Home
%3CLINGO-SUB%20id%3D%22lingo-sub-269121%22%20slang%3D%22en-US%22%3EStart%20consuming%20Windows%20Defender%20ATP%20alerts%20data%20on%20IBM%20QRadar%20SIEM%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-269121%22%20slang%3D%22en-US%22%3E%3CP%3EHi%20Everyone%2C%3C%2FP%3E%0A%3CP%3EWe%E2%80%99re%20very%20excited%20to%20share%20that%20IBM%20QRadar%20has%20released%20an%20adapter%20for%20Windows%20Defender%20Advanced%20Threat%20Protection.%20IBM%20QRadar%20now%20joins%20the%20list%20of%20security%20event%20and%20incidents%20management%20(SIEM)%20solutions%20that%20can%20consume%20Windows%20Defender%20ATP%20alerts%20data%2C%20alongside%20ArcSight%20and%20Splunk.%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20more%20information%20about%20connecting%20Windows%20Defender%20ATP%20to%20IBM%20QRadar%2C%20see%3A%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fwindows-defender-atp%2Fenable-siem-integration-windows-defender-advanced-threat-protection%23integrate-windows-defender-atp-with-ibm-qradar%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fwindows%2Fsecurity%2Fthreat-protection%2Fwindows-defender-atp%2Fenable-siem-integration-windows-defender-advanced-threat-protection%23integrate-windows-defender-atp-with-ibm-qradar%3C%2FA%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EThanks%2C%3C%2FP%3E%0A%3CP%3EWindows%20Defender%20ATP%20Team%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Hi Everyone,

We’re very excited to share that IBM QRadar has released an adapter for Windows Defender Advanced Threat Protection. IBM QRadar now joins the list of security event and incidents management (SIEM) solutions that can consume Windows Defender ATP alerts data, alongside ArcSight and Splunk. 

For more information about connecting Windows Defender ATP to IBM QRadar, see: https://docs.microsoft.com/en-us/windows/security/threat-protection/windows-defender-atp/enable-siem...

 

Thanks,

Windows Defender ATP Team