Forum Discussion

c4s_h3's avatar
c4s_h3
Copper Contributor
Aug 18, 2022

Is it possible to alert on live response session use in Defender for Endpoint?

Live response sessions are logged under the Action Center, but I don't see a way to send alerts when a live response session is initiated.

 

I looked at events in some of the Device-related tables under Advanced Hunting but I could not identify any events that appeared to match the live response session (or at least not obviously so).

 

Live response sessions are powerful tools and I want my security team to have access to them, but I also want to make sure multiple people are notified whenever a live response session is used. Burying this data under History in the Action Center is insufficient.

Resources