Recued
Menu
← Back to recipes

Microsoft Defender machine investigation brief

by recued-core v1 8 views

Use “Microsoft Defender machine investigation brief” in Recued. It provides a read-only investigation brief for one Microsoft Defender for Endpoint machine.

How it works 20 steps

Inspect the data fetches, transforms, gates, and output this recipe runs.

Process (20 steps)
machine_id trim
Trim whitespace from setting machine id
machine_action_filter template
Generate text from a template
machine ?
alerts_raw ?
vulnerabilities_raw ?
logon_users_raw ?
actions_raw ?
defaults defaults
Apply defaults
alert_count count
Count items in alerts
vulnerability_count count
Count items in vulnerabilities
logon_user_count count
Count items in logon users
action_count count
Count items in actions
summarize ?
alert_rows slice
Take a subset of
vulnerability_rows slice
Take a subset of
logon_user_rows slice
Take a subset of
alert_table to_table
Format results as a data table
vulnerability_table to_table
Format results as a data table
logon_user_table to_table
Format results as a data table
card to_summary
Format results as a summary card
Settings 5 configurable

Configurable at install. Defaults shown — change them anytime in Recued.

focus setting = Summarize this Defender for Endpoint machine's risk score, exposure level, health, OS, last seen time, related alerts, logon users, discovered vulnerabilities, recent machine actions, likely priority, and concrete next steps. Do not invent facts outside the Defender data.
row limit setting = 20
machine id setting =
max length setting = 900
microsoft defender setting =

Trust & control

What installing this recipe would let it do. Recued grants these permissions at install — review them there before approving.

Permissions it requires

Read your Microsoft-defender connection
Declared by the recipe — Recued grants these at install, where you review them before approving.

About

Tags

microsoft-defender-endpoint microsoft-defender-endpointdefender-for-endpointendpoint-securitymachinesalertsvulnerabilitiesai-summarypack:microsoft-defender-endpoint

Details

20 steps 5 configurable settings recipe_id: machine-brief-microsoft-defender-endpoint