
Endpoint
- URL: /api/machines
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Parameters for the Get Machines action |
parameters.$select | string | Optional | Parameters for the Get Machines action |
parameters.$orderby | string | Optional | Parameters for the Get Machines action |
parameters.$top | number | Optional | Parameters for the Get Machines action |
parameters.$skip | number | Optional | Parameters for the Get Machines action |
parameters.$count | boolean | Optional | Parameters for the Get Machines action |
parameters.$expand | string | Optional | Parameters for the Get Machines action |
Input Example
{"parameters":{"$filter":"type eq 'Microsoft.Compute/virtualMachines' and name eq 'myVM'","$select":"PROPERTY1,PROPERTY2","$orderby":"PROPERTY_NAME asc","$top":10,"$skip":0,"$count":true,"$expand":"RELATED_ENTITY_NAME"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.mergedIntoMachineId | object | Unique identifier |
value.isPotentialDuplication | boolean | Value for the parameter |
value.isExcluded | boolean | Value for the parameter |
value.exclusionReason | object | Value for the parameter |
value.computerDnsName | string | Name of the resource |
value.firstSeen | string | Value for the parameter |
value.lastSeen | string | Value for the parameter |
value.osPlatform | string | Value for the parameter |
value.osVersion | object | Value for the parameter |
value.osProcessor | string | Value for the parameter |
value.version | string | Value for the parameter |
value.lastIpAddress | string | Value for the parameter |
value.lastExternalIpAddress | string | Value for the parameter |
value.agentVersion | string | Value for the parameter |
value.osBuild | number | Value for the parameter |
value.healthStatus | string | Status value |
value.deviceValue | string | Value for the parameter |
value.rbacGroupId | number | Unique identifier |
value.rbacGroupName | object | Name of the resource |
value.riskScore | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 04 May 2023 18:25:21 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Machines","value":[{}]}}
Get User Related Alerts
Retrieve alerts associated with a specific user in Microsoft Defender using the unique 'user' identifier.
Endpoint
- URL: /api/users/{{id}}/alerts
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID is not the full UPN, but only the user name. (for example, to retrieve alerts for [email protected] use /api/users/user1/alerts). |
Input Example
{"path_parameters":{"id":"Chris Phillips"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.incidentId | number | Unique identifier |
value.investigationId | object | Unique identifier |
value.assignedTo | object | Value for the parameter |
value.severity | string | Value for the parameter |
value.status | string | Status value |
value.classification | object | Value for the parameter |
value.determination | object | Value for the parameter |
value.investigationState | string | Value for the parameter |
value.detectionSource | string | Value for the parameter |
value.detectorId | string | Unique identifier |
value.category | string | Value for the parameter |
value.threatFamilyName | object | Name of the resource |
value.title | string | Value for the parameter |
value.description | string | Value for the parameter |
value.alertCreationTime | string | Value for the parameter |
value.firstEventTime | string | Value for the parameter |
value.lastEventTime | string | Value for the parameter |
value.lastUpdateTime | string | Value for the parameter |
value.resolvedTime | object | Value for the parameter |
value.machineId | string | Unique identifier |
Output Example
{"@odata.context":"string","value":[{"id":"12345678-1234-1234-1234-123456789abc","incidentId":123,"investigationId":{},"assignedTo":{},"severity":"string","status":"active","classification":{},"determination":{},"investigationState":"string","detectionSource":"string","detectorId":"string","category":"string","threatFamilyName":{},"title":"string","description":"string"}]}
Get User Related Machines
Retrieve a list of machines associated with a specific user in Microsoft Defender using the user's unique identifier.
Endpoint
- URL: /api/users/{{id}}/machines
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The ID is not the full UPN, but only the user name. (for example, to retrieve machines for [email protected] use /api/users/user1/machines). |
Input Example
{"path_parameters":{"id":"Chris Phillips"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.computerDnsName | string | Name of the resource |
value.firstSeen | string | Value for the parameter |
value.lastSeen | string | Value for the parameter |
value.osPlatform | string | Value for the parameter |
value.onboardingStatus | string | Status value |
value.osProcessor | string | Value for the parameter |
value.version | string | Value for the parameter |
value.osBuild | number | Value for the parameter |
value.lastIpAddress | string | Value for the parameter |
value.lastExternalIpAddress | string | Value for the parameter |
value.healthStatus | string | Status value |
value.rbacGroupName | string | Name of the resource |
value.rbacGroupId | string | Unique identifier |
value.riskScore | string | Value for the parameter |
value.aadDeviceId | object | Unique identifier |
value.machineTags | array | Value for the parameter |
value.exposureLevel | string | Value for the parameter |
value.deviceValue | string | Value for the parameter |
value.ipAddresses | array | Value for the parameter |
value.ipAddresses.ipAddress | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 26 May 2025 09:21:18 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","mise-correlation-id":"c6ccd948-929b-4073-be4d-df4328ff6798","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securityce...
Get Vulnerability by ID
Retrieve detailed information for a specified vulnerability ID from Microsoft Defender using the vulnerability_id as a path parameter.
Endpoint
- URL: /api/vulnerabilities/{{vulnerability_id}}
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.vulnerability_id | string | Required | Vulnerability ID. |
Input Example
{"path_parameters":{"vulnerability_id":"CVE-2024-7163"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
id | string | Unique identifier |
name | string | Name of the resource |
description | string | Output field: description |
severity | string | Output field: severity |
cvssV3 | number | Output field: cvssV3 |
cvssVector | string | Output field: cvssVector |
exposedMachines | number | Output field: exposedMachines |
publishedOn | string | Output field: publishedOn |
updatedOn | string | Output field: updatedOn |
firstDetected | object | Output field: firstDetected |
publicExploit | boolean | Output field: publicExploit |
exploitVerified | boolean | Output field: exploitVerified |
exploitInKit | boolean | Output field: exploitInKit |
exploitTypes | array | Type of the resource |
exploitTypes.file_name | string | Name of the resource |
exploitTypes.file | string | Type of the resource |
exploitUris | array | Output field: exploitUris |
exploitUris.file_name | string | Name of the resource |
exploitUris.file | string | Output field: exploitUris.file |
cveSupportability | string | Output field: cveSupportability |
tags | array | Output field: tags |
tags.file_name | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 30 Jul 2024 05:46:08 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Vulnerabilities/$entity","id...
Import Indicators
Submit or update a batch of indicators in Microsoft Defender using a specified JSON body format.
Endpoint
- URL: api/indicators/import
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
Indicators | array | Optional | Parameter for Import Indicators |
Indicators.indicatorValue | string | Optional | The Value of the Indicator entity. |
Indicators.indicatorType | string | Optional | The Type of the Indicator entity. |
Indicators.action | string | Optional | The action that is taken if the indicator is discovered in the organization. |
Indicators.application | string | Optional | The application associated with the indicator. |
Indicators.source | string | Optional | The source of the indicator. |
Indicators.expirationTime | string | Optional | The expiration time of the indicator. |
Indicators.sourceType | string | Optional | User in case the Indicator created by a user (for example, from the portal), AadApp in case it submitted using automated application via the API. |
Indicators.severity | string | Optional | The severity of the indicator. The severity of the indicator. Possible values are - Informational, Low, Medium, and High. |
Indicators.title | string | Optional | The title of the indicator. |
Indicators.description | string | Optional | The description of the indicator. |
Indicators.recommendedActions | string | Optional | The recommended actions for the indicator. |
Indicators.rbacGroupNames | array | Optional | RBAC device group names where the indicator is exposed and active. Empty list in case it exposed to all devices. |
Input Example
{"json_body":{"Indicators":[{"indicatorValue":"881c0f10c75e64ec39d257a131fcd531f47dd2cff2070ae94baa347d375126fd","indicatorType":"FileSha256","action":"AlertAndBlock","application":"WindowsDefenderATP","source":"[email protected]","expirationTime":"2021-12-12T00:00:00Z","sourceType":"User","severity":"Informational","title":"Michael test","description":"test","recommendedActions":"nothing","rbacGroupNames":["team1"]}]}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.indicator | string | Value for the parameter |
value.isFailed | boolean | Value for the parameter |
value.failureReason | object | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{},"reason":"OK","json_body":{"value":[{},{}]}}
Invoke Collection Investigation Package
Initiate the collection of an investigation package from a machine using its ID in Microsoft Defender.
Endpoint
- URL: /api/machines/{{id}}/collectInvestigationPackage
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Invoke Collection Investigation Package action |
Comment | string | Optional | Parameter for Invoke Collection Investigation Package |
Input Example
{"json_body":{"comment":"a comment","Isolationtype":"Isolationtype"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Isolate Machine
Initiate isolation of a specified machine in Microsoft Defender using its unique ID. Requires a comment for the action.
Endpoint
- URL: /api/machines/{{id}}/isolate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Isolate Machine action |
Comment | string | Optional | Comment to associate with the action. |
IsolationType | string | Optional | Type of the isolation. Allowed values are Full or Selective. IsolationType controls the type of isolation to perform and can be one of the following Full- Full isolation. Selective- Restrict only limited set of applications from accessing the network. |
Input Example
{"json_body":{"comment":"Isolate machine due to alert 1234","Isolationtype":"Full"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
List All Remediation Activities
Retrieve comprehensive details on all remediation activities, including statuses and identifiers, within Microsoft Defender.
Endpoint
- URL: /api/remediationtasks
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$skip | number | Optional | Indexes into a result set. Also used by some APIs to implement paging and can be used together with $top to manually page results. |
parameters.$top | number | Optional | Sets the page size of results. Top with max value of 10,000. |
parameters.$filter | string | Optional | Filter on createdon and status properties. |
Input Example
{"parameters":{"$skip":1,"$top":1,"$filter":"createdon gt 2018-08-01Z"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.title | string | Value for the parameter |
value.createdOn | string | Value for the parameter |
value.requesterId | string | Unique identifier |
value.requesterEmail | string | Value for the parameter |
value.status | string | Status value |
value.statusLastModifiedOn | string | Status value |
value.description | string | Value for the parameter |
value.relatedComponent | string | Value for the parameter |
value.targetDevices | number | Value for the parameter |
value.rbacGroupNames | array | Name of the resource |
value.fixedDevices | number | Value for the parameter |
value.requesterNotes | string | Value for the parameter |
value.dueOn | string | Value for the parameter |
value.category | string | Value for the parameter |
value.productivityImpactRemediationType | string | Type of the resource |
value.priority | string | Value for the parameter |
value.completionMethod | string | HTTP method to use |
value.completerId | string | Unique identifier |
value.completerEmail | string | Value for the parameter |
value.scid | string | Unique identifier |
Output Example
{"status_code":200,"response_headers":{"Date":"Mon, 10 Feb 2025 05:20:10 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","mise-correlation-id":"245dc196-fb84-44dd-adc4-d91b3abec8da","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securityce...
List Devices by Vulnerability
Retrieve a list of devices affected by a specified vulnerability in Microsoft Defender using the provided vulnerability ID.
Endpoint
- URL: /api/vulnerabilities/{{vulnerability_id}}/machineReferences
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.vulnerability_id | string | Required | Vulnerability ID. |
Input Example
{"path_parameters":{"vulnerability_id":"CVE-2024-7163"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.count | number | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.computerDnsName | string | Name of the resource |
value.osPlatform | string | Value for the parameter |
value.rbacGroupName | string | Name of the resource |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 30 Jul 2024 05:49:03 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Collection(microsoft.wind......
List Vulnerabilities
Retrieve a comprehensive list of vulnerabilities identified by Microsoft Defender for proactive threat mitigation.
Endpoint
- URL: /api/vulnerabilities
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Filter the vulnerabilities using id, name, description, cvssV3, publishedOn, severity, and updatedOn properties. |
parameters.$top | number | Optional | The number of items in the queried collection to be included in the response. Max value of 8,000. |
parameters.$skip | number | Optional | The number of items in the queried collection that are to be skipped and not included in the response. |
Input Example
{"parameters":{"$filter":"publishedOn+ge+2019-11-22T00:00:00Z","$top":10,"$skip":15}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.count | number | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.name | string | Name of the resource |
value.description | string | Value for the parameter |
value.severity | string | Value for the parameter |
value.cvssV3 | number | Value for the parameter |
value.cvssVector | string | Value for the parameter |
value.exposedMachines | number | Value for the parameter |
value.publishedOn | string | Value for the parameter |
value.updatedOn | string | Value for the parameter |
value.firstDetected | object | Value for the parameter |
value.publicExploit | boolean | Value for the parameter |
value.exploitVerified | boolean | Value for the parameter |
value.exploitInKit | boolean | Value for the parameter |
value.exploitTypes | array | Type of the resource |
value.exploitTypes.file_name | string | Name of the resource |
value.exploitTypes.file | string | Type of the resource |
value.exploitUris | array | Value for the parameter |
value.exploitUris.file_name | string | Name of the resource |
value.exploitUris.file | string | Value for the parameter |
value.cveSupportability | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 30 Jul 2024 05:38:55 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Vulnerabilities","@odata.cou...
List Vulnerabilities by Machine and Software
Retrieve a categorized list of vulnerabilities by machine and software from Microsoft Defender.
Endpoint
- URL: /api/vulnerabilities/machinesVulnerabilities
- Method: GET
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
parameters.$filter | string | Optional | Filter the vulnerabilities using id, cveId, machineId, fixingKbId, productName, productVersion, severity, and productVendor properties. |
parameters.$top | number | Optional | The number of items in the queried collection to be included in the response. Max value of 10,000. |
parameters.$skip | number | Optional | The number of items in the queried collection that are to be skipped and not included in the response. |
Input Example
{"parameters":{"$filter":"publishedOn+ge+2019-11-22T00:00:00Z","$top":10,"$skip":15}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
@odata.count | number | Response data |
value | array | Value for the parameter |
value.id | string | Unique identifier |
value.cveId | string | Unique identifier |
value.machineId | string | Unique identifier |
value.fixingKbId | string | Unique identifier |
value.productName | string | Name of the resource |
value.productVendor | string | Value for the parameter |
value.productVersion | string | Value for the parameter |
value.severity | string | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Date":"Tue, 30 Jul 2024 05:42:20 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Collection(microsoft.wind......
Offboard Machine
Initiate the offboarding of a machine from Microsoft Defender using the provided unique machine ID.
Endpoint
- URL: /api/machines/{{id}}/offboard
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Offboard Machine action |
Comment | string | Optional | Parameter for Offboard Machine |
Input Example
{"json_body":{"comment":"a comment"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Query Advanced Hunting
Execute an advanced hunting query in Microsoft Defender to identify threats. Requires a 'Query' parameter.
Endpoint
- URL: /api/advancedhunting/run
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
Query | string | Optional | The query to run. |
Input Example
{"json_body":{"Query":"DeviceProcessEvents | where InitiatingProcessFileName =~ \"powershell.exe\" | project Timestamp, FileName, InitiatingProcessFileName | order by Timestamp desc | limit 2"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
Stats | object | Output field: Stats |
Stats.ExecutionTime | number | Time value |
Stats.resource_usage | object | Output field: Stats.resource_usage |
Stats.resource_usage.cache | object | Output field: Stats.resource_usage.cache |
Stats.resource_usage.cache.memory | object | Output field: Stats.resource_usage.cache.memory |
Stats.resource_usage.cache.disk | object | Output field: Stats.resource_usage.cache.disk |
Stats.resource_usage.cpu | object | Output field: Stats.resource_usage.cpu |
Stats.resource_usage.cpu.user | string | Output field: Stats.resource_usage.cpu.user |
Stats.resource_usage.cpu.kernel | string | Output field: Stats.resource_usage.cpu.kernel |
Stats.resource_usage.cpu.total cpu | string | Output field: Stats.resource_usage.cpu.total cpu |
Stats.resource_usage.memory | object | Output field: Stats.resource_usage.memory |
Stats.resource_usage.memory.peak_per_node | number | Output field: Stats.resource_usage.memory.peak_per_node |
Stats.dataset_statistics | array | Response data |
Stats.dataset_statistics.table_row_count | number | Response data |
Stats.dataset_statistics.table_size | number | Response data |
Schema | array | Output field: Schema |
Schema.Name | string | Name of the resource |
Schema.Type | string | Type of the resource |
Results | array | Result of the operation |
Results.file_name | string | Name of the resource |
Results.file | string | Result of the operation |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 05 Sep 2024 07:29:53 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"Stats":{"ExecutionTime":0.171881,"resource_usage":{},"dataset_statistics":[]},"Schema":[{},{},{}],"Results":[]}}
Remove APP Restriction
Remove an existing application restriction in Microsoft Defender using the specified unique identifier (ID).
Endpoint
- URL: /api/machines/{{id}}/unrestrictCodeExecution
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Remove APP Restriction action |
Comment | string | Optional | Parameter for Remove APP Restriction |
Isolationtype | string | Optional | Type of the resource |
Input Example
{"json_body":{"comment":"a comment","Isolationtype":"Isolationtype"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Reset User Password (Authentication Method)
Reset a user's password using Microsoft Graph's password authentication method. Requires user_id and password_method_id as path parameters.
Endpoint
- URL: /users/{{user_id}}/authentication/methods/{{password_method_id}}/resetPassword
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.user_id | string | Required | User object ID or userPrincipalName. |
path_parameters.password_method_id | string | Required | Password authentication method id (Graph passwordMethods-id). |
newPassword | string | Optional | New password; omit when using an empty body for a generated password. |
Input Example
{"path_parameters":{"user_id":"6ea91a8d-e32e-41a1-b7bd-d2d185eed0e0","password_method_id":"28c10230-6103-485e-b985-444c60001490"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
@odata.context | string | Response data |
newPassword | string | Output field: newPassword |
Output Example
{"status_code":202,"response_headers":{"Content-Type":"application/json","Location":"https://graph.microsoft.com/v1.0/users/6ea91a8d-e32e-41a1-b7bd-d2d185eed0e0/auth..."},"reason":"Accepted","json_body":{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#microsoft.graph.passwordResetResponse","newPassword":"Cuyo5459"}}
Restrict APP Execution
Initiate an application execution restriction in Microsoft Defender using a specific entity ID.
Endpoint
- URL: /api/machines/{{id}}/restrictCodeExecution
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Restrict APP Execution action |
Comment | string | Optional | Parameter for Restrict APP Execution |
Input Example
{"json_body":{"comment":"a comment"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Revoke User Sign-In Sessions
Invalidate a user's refresh tokens and sign-in sessions in Microsoft Defender using the user_id path parameter.
Endpoint
- URL: /users/{{user_id}}/revokeSignInSessions
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.user_id | string | Required | User object ID or userPrincipalName. |
Input Example
{"path_parameters":{"user_id":"6ea91a8d-e32e-41a1-b7bd-d2d185eed0e0"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
@odata.context | string | Response data |
value | boolean | Value for the parameter |
Output Example
{"status_code":200,"response_headers":{"Content-Type":"application/json"},"reason":"OK","json_body":{"@odata.context":"https://graph.microsoft.com/v1.0/$metadata#Edm.Boolean","value":true}}
Run Antivirus Scan
Initiate a Microsoft Defender antivirus scan on a specified entity by machine ID, with options to customize the comment and scan type.
Endpoint
- URL: /api/machines/{{id}}/runAntiVirusScan
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Run Antivirus Scan action |
Comment | string | Optional | Comment to associate with the action. |
ScanType | string | Optional | Defines the type of the Scan. Possible values are Quick or Full. Quick- Perform quick scan on the device. Full- Perform full scan on the device. |
Input Example
{"json_body":{"Comment":"Check machine for viruses due to alert 3212","ScanType":"Full"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
type | string | Type of the resource |
scope | string | Output field: scope |
requestor | string | Output field: requestor |
requestorComment | string | Output field: requestorComment |
status | string | Status value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
creationDateTimeUtc | string | Output field: creationDateTimeUtc |
lastUpdateDateTimeUtc | string | Output field: lastUpdateDateTimeUtc |
relatedFileInfo | object | Output field: relatedFileInfo |
Output Example
{"status_code":201,"response_headers":{"Date":"Fri, 13 Dec 2024 07:45:13 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"id":"5382f7ea-7557-4ab7-9782-d50480024a4e","type":"Isolate","scope":"Selective","requestor":"Analyst...
Run Query
Execute a custom query in Microsoft Defender and return results. Specify 'Query' in the JSON body.
Endpoint
- URL: /api/advancedqueries/run
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
Query | string | Optional | Parameter for Run Query |
Input Example
{"json_body":{"Query":"a query"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.target | string | Error message if any |
Output Example
{"status_code":400,"response_headers":{"Date":"Thu, 04 May 2023 18:35:41 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Bad Request","json_body":{"error":{"code":"BadRequest","message":"A recognition error occurred.. Fix syntax errors in your query.","target":"|1d25001e-48e8e09dbddde4f4."}}}
Start Investigation
Initiate an automated investigation on a device in Microsoft Defender using the specified ID and comment.
Endpoint
- URL: /api/machines/{{id}}/startInvestigation
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | The Machine ID. |
Comment | string | Optional | Comment to associate with the action. |
Input Example
{"json_body":{"Comment":"Test investigation"},"path_parameters":{"id":"1e5bc9d7e413ddd7902c2932e418702b84d0cc07"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
id | string | Unique identifier |
startTime | string | Time value |
endTime | string | Time value |
state | string | Output field: state |
cancelledBy | string | Output field: cancelledBy |
statusDetails | string | Status value |
machineId | string | Unique identifier |
computerDnsName | string | Name of the resource |
triggeringAlertId | string | Unique identifier |
Output Example
{"status_code":201,"response_headers":{"Date":"Fri, 07 Feb 2025 06:30:27 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","mise-correlation-id":"08ce5338-e4be-4eab-a417-d0a5cf40bfac","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"id":"63004","startTime":"2020-01-06T13:...
Stop and Quarantine File
Initiate the stoppage and quarantine of a file using its 'id' to mitigate threats in Microsoft Defender.
Endpoint
- URL: /api/machines/{{id}}/StopAndQuarantineFile
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Stop and Quarantine File action |
Comment | string | Optional | Parameter for Stop and Quarantine File |
Sha1 | string | Optional | Parameter for Stop and Quarantine File |
Input Example
{"json_body":{"Comment":"a comment","Sha1":"some file"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
error | object | Error message if any |
error.code | string | Error message if any |
error.message | string | Response message |
error.target | string | Error message if any |
Output Example
{"status_code":400,"response_headers":{"Date":"Thu, 04 May 2023 18:35:41 GMT","Content-Type":"application/json; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Bad Request","json_body":{"error":{"code":"BadRequest","message":"A recognition error occurred.. Fix syntax errors in your query.","target":"|1d25001e-48e8e09dbddde4f4."}}}
Submit Indicator
Enhance tracking, alerting, and threat detection with a new indicator submission to Microsoft Defender.
Endpoint
- URL: /api/indicators
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
indicatorValue | string | Optional | Value for the parameter |
indicatorType | string | Optional | Type of the resource |
action | string | Optional | Parameter for Submit Indicator |
title | string | Optional | Parameter for Submit Indicator |
expirationTime | string | Optional | Time value |
severity | string | Optional | Parameter for Submit Indicator |
description | string | Optional | Parameter for Submit Indicator |
recommendedActions | string | Optional | Parameter for Submit Indicator |
Input Example
{"json_body":{"indicatorValue":"192.168.1.1","indicatorType":"DomainName","action":"AlertAndBlock","title":"Malicious IP Address","expirationTime":"2020-12-12T00:00:00Z","severity":"High","description":"My indicator description","recommendedActions":"My recommendations are ..."}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
UnIsolate Machine
Reverse the isolation of a specified machine in Microsoft Defender using the provided machine ID.
Endpoint
- URL: /api/machines/{{id}}/unisolate
- Method: POST
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the UnIsolate Machine action |
Comment | string | Optional | Parameter for UnIsolate Machine |
Isolationtype | string | Optional | Type of the resource |
Input Example
{"json_body":{"comment":"a comment","Isolationtype":"Isolationtype"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Update Alert
Update an existing alert in Microsoft Defender by specifying the unique alert ID as a path parameter.
Endpoint
- URL: /api/alerts/{{id}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | string | Required | Parameters for the Update Alert action |
status | string | Optional | Status value |
assignedTo | string | Optional | Parameter for Update Alert |
classification | string | Optional | Parameter for Update Alert |
determination | string | Optional | Parameter for Update Alert |
Input Example
{"json_body":{"status":"a comment","assignedTo":"assignedTo","classification":"classification","determination":"determination"},"path_parameters":{"id":"556b3952acb0bff29816d267822305781cc183ec"}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
response_text | string | Output field: response_text |
Output Example
{"status_code":405,"response_headers":{"Date":"Thu, 04 May 2023 18:07:32 GMT","Content-Length":"0","Connection":"keep-alive","Allow":"POST","Strict-Transport-Security":"max-age=15724800; includeSubDomains"},"reason":"Method Not Allowed","response_text":""}
Update Incident by ID
Update an existing incident's details in Microsoft Defender, including status, determination, and classification, using the incident ID.
Endpoint
- URL: api/incidents/{{id}}
- Method: PATCH
Input
Argument Name | Type | Required | Description |
|---|---|---|---|
path_parameters.id | number | Required | Incident ID. |
status | string | Optional | Specifies the current status of the incident. |
assignedTo | string | Optional | Owner of the incident. |
classification | string | Optional | Specification of the incident. |
determination | string | Optional | Specifies the determination of the incident. |
tags | array | Optional | List of Incident tags. |
comment | string | Optional | Comment to be added to the incident. |
Input Example
{"json_body":{"status":"Resolved","assignedTo":"[email protected]","classification":"TruePositive","determination":"Malware","tags":["Yossi's playground","Don't mess with the Zohan"],"comment":"pen testing"},"path_parameters":{"id":437}}
Output
Parameter | Type | Description |
|---|---|---|
status_code | number | HTTP status code of the response |
reason | string | Response reason phrase |
@odata.context | string | Response data |
incidentId | number | Unique identifier |
incidentUri | string | Unique identifier |
redirectIncidentId | object | Unique identifier |
incidentName | string | Unique identifier |
createdTime | string | Time value |
lastUpdateTime | string | Time value |
assignedTo | object | Output field: assignedTo |
classification | string | Output field: classification |
determination | string | Output field: determination |
status | string | Status value |
severity | string | Output field: severity |
tags | array | Output field: tags |
tags.file_name | string | Name of the resource |
tags.file | string | Output field: tags.file |
comments | array | Output field: comments |
comments.file_name | string | Name of the resource |
comments.file | string | Output field: comments.file |
alerts | array | Output field: alerts |
alerts.alertId | string | Unique identifier |
alerts.providerAlertId | string | Unique identifier |
alerts.incidentId | number | Unique identifier |
alerts.serviceSource | string | Output field: alerts.serviceSource |
Output Example
{"status_code":200,"response_headers":{"Date":"Thu, 05 Sep 2024 07:20:44 GMT","Content-Type":"application/json; odata.metadata=minimal; odata.streaming=true; charset=utf-8","Transfer-Encoding":"chunked","Connection":"keep-alive","Content-Encoding":"deflate","Vary":"Accept-Encoding","OData-Version":"4.0","Strict-Transport-Security":"max-age=31536000; includeSubDomains"},"reason":"OK","json_body":{"@odata.context":"https://api.securitycenter.microsoft.com/api/$metadata#Incidents/$entity","incident...
Response Headers
Header | Description | Example |
|---|---|---|
Allow | HTTP response header: Allow | POST |
Connection | HTTP response header: Connection | keep-alive |
Content-Encoding | HTTP response header: Content-Encoding | deflate |
Content-Length | The length of the response body in bytes | 0 |
Content-Type | The media type of the resource | application/json |
Date | The date and time at which the message was originated | Thu, 04 May 2023 13:16:32 GMT |
mise-correlation-id | HTTP response header: mise-correlation-id | 08ce5338-e4be-4eab-a417-d0a5cf40bfac |
OData-Version | HTTP response header: OData-Version | 4.0 |
Strict-Transport-Security | HTTP response header: Strict-Transport-Security | max-age=31536000; includeSubDomains |
Transfer-Encoding | HTTP response header: Transfer-Encoding | chunked |
Vary | HTTP response header: Vary | Accept-Encoding |