Create and configure the sightings search profile automatically using the Microsoft Defender for Endpoint.

Before you begin

Role required: sn_si.admin, sn_si.admin

About this task

You can use the Sightings Search workflow to perform the sighting searches. This workflow accepts a list of observables, finds any implementing capabilities, creates the queries that are based on the sighting search configurations, and executes the searches that are based on the configured workflow.

The Microsoft Defender for Endpoint provides a base system sighting search profile that enables you to configure the automatic sighting searches. With this profile, you can access the related observable sighting information of an organization and also see the sightings from other organizations.

Procedure

  1. Navigate to Integrations > Sighting Search Configuration.
  2. Click New.
  3. On the form, fill in the following fields.
  4. Click Submit.