Is Microsoft Defender for Endpoint good?
ID: fca40586-6d53-58bf-b742-1943d3802542
STIX ID: report--fca40586-6d53-58bf-b742-1943d3802542
Feed Name: Expel Blog
This post describes how Expel leverages Microsoft Defender for Endpoint and its APIs to automate alert triage and decision support for analysts, demonstrating features such as process trees, timeline generation, prevalence queries, and AV action retrieval with an illustrative example of suspicious "net" commands consistent with a webshell.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
