redcanaryco / surveyor

A cross-platform baselining, threat hunting, and attack surface analysis tool for security teams.
MIT License
170 stars 59 forks source link

New Product: ATP Support #38

Closed rc-abodkins closed 2 years ago

rc-abodkins commented 4 years ago

Which category is the feature part of?

Use Cases

Proposal Determine if it is possible to add support for ATP.

Additional context Add any other context or screenshots about the feature request here.

pmichaudrc commented 3 years ago

We may be able to use the Graph API and do advanced hunting queries to pull in Process Execution summaries.

https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/run-advanced-query-api

jholtmann commented 2 years ago

This was implemented with #44