Microsoft Defender Incidents
自動配備
Filigranの提供による
Detection & Response Enablement
概要
Imports incidents, alerts, and observables from Microsoft Defender XDR into OpenCTI as STIX Incidents linked to associated IOCs.
The Microsoft Defender Incidents connector imports incidents, alerts, indicators, and observables from Microsoft Defender XDR (formerly Microsoft 365 Defender) into OpenCTI. It creates structured STIX Incidents linked to associated IOCs and entities, enabling SOC teams to correlate endpoint detections with threat intelligence.