Live Response is a crucial tool for Incident Responders, and we are strong believers that Live Response should and could be used in ways that helps organizations to automate and orchestrate containment and response actions.
With that in mind, and following-up on last year's Live response public preview announcement, we are happy to share that we continue to expand support of existing APIs across all of our supported platforms in Microsoft Defender for Endpoint, alongside announcing new ones that will help simplify and augment organization's response automation and orchestration.
First, Live Response API is now available in Public Preview for Linux, providing a path for real-time actions against these platforms, with built-in capabilities to upload and download files and executescripts. Customers that are already using Live Response API for Windows 10, Windows Server 2019 and other supported OS versions will see no change in the actual API schema. Just ensure that you select the correct scripts to be executed :)
Here are the links for the existing Microsoft Defender for Endpoint Live Response APIs documentation, if you haven't yet had a chance to read it before:
To check how to use Live Response API, please refer to the initial announcement of Live Response API, referenced at the beginning of this article.
Last, but not least, we are now also making available in Public Preview, the new API that will allow you to manage the Live Response Library (storage within the service to host scripts and other relevant tools for Incident Responders).
How to use the Live Response Library API
In this tutorial we will show you how to use the Live Response Library API to upload a file and then list existing files available in the library.
Step 1 - Upload file to Live Response Library
Request (HTTP POST)
And here is an example of a curl command, to upload a file (mdatp1.png), with a given description and finally with the option to override the file if it already exists in the library.
From our end, we would like to extend a big Thank You to all of our customers and promise you that we will continue to bring you new and improved features and capabilities that will definitely delight you.