question

cdd avatar image
0 Votes"
cdd asked ·

Defender ATP - Pull machine timeline events via API or Advanced Threat Hunting

We are working on a SOAR project and are trying to figure out if it is possible either through the API or the Advanced Hunting queries to pull a list of events from the machine timeline when alerts occur.

We have successfully integrated and can query and pull information but I am having trouble finding if this specific use case is an option.

Thanks

not-supported
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

DSPatrick avatar image
0 Votes"
DSPatrick answered ·

Defender ATP is not currently supported here on QnA. I'd try asking for help in dedicated forums here.

https://social.technet.microsoft.com/Forums/en-US/home?forum=WindowsDefenderATPPreview


--please don't forget to Accept as answer if the reply is helpful--


Regards, Dave Patrick ....
Microsoft Certified Professional
Microsoft MVP [Windows Server] Datacenter Management


Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.





· Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.