This extension for Splunk® is a rewrite of the Add-on already created by pdoconnell (TA-microsoft-windefender) that we adapt to our needs and requirements. This add-on is intended as a complement to the Splunk Add-on for Microsoft Windows, which also manages the basic operations of the field extraction from the xml or raw events. If you have installed that add-on you can also use this one to extract more information and present it according to CIM. Code is hosted on Github: https://github.com/nextpart/Defender_TA_nxtp
(1)
Categories
Created By
Source Code
Type
Downloads
Licensing
Splunk Answers
Resources