Latest Version 1.4.1
August 27, 2024
This add-on provides field extractions and CIM compatibility for the Endpoint datamodel for Microsoft Defender Advanced Hunting data. The data is similar in content to Sysmon data and can be used by Detection Searches in i.e. Splunk Enterprise Security Content Update.
(0)
Categories
Created By
Contributors
Type
Downloads
Licensing
Splunk Answers
Resources