Skip to content

[meta] Update Microsoft Defender for Endpoint integration to Leverage Native Cloud Security Workflows #14661

@kcreddy

Description

@kcreddy

As part of effort to leverage Cloud Security workflows such as Elastic CSPM and CNVM for 3rd party integrations, the vulnerabilities data from Microsoft Defender for Endpoint needs to be enriched just like previous enhancements for Wiz, Qualys VMDR, and Rapid7 InsighVM.

For this work, the microsoft_defender_endpoint.vulnerability data stream which ingests exported vulnerabilities of assets must be enriched to support Elastic CNVM workflow.

Tasks:

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions