Files
windows-itpro-docs/windows/security/threat-protection/windows-defender-atp/TOC.md
Joey Caparas e488291a6a typo
2018-08-31 13:49:41 -07:00

32 KiB

Windows Defender Advanced Threat Protection

Overview

Attack surface reduction

Hardware-based isolation

Application isolation
System isolation

Application control

Exploit protection

Network protection

Controlled folder access

Attack surface reduction

Network firewall

Next generation protection

Endpoint detection and response

Security operations dashboard

Alerts queue

View and organize the Alerts queue
Manage alerts
Investigate alerts
Investigate files
Investigate machines
Investigate an IP address
Investigate a domain
Investigate a user account

Machines list

View and organize the Machines list
Manage machine group and tags
Machine timeline
Search for specific events
Filter events from a specific date
Export machine timeline events
Navigate between pages

Take response actions

Take response actions on a machine
Collect investigation package
Run antivirus scan
Restrict app execution
Remove app restriction
Isolate machines from the network
Release machine from isolation
Check activity details in Action center
Take response actions on a file
Stop and quarantine files in your network
Remove file from quarantine
Block files in your network
Remove file from blocked list
Check activity details in Action center
Deep analysis
Submit files for analysis
View deep analysis reports
Troubleshoot deep analysis

Automated investigation and remediation

Learn about the automated investigation and remediation dashboard

Secure score

Threat analytics

Threat analytics for Spectre and Meltdown

Advanced hunting

Query data using Advanced hunting

Advanced hunting reference
Advanced hunting query language best practices

Custom detections

#####Create custom detections rules

Management and APIs

Understand threat intelligence concepts

Supported Windows Defender ATP APIs

#####Actor

Get actor information

#####Alerts

Get alerts
Get alert information by ID

######Domain ####### Get domain related alerts ####### Get domain related machines ####### Get domain statistics ####### Is domain seen in organization

#####File

Block file API
Get file information
Get file statistics
Get FileActions collection API
Unblock file API

#####IP

Get IP statistics
Is IP seen in organization

#####Machines

Collect investigation package API
Find machine information by IP
Get machines
Get FileMachineAction object API
Get FileMachineActions collection API
Get machine by ID
Get machine log on users
Get MachineAction object API
Get MachineActions collection API
Get machines
Get package SAS URI API
Isolate machine API
Release machine from isolation API
Remove app restriction API
Request sample API
Restrict app execution API
Run antivirus scan API
Stop and quarantine file API

#####User

Get user information

Managed service provider provider support

Microsoft threat protection

Protect users, data, and devices with conditional access

Microsoft Cloud App Security integration overview

Portal overview

Get started

Minimum requirements

Validate licensing and complete setup

Preview features

Data storage and privacy

Assign user access to the portal

Evaluate Windows Defender ATP

####Evaluate attack surface reduction

Hardware-based isolation
Application control
Exploit protection
Network Protection
Controlled folder access
Attack surface reduction
Network firewall

Evaluate next generation protection

Access the Windows Defender Security Center Community Center

Configure and manage capabilities

Configure attack surface reduction

Hardware-based isolation

Configuration settings](../windows-defender-application-guard/configure-wd-app-guard.md)

Application control

Exploit protection

Customize exploit protection
Import/export configurations

Network protection

Controlled folder access

Customize controlled folder access

Attack surface reduction controls

Customize attack surface reduction

Network firewall

Configure next generation protection

Utilize Microsoft cloud-delivered protection

Enable cloud-delivered protection
Specify the cloud-delivered protection level
Configure and validate network connections
Enable Block at first sight
Configure the cloud block timeout period

Configure behavioral, heuristic, and real-time protection

Detect and block Potentially Unwanted Applications
Enable and configure always-on protection and monitoring

Antivirus on Windows Server 2016

Antivirus compatibility

Use limited periodic antivirus scanning

Deploy, manage updates, and report on antivirus

Deploy and enable antivirus
Deployment guide for VDI environments
Report on antivirus protection
Troubleshoot antivirus reporting in Update Compliance
Manage updates and apply baselines
Manage protection and definition updates
Manage when protection updates should be downloaded and applied
Manage updates for endpoints that are out of date
Manage event-based forced updates
Manage updates for mobile devices and VMs

Customize, initiate, and review the results of scans and remediation

Configure and validate exclusions in antivirus scans
Configure and validate exclusions based on file name, extension, and folder location
Configure and validate exclusions for files opened by processes
Configure antivirus exclusions Windows Server 2016
Configure scanning antivirus options
Configure remediation for scans
Configure scheduled scans
Configure and run scans
Review scan results
Run and review the results of an offline scan

Restore quarantined files

Manage antivirus in your business

Use Group Policy settings to configure and manage antivirus
Use System Center Configuration Manager and Microsoft Intune to configure and manage antivirus
Use PowerShell cmdlets to configure and manage antivirus
Use Windows Management Instrumentation (WMI) to configure and manage antivirus
Use the mpcmdrun.exe commandline tool to configure and manage antivirus

Manage scans and remediation

Configure and validate exclusions in antivirus scans
Configure and validate exclusions based on file name, extension, and folder location
Configure and validate exclusions for files opened by processes
Configure antivirus exclusions on Windows Server 2016
Configure scanning options
Configure remediation for scans
Configure scheduled scans
Configure and run scans
Review scan results
Run and review the results of an offline scan
Restore quarantined files

Manage next generation protection in your business

Use Microsoft Intune and System Center Configuration Manager to manage next generation protection
Use Group Policy settings to manage next generation protection
Use PowerShell cmdlets to manage next generation protection
Use Windows Management Instrumentation (WMI) to manage next generation protection
Use the mpcmdrun.exe command line tool to manage next generation protection

Configure Secure score dashboard security controls

Management and API support

Onboard machines

Onboard previous versions of Windows
Onboard Windows 10 machines
Onboard machines using Group Policy
Onboard machines using System Center Configuration Manager
Onboard machines using Mobile Device Management tools

####### Onboard machines using Microsoft Intune

Onboard machines using a local script
Onboard non-persistent virtual desktop infrastructure (VDI) machines
Onboard servers
Onboard non-Windows machines
Run a detection test on a newly onboarded machine
Run simulated attacks on machines
Configure proxy and Internet connectivity settings
Troubleshoot onboarding issues
Troubleshoot subscription and portal access issues

API for custom alerts

Enable the custom threat intelligence application
Use the Windows Defender ATP exposed APIs
Use the threat intelligence API to create custom alerts
Create custom threat intelligence alerts
PowerShell code examples
Python code examples
Experiment with custom threat intelligence alerts
Troubleshoot custom threat intelligence issues

Pull alerts to your SIEM tools

Enable SIEM integration
Configure Splunk to pull alerts
Configure HP ArcSight to pull alerts
Windows Defender ATP alert API fields
Pull alerts using REST API
Troubleshoot SIEM tool integration issues

Reporting

Create and build Power BI reports using Windows Defender ATP data

Role-based access control

Manage portal access using RBAC
Create and manage roles
Create and manage machine groups

####### Create and manage machine tags

Configure managed security service provider (MSSP) support

Configure Microsoft threat protection integration

Configure conditional access

Configure Microsoft Cloud App Security integration

Configure Windows Defender Security Center settings

General

Update data retention settings
Configure alert notifications
Enable and create Power BI reports using Windows Defender Security center data
Enable Secure score security controls
Configure advanced features

Permissions

Use basic permissions to access the portal
Manage portal access using RBAC
Create and manage roles
Create and manage machine groups

####### Create and manage machine tags

APIs

Enable Threat intel
Enable SIEM integration

####Rules

Manage suppression rules
Manage automation allowed/blocked
Manage automation file uploads
Manage automation folder exclusions

####Machine management

Onboarding machines
Offboarding machines

Configure Windows Defender Security Center time zone settings

Troubleshoot Windows Defender ATP

###Troubleshoot sensor state

Check sensor state

Fix unhealthy sensors

Inactive machines

Misconfigured machines

Review sensor events and errors on machines with Event Viewer

Troubleshoot Windows Defender ATP service issues

Check service health

###Troubleshoot attack surface reduction

Network protection

Attack surface reduction rules

Troubleshoot next generation protection