Home
%3CLINGO-SUB%20id%3D%22lingo-sub-103084%22%20slang%3D%22en-US%22%3EWhat's%20new%20in%20the%20WDATP%20Portal%3F%20March%2023rd%202017%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-103084%22%20slang%3D%22en-US%22%3E%3CP%3E%3CFONT%20color%3D%22%23993366%22%3E%3CSTRONG%3EWindows%20Defender%20ATP%20%26amp%3B%20O365%20integration%20%E2%80%93%20it%E2%80%99s%20here!%3C%2FSTRONG%3E%3C%2FFONT%3E%3CBR%20%2F%3EWe%E2%80%99ve%20all%20being%20waiting%20for%20this%20for%20a%20long%20time%2C%20and%20we%20can%20finally%20announce%3A%20it%E2%80%99s%20here!!%26nbsp%3B%3CBR%20%2F%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22455i3AB89E7C95649398%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%221.jpg%22%20title%3D%221.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3E%3CFONT%20color%3D%22%23993366%22%3E%26nbsp%3B%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3E%3CFONT%20color%3D%22%23993366%22%3E%3CSTRONG%3EMachine%20timeline%20full%20verbose%20mode%20%26amp%3B%20advanced%20search%3C%2FSTRONG%3E%3C%2FFONT%3E%3CBR%20%2F%3EWe're%20turning%20on%20%22Full%20Verbose%20mode%22%20-%20which%20means%20the%20Machine%20Timeline%20now%20displays%20ALL%20raw%20events%20-%20without%20aggregations%20or%20any%20other%20filtering.%3CBR%20%2F%3ETo%20allow%20you%20to%20harness%20this%20huge%20amount%20of%20information%2C%20we're%20enabling%20Typed%20Search%20over%20the%20Machine%20Timeline%20combined%20with%20Filtering%20by%20Event%20Type.%3CBR%20%2F%3ESo%20you%20can%20enter%20any%20filename%2C%20hash%2C%20command%20line%2C%20etc.%2C%20then%20filter%20the%20results%20to%20only%20view%20Process%20events%20matching%20the%20search%20criteria%2C%20or%20to%20only%20view%20file%20events%2C%20%3CBR%20%2F%3Eor%20even%20better%3A%20to%20view%20only%20network%20events%20over%20a%20period%20of%20time%20to%20make%20sure%20no%20suspicious%20outbound%20communications%20go%20unnoticed.%3CBR%20%2F%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20998px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22457iF4F567F2F975D822%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%222.jpg%22%20title%3D%222.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20color%3D%22%23993366%22%3E%3CSTRONG%3EDomain-joined%2C%20AAD-joined%2C%20and%20unjoined%20machines%3C%2FSTRONG%3E%3C%2FFONT%3E%3CBR%20%2F%3EWe%20now%20display%20the%20association%20of%20machines%20more%20consistently%3A%3CBR%20%2F%3E%E2%80%A2%26nbsp%3BDomain-joined%20machines%20will%20have%20their%20domain%20displayed%3CBR%20%2F%3E%E2%80%A2%26nbsp%3BAAD-joined%20machines%20will%20display%20%22AAD%20joined%22%20in%20the%20machine%20domain%20field%3CBR%20%2F%3E%E2%80%A2%26nbsp%3BWorkgroup-joined%20machines%20(%22unjoined%22)%20will%20display%20%22Workgroup%22%20in%20the%20machine%20domain%20field%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3E%3CSTRONG%3E%3CFONT%20color%3D%22%23993366%22%3EProcess%20field%20reparenting%20support%3C%2FFONT%3E%3C%2FSTRONG%3E%3CBR%20%2F%3EWhen%20a%20process%20is%20elevated%2C%20its%20reported%20parent%20(e.g.%20the%20initiating%20process)%20svchost%20will%20be%20displayed%20in%20the%20process%20tree%2C%20while%20its%20logical%20parent%20will%20be%20reported%20%3CBR%20%2F%3Ein%20the%20reparented%20process%20fields.%20The%20process%20tree%20will%20display%20the%20logical%20parent%20with%20a%20description%20explaining%20that%20it's%20elevated.%3CBR%20%2F%3EBeta%20feature%20(flighting%20on%20MSFT%20only).%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3E%3CSTRONG%3E%3CFONT%20color%3D%22%23993366%22%3EResponse%20Actions%20-%20Improved%20Usability%3C%2FFONT%3E%3C%2FSTRONG%3E%3CBR%20%2F%3EWe%20added%20the%20option%20of%20canceling%20a%20pending%20response%20action%20-%20simply%20open%20the%20Action%20Center%20from%20the%20Actions%20menu%20and%20click%20on%20%22X%20Cancel%20action%22%3CBR%20%2F%3E%26nbsp%3B%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20998px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F22458iE5FE9C10EBBDE1A7%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%223.jpg%22%20title%3D%223.jpg%22%20%2F%3E%3C%2FSPAN%3E%3CBR%20%2F%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20color%3D%22%23993366%22%3E%3CSTRONG%3ESIEM%20Onboarding%20Automation%3C%2FSTRONG%3E%3C%2FFONT%3E%3CBR%20%2F%3EWe%20created%20a%20new%20SIEM%20onboarding%20automation%20wizard%20in%20the%20portal.%3CBR%20%2F%3ECustomers%20can%20now%20login%20to%20the%20portal%20and%20create%20an%20AAD%20application%20for%20SIEM%20in%20a%20single%20click.%20Once%20the%20Application%20is%20created%2C%20%3CBR%20%2F%3Ethey%20can%20download%20a%20details%20files%20specifically%20for%20their%20SIEM%20solution%20and%20generate%20tokens%20to%20be%20used%20in%20configuring%20the%20SIEM%20connector.%20%3CBR%20%2F%3EWhat%20used%20to%20be%20a%20long%20and%20complicated%20process%20is%20now%20short%20and%20simple%2C%20and%20adoption%20is%20already%20showing%20its%20first%20fruits%3A%3CBR%20%2F%3ESince%20releasing%20the%20new%20onboarding%20wizard%2C%20two%20customers%20have%20already%20used%20it%20to%20create%20an%20application%3B%3CBR%20%2F%3Eone%20downloaded%20a%20Splunk%20properties%20file%20and%20queried%20our%20Alerts%20RESTful%20service%20-%2014%20minutes%20to%20complete%20the%20E2E%20flow!%3CBR%20%2F%3E%26nbsp%3B%3CBR%20%2F%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20952px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F19568iFC0C47249CC1FFAC%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%224.jpg%22%20title%3D%224.jpg%22%20%2F%3E%3C%2FSPAN%3E%26nbsp%3B%3CBR%20%2F%3E%3CFONT%20color%3D%22%23993366%22%3E%3CSTRONG%3ESIEM%20Documentation%3C%2FSTRONG%3E%3C%2FFONT%3E%3CBR%20%2F%3EWe%20updated%20SIEM%20TechNet%20documentation%20to%20align%20with%20the%20new%20SIEM%20onboarding%20automation%20process.%20%3CBR%20%2F%3EIn%20addition%2C%20we%20published%20the%20list%20of%20available%20fields%20in%20the%20alerts%20API%20and%20documented%20the%20process%20of%20pulling%20alerts%20directly%20from%20the%20alerts%20REST%20API%2C%20%3CBR%20%2F%3Eincluding%3A%20authorization%20flow%20to%20obtain%20access%20tokens%2C%20alerts%20API%20request%20syntax%20and%20parameters%2C%20response%2C%20and%20code%20example.%3CBR%20%2F%3ECustomers%20can%20now%20programmatically%20access%20the%20alerts%20API%20and%20pull%20alerts%20directly%20to%20their%20existing%20systems%20-%20One%20customer%20is%20already%20using%20this%20option%2C%20%3CBR%20%2F%3Eother%20customers%20are%20on%20the%20way.%3CBR%20%2F%3EThank%20you%2C%3CBR%20%2F%3EWindows%20Defender%20ATP%20team%3C%2FP%3E%3C%2FLINGO-BODY%3E
Microsoft

Windows Defender ATP & O365 integration – it’s here!
We’ve all being waiting for this for a long time, and we can finally announce: it’s here!! 
 1.jpg
 
 

Machine timeline full verbose mode & advanced search
We're turning on "Full Verbose mode" - which means the Machine Timeline now displays ALL raw events - without aggregations or any other filtering.
To allow you to harness this huge amount of information, we're enabling Typed Search over the Machine Timeline combined with Filtering by Event Type.
So you can enter any filename, hash, command line, etc., then filter the results to only view Process events matching the search criteria, or to only view file events,
or even better: to view only network events over a period of time to make sure no suspicious outbound communications go unnoticed.
 2.jpg

 

Domain-joined, AAD-joined, and unjoined machines
We now display the association of machines more consistently:
• Domain-joined machines will have their domain displayed
• AAD-joined machines will display "AAD joined" in the machine domain field
• Workgroup-joined machines ("unjoined") will display "Workgroup" in the machine domain field
 
Process field reparenting support
When a process is elevated, its reported parent (e.g. the initiating process) svchost will be displayed in the process tree, while its logical parent will be reported
in the reparented process fields. The process tree will display the logical parent with a description explaining that it's elevated.
Beta feature (flighting on MSFT only).
 
Response Actions - Improved Usability
We added the option of canceling a pending response action - simply open the Action Center from the Actions menu and click on "X Cancel action"
 3.jpg
 

SIEM Onboarding Automation
We created a new SIEM onboarding automation wizard in the portal.
Customers can now login to the portal and create an AAD application for SIEM in a single click. Once the Application is created,
they can download a details files specifically for their SIEM solution and generate tokens to be used in configuring the SIEM connector.
What used to be a long and complicated process is now short and simple, and adoption is already showing its first fruits:
Since releasing the new onboarding wizard, two customers have already used it to create an application;
one downloaded a Splunk properties file and queried our Alerts RESTful service - 14 minutes to complete the E2E flow!
 
4.jpg 
SIEM Documentation
We updated SIEM TechNet documentation to align with the new SIEM onboarding automation process.
In addition, we published the list of available fields in the alerts API and documented the process of pulling alerts directly from the alerts REST API,
including: authorization flow to obtain access tokens, alerts API request syntax and parameters, response, and code example.
Customers can now programmatically access the alerts API and pull alerts directly to their existing systems - One customer is already using this option,
other customers are on the way.
Thank you,
Windows Defender ATP team