mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-19 00:37:22 +00:00
Add prereleased prefix
This commit is contained in:
parent
bc236fc8f7
commit
d98bc8fac0
@ -102,11 +102,6 @@
|
||||
#### [Supported Windows Defender ATP APIs](exposed-apis-list.md)
|
||||
##### [Advanced Hunting](run-advanced-query-api.md)
|
||||
|
||||
#### How to use APIs - Samples
|
||||
##### [Schedule advanced Hunting using Microsoft Flow](run-advanced-query-sample-ms-flow.md)
|
||||
##### [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md)
|
||||
##### [Advanced Hunting using Python](run-advanced-query-sample-python.md)
|
||||
|
||||
##### [Alert](alerts-windows-defender-advanced-threat-protection-new.md)
|
||||
###### [List alerts](get-alerts-windows-defender-advanced-threat-protection-new.md)
|
||||
###### [Create alert](create-alert-by-reference-windows-defender-advanced-threat-protection-new.md)
|
||||
@ -158,6 +153,12 @@
|
||||
###### [Get user related alerts](get-user-related-alerts-windows-defender-advanced-threat-protection-new.md)
|
||||
###### [Get user related machines](get-user-related-machines-windows-defender-advanced-threat-protection-new.md)
|
||||
|
||||
#### How to use APIs - Samples
|
||||
##### [Schedule advanced Hunting using Microsoft Flow](run-advanced-query-sample-ms-flow.md)
|
||||
##### [Advanced Hunting using PowerShell](run-advanced-query-sample-powershell.md)
|
||||
##### [Advanced Hunting using Python](run-advanced-query-sample-python.md)
|
||||
|
||||
|
||||
### [Use the Windows Defender ATP exposed APIs](exposed-apis-windows-defender-advanced-threat-protection.md)
|
||||
#### [Supported Windows Defender ATP APIs](supported-apis-windows-defender-advanced-threat-protection.md)
|
||||
#####Actor
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Alert resource type
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
Represents an alert entity in WDATP.
|
||||
|
||||
# Methods
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Block file API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Collect investigation package API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Create alert from event API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# File resource type
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
Represent a file entity in WDATP.
|
||||
|
||||
# Methods
|
||||
|
@ -15,6 +15,8 @@ ms.date: 07/25/2018
|
||||
|
||||
# Find machine information by internal IP API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert information by ID API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert related domain information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert related files information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert related IP information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert related machine information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alert related user information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get domain related alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get domain related machines API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get domain statistics API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get file information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get file related alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get file related machines API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get file statistics API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get IP related alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -14,6 +14,12 @@ ms.date: 12/08/2017
|
||||
---
|
||||
|
||||
# Get IP related machines API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
Retrieves a collection of alerts related to a given IP address.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get IP statistics API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves the prevalence for the given IP.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get machine by ID API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves a machine entity by ID.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,13 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get machine log on users API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
|
||||
Retrieves a collection of logged on users.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get machine related alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves a collection of alerts related to a given machine ID.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get MachineAction object API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Get actions done on a machine.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,6 +15,8 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get MachineActions collection API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get machines API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves a collection of recently seen machines.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get package SAS URI API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Get a URI that allows downloading of an investigation package.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get user information API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieve a User entity by key (user name or domain\user).
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get user related alerts API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves a collection of alerts related to a given user ID.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Get user related machines API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Retrieves a collection of machines related to a given user ID.
|
||||
|
||||
## Permissions
|
||||
|
@ -14,6 +14,13 @@ ms.date: 04/24/2018
|
||||
---
|
||||
|
||||
# Was domain seen in org
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
Answers whether a domain was seen in the organization.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Was IP seen in org
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Answers whether an IP was seen in the organization.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Isolate machine API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Isolates a machine from accessing external network.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Collect investigation package API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Offboard machine from WDATP.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Restrict app execution API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Restrict execution of all applications on the machine except a predefined set.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Run antivirus scan API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Initiate Windows Defender Antivirus scan on the machine.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,6 +15,8 @@ ms.date: 30/07/2018
|
||||
|
||||
# Supported Windows Defender ATP query APIs
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows 10 Enterprise
|
||||
@ -23,8 +25,6 @@ ms.date: 30/07/2018
|
||||
- Windows 10 Pro Education
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
>Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-supportedapis-abovefoldlink)
|
||||
|
||||
Learn more about the individual supported entities where you can run API calls to and details such as HTTP request values, request headers and expected responses.
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Unblock file API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Allow a file to be executed in the organization, using Windows Defender Antivirus.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,12 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Release machine from isolation API
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
|
||||
Undo isolation of a machine.
|
||||
|
||||
## Permissions
|
||||
|
@ -15,11 +15,12 @@ ms.date: 12/08/2017
|
||||
|
||||
# Update alert
|
||||
|
||||
[!include[Prerelease information](prerelease.md)]
|
||||
|
||||
**Applies to:**
|
||||
|
||||
- Windows Defender Advanced Threat Protection (Windows Defender ATP)
|
||||
|
||||
|
||||
Update the properties of an alert object.
|
||||
|
||||
## Permissions
|
||||
|
Loading…
x
Reference in New Issue
Block a user