add blurb

This commit is contained in:
Joey Caparas 2017-12-07 16:27:42 -08:00
parent 0dcf571ad8
commit 8f11891716
42 changed files with 332 additions and 30 deletions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Block file # Block file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Prevent a file from being executed in the organization using Windows Defender Antivirus. Prevent a file from being executed in the organization using Windows Defender Antivirus.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Collect investigation package # Collect investigation package
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Collect investigation package from a machine. Collect investigation package from a machine.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
--- ---
# Find machine information by interal IP # Find machine information by interal IP
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Find a machine entity around a specific timestamp by FQDN or internal IP. Find a machine entity around a specific timestamp by FQDN or internal IP.
## Permissions ## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get actor information # Get actor information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves an actor information report. Retrieves an actor information report.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
--- ---
# Get actor related alerts # Get actor related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all alerts related to a given actor. Retrieves all alerts related to a given actor.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert information by ID # Get alert information by ID
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves an alert by its ID. Retrieves an alert by its ID.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert related domain information # Get alert related domain information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all domains related to a specific alert. Retrieves all domains related to a specific alert.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert related files information # Get alert related files information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all files related to a specific alert. Retrieves all files related to a specific alert.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert related IP information # Get alert related IP information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all IPs related to a specific alert. Retrieves all IPs related to a specific alert.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert related machine information # Get alert related machine information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves all machines related to a specific alert. Retrieves all machines related to a specific alert.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alert related user information # Get alert related user information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the user associated to a specific alert. Retrieves the user associated to a specific alert.
## Permissions ## Permissions

View File

@ -10,12 +10,25 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get alerts # Get alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves top recent alerts. Retrieves top recent alerts.
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
## Permissions ## Permissions
User needs read permissions. User needs read permissions.

View File

@ -10,10 +10,16 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get domain related alerts # Get domain related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given domain address. Retrieves a collection of alerts related to a given domain address.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get domain related machines # Get domain related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given domain address. Retrieves a collection of machines related to a given domain address.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get domain statistics # Get domain statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given domain. Retrieves the prevalence for the given domain.
## Permissions ## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get file information # Get file information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a file by identifier Sha1, Sha256, or MD5. Retrieves a file by identifier Sha1, Sha256, or MD5.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get file related alerts # Get file related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given file hash. Retrieves a collection of alerts related to a given file hash.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
--- ---
# Get file related machines # Get file related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given file hash. Retrieves a collection of machines related to a given file hash.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 10/16/2017
--- ---
# Get file statistics # Get file statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given file. Retrieves the prevalence for the given file.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get FileActions collection # Get FileActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets collection of actions done on files. Get FileActions collection API supports OData V4 queries. Gets collection of actions done on files. Get FileActions collection API supports OData V4 queries.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Get FileMachineAction object # Get FileMachineAction object
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets file and machine actions. Gets file and machine actions.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Get FileMachineActions collection # Get FileMachineActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get collection of file and machine actions. Get FileMachineActions collection API supports OData V4 queries. Get collection of file and machine actions. Get FileMachineActions collection API supports OData V4 queries.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get IP related alerts # Get IP related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given IP address. Retrieves a collection of alerts related to a given IP address.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get IP statistics # Get IP statistics
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves the prevalence for the given IP. Retrieves the prevalence for the given IP.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get machine by ID # Get machine by ID
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a machine entity by ID. Retrieves a machine entity by ID.
## Permissions ## Permissions

View File

@ -10,10 +10,18 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get machine log on users # Get machine log on users
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of logged on users. Retrieves a collection of logged on users.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get machine related alerts # Get machine related alerts
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of alerts related to a given machine ID. Retrieves a collection of alerts related to a given machine ID.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Get MachineAction object # Get MachineAction object
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get actions done on a machine. Get actions done on a machine.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Get MachineActions collection # Get MachineActions collection
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Gets collection of actions done on machines. Get MachineAction collection API supports OData V4 queries. Gets collection of actions done on machines. Get MachineAction collection API supports OData V4 queries.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get machines # Get machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of recently seen machines. Retrieves a collection of recently seen machines.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Get package SAS URI # Get package SAS URI
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Get a URI that allows downloading of an investigation package. Get a URI that allows downloading of an investigation package.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get user information # Get user information
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieve a User entity by key (user name or domain\user). Retrieve a User entity by key (user name or domain\user).
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Get user related machines # Get user related machines
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Retrieves a collection of machines related to a given user ID. Retrieves a collection of machines related to a given user ID.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 10/16/2017 ms.date: 12/08/2017
--- ---
# Is IP seen in org # Is IP seen in org
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Answers whether an IP was seen in the organization. Answers whether an IP was seen in the organization.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/06/2017
--- ---
# Isolate machine # Isolate machine
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Isolates a machine from accessing external network. Isolates a machine from accessing external network.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 12/07/2017 ms.date: 12/08/2017
--- ---
# Request sample # Request sample API
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Request sample of a file from a specific machine. File will be collected from the machine and uploaded to a secure storage. Request sample of a file from a specific machine. File will be collected from the machine and uploaded to a secure storage.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 12/07/2017 ms.date: 12/08/2017
--- ---
# Restrict app execution # Restrict app execution API
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Restrict execution of set of predefined applications. Restrict execution of set of predefined applications.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Run antivirus scan # Run antivirus scan
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Initiate Windows Defender Antivirus scan on the machine. Initiate Windows Defender Antivirus scan on the machine.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Stop and quarantine file # Stop and quarantine file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Stop execution of a file on a machine and ensure its not executed again on that machine. Stop execution of a file on a machine and ensure its not executed again on that machine.
## Permissions ## Permissions

View File

@ -14,6 +14,13 @@ ms.date: 12/07/2017
--- ---
# Unblock file # Unblock file
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Allow a file to be executed in the organization, using Windows Defender Antivirus. Allow a file to be executed in the organization, using Windows Defender Antivirus.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 12/07/2017 ms.date: 12/08/2017
--- ---
# Release machine from isolation # Release machine from isolation
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Undo isolation of a machine. Undo isolation of a machine.
## Permissions ## Permissions

View File

@ -10,10 +10,17 @@ ms.pagetype: security
ms.author: macapara ms.author: macapara
author: mjcaparas author: mjcaparas
ms.localizationpriority: high ms.localizationpriority: high
ms.date: 12/07/2017 ms.date: 12/08/2017
--- ---
# Remove app restriction # Remove app restriction
**Applies to:**
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
[!include[Prerelease information](prerelease.md)]
Unrestrict execution of set of predefined applications. Unrestrict execution of set of predefined applications.
## Permissions ## Permissions