Microsoft Defender Incidents
Automatic deploy
Supported by Filigran
Detection & Response Enablement
Overview
Imports incidents, alerts, and observables from Microsoft Defender XDR into OpenCTI as STIX Incidents linked to associated IOCs.
The Microsoft Defender Incidents connector imports incidents, alerts, indicators, and observables from Microsoft Defender XDR (formerly Microsoft 365 Defender) into OpenCTI. It creates structured STIX Incidents linked to associated IOCs and entities, enabling SOC teams to correlate endpoint detections with threat intelligence.