logo

Microsoft Defender for Endpoint Internal 0x06 — Custom Collection

ID: c1a2d147-b3ae-5788-8122-7345936d51bb

STIX ID: report--c1a2d147-b3ae-5788-8122-7345936d51bb

Feed Name: FalconForce

Date Published: 2025-11-20

Date Updated: 2026-04-27

Author: Olaf Hartong

...
...

This post introduces Microsoft Defender for Endpoint’s Custom Collection feature, which allows organizations to define fine-grained telemetry collection rules (capped at 25,000 events per rule per device per day) for process, network, file, image load, and script events, with data stored in Microsoft Sentinel under dedicated tables that include rule metadata and may incur additional cost. It outlines practical use cases (e.g., surge logging during investigations, targeted web shell monitoring), deployment requirements (Defender P2, Sentinel connection, client version ≥10.8805), and management through the Defender XDR portal, and it announces FalconForce’s TelemetryCollectionManager and YAML schema that enable validating, deploying, exporting, converting, and deleting rules to support a rules-as-code approach and community contributions.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.