Apps
Microsoft Defender for Endpoin...
Interpres Application - Microsoft Defender for Endpoint
- Type: SIEM/Data Lake
- Vendor: Microsoft
This app integrates with Microsoft Defender for Endpoint to execute various containment, corrective and investigative actions
- Search for App registrations

- Click + New registration

- Enter "Interpres" for the app name. Leave the other defaults (Single-tenant, no Redirect URI). Click "Register".

- Copy the application (client) ID and the Directory (tenant) ID over to the Interpres integration setup page

- Click Manifest
7. Replace requiredResourceAccess with the following:

As an alternative to Step 7, you can manually add the following permissions (as Application):
- Click Save

- Click API permissions then Grant admin consent for YOUR_TENANT

- Click Certificates & Secrets then New client secret

- Enter "Interpres" for the description and choose "12 months".

- Copy the client secret "Value" over to the Interpres integration setup.
- Tenant ID: Tenant ID
- Client ID: Client ID
- Client Secret: Client Secret
- Limit Data: Optimizes performance by limiting non-essential API requests
Check there is connectivity (green light) in the integration created.
- Get Assets: Gets the machines on the network.
- Get Vulnerabilites: Gets a list of active CVEs for each asset.
- Get Alerts: Gets the latest triggered alerts.
- Get Detections: This action processes triggered alerts (not to be confused with the detection logic). These are turned into the Interpres Detection. The detection list should contain any detection that was seen over the course of this plugin being installed.
- Get Available Telemetry: Returns a list of telemetry identifiers with their current status. This is a static list.