Apps
Microsoft Defender for Endpoin...

Interpres Application - Microsoft Defender for Endpoint

  • Type: SIEM/Data Lake
  • Vendor: Microsoft

This app integrates with Microsoft Defender for Endpoint to execute various containment, corrective and investigative actions

Vendor setup

  1. Search for App registrations
Document image

  1. Click + New registration
Document image

  1. Enter "Interpres" for the app name. Leave the other defaults (Single-tenant, no Redirect URI). Click "Register".
Document image

  1. Copy the application (client) ID and the Directory (tenant) ID over to the Interpres integration setup page
Document image

  1. Click Manifest

7. Replace requiredResourceAccess with the following:

Document image

JSON


As an alternative to Step 7, you can manually add the following permissions (as Application):

Text

  1. Click Save
Document image

  1. Click API permissions then Grant admin consent for YOUR_TENANT
Document image

  1. Click Certificates & Secrets then New client secret
Document image

  1. Enter "Interpres" for the description and choose "12 months".
Document image

  1. Copy the client secret "Value" over to the Interpres integration setup.

App Configuration

App Parameters:

  • Tenant ID: Tenant ID
  • Client ID: Client ID
  • Client Secret: Client Secret
  • Limit Data: Optimizes performance by limiting non-essential API requests

App Validation

Check there is connectivity (green light) in the integration created.

Implemented Actions

  • Get Assets: Gets the machines on the network.
  • Get Vulnerabilites: Gets a list of active CVEs for each asset.
  • Get Alerts: Gets the latest triggered alerts.
  • Get Detections: This action processes triggered alerts (not to be confused with the detection logic). These are turned into the Interpres Detection. The detection list should contain any detection that was seen over the course of this plugin being installed.
  • Get Available Telemetry: Returns a list of telemetry identifiers with their current status. This is a static list.