Forum Discussion

Qusai_Ismail's avatar
Qusai_Ismail
Brass Contributor
Oct 11, 2022
Solved

Microsoft Defender Antivirus Modes

Hello,

 

Is there a way from Microsoft Sentinel using a Query to check when a device turn off the Defender Antivirus.

 

 

BR,

 

4 Replies

  • P4tr8k's avatar
    P4tr8k
    Brass Contributor
    You can try use this:
    https://github.com/microsoft/Microsoft-365-Defender-Hunting-Queries/blob/master/General%20queries/MD%20AV%20Signature%20and%20Platform%20Version.md
    • Qusai_Ismail's avatar
      Qusai_Ismail
      Brass Contributor
      Thanks, but it's for Defender Hunting, we need to make a rule for periodic check.
      • Jonhed's avatar
        Jonhed
        Iron Contributor
        Like Clive said, this table is only available on security.microsoft.com, so the best option would be to just use a custom detection rule there. This can create MDE incidents when a device with AV disabled is found, and this incident can then be synced to Sentinel through the M365D connector if you want it over there.

Resources