Microsoft Defender machine investigation brief
Use “Microsoft Defender machine investigation brief” in Recued. It provides a read-only investigation brief for one Microsoft Defender for Endpoint machine.
How it works
Inspect the data fetches, transforms, gates, and output this recipe runs.
Process (20 steps)
machine_id
trim
Trim whitespace from setting machine id
machine_action_filter
template
Generate text from a template
machine
?
alerts_raw
?
vulnerabilities_raw
?
logon_users_raw
?
actions_raw
?
defaults
defaults
Apply defaults
alert_count
count
Count items in alerts
vulnerability_count
count
Count items in vulnerabilities
logon_user_count
count
Count items in logon users
action_count
count
Count items in actions
summarize
?
alert_rows
slice
Take a subset of
vulnerability_rows
slice
Take a subset of
logon_user_rows
slice
Take a subset of
alert_table
to_table
Format results as a data table
vulnerability_table
to_table
Format results as a data table
logon_user_table
to_table
Format results as a data table
card
to_summary
Format results as a summary card
Settings
Configurable at install. Defaults shown — change them anytime in Recued.
focus
setting
=
Summarize this Defender for Endpoint machine's risk score, exposure level, health, OS, last seen time, related alerts, logon users, discovered vulnerabilities, recent machine actions, likely priority, and concrete next steps. Do not invent facts outside the Defender data.
row limit
setting
=
20
machine id
setting
=
max length
setting
=
900
microsoft defender
setting
=
Trust & control
What installing this recipe would let it do. Recued grants these permissions at install — review them there before approving.