Create and configure a profile for sightings search with the Microsoft Defender for Endpoint integration
-
- UpdatedJan 30, 2025
- 2 minutes to read
- Yokohama
- Security Incident Response integrations
Create and configure the sightings search profile automatically using the Microsoft Defender for Endpoint.
Before you begin
Role required: sn_si.admin, sn_si.admin
About this task
You can use the Sightings Search workflow to perform the sighting searches. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries that are based on the sighting search configurations, and executes the searches that are based on the configured workflow.
The Microsoft Defender for Endpoint provides a base system sighting search profile that enables you to configure the automatic sighting searches. With this profile, you can access the related observable sighting information of an organization and also see the sightings from other organizations.
Procedure