add blurb

This commit is contained in:
Joey Caparas 2017-12-07 16:27:42 -08:00
parent 0dcf571ad8
commit 8f11891716
42 changed files with 332 additions and 30 deletions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Block file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Prevent a file from being executed in the organization using Windows Defender Antivirus.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Collect investigation package
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Collect investigation package from a machine.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
---
# Find machine information by interal IP
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Find a machine entity around a specific timestamp by FQDN or internal IP.
## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get actor information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves an actor information report.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
---
# Get actor related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all alerts related to a given actor.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert information by ID
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves an alert by its ID.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert related domain information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all domains related to a specific alert.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert related files information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all files related to a specific alert.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert related IP information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all IPs related to a specific alert.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert related machine information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all machines related to a specific alert.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alert related user information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the user associated to a specific alert.
## Permissions

View File

@ -10,12 +10,25 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves top recent alerts.
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
## Permissions
User needs read permissions.

View File

@ -10,10 +10,16 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get domain related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given domain address.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get domain related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given domain address.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get domain statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given domain.
## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get file information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a file by identifier Sha1, Sha256, or MD5.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get file related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given file hash.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
---
# Get file related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given file hash.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
---
# Get file statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given file.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get FileActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets collection of actions done on files. Get FileActions collection API supports OData V4 queries.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Get FileMachineAction object
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets file and machine actions.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Get FileMachineActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get collection of file and machine actions. Get FileMachineActions collection API supports OData V4 queries.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get IP related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given IP address.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get IP statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given IP.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get machine by ID
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a machine entity by ID.
## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get machine log on users
# Get machine log on users
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of logged on users.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get machine related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given machine ID.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Get MachineAction object
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get actions done on a machine.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Get MachineActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets collection of actions done on machines. Get MachineAction collection API supports OData V4 queries.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of recently seen machines.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Get package SAS URI
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get a URI that allows downloading of an investigation package.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get user information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieve a User entity by key (user name or domain\user).
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Get user related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given user ID.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 10/16/2017
ms.date: 12/08/2017
---
# Is IP seen in org
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Answers whether an IP was seen in the organization.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/06/2017
---
# Isolate machine
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Isolates a machine from accessing external network.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 12/07/2017
ms.date: 12/08/2017
---
# Request sample
# Request sample API
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Request sample of a file from a specific machine. File will be collected from the machine and uploaded to a secure storage.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 12/07/2017
ms.date: 12/08/2017
---
# Restrict app execution
# Restrict app execution API
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Restrict execution of set of predefined applications.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Run antivirus scan
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Initiate Windows Defender Antivirus scan on the machine.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Stop and quarantine file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Stop execution of a file on a machine and ensure its not executed again on that machine.
## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
---
# Unblock file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Allow a file to be executed in the organization, using Windows Defender Antivirus.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 12/07/2017
ms.date: 12/08/2017
---
# Release machine from isolation
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Undo isolation of a machine.
## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara
author: mjcaparas
ms.localizationpriority: high
ms.date: 12/07/2017
ms.date: 12/08/2017
---
# Remove app restriction
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Unrestrict execution of set of predefined applications.
## Permissions