API for Timeline values ?

%3CLINGO-SUB%20id%3D%22lingo-sub-2204672%22%20slang%3D%22en-US%22%3EAPI%20for%20Timeline%20values%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2204672%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3EI%20was%20wondering%20where%20the%20information%20for%20%22originally%20impacted%20devices%22%20column%20in%20the%20%22Event%20Timeline%22is%20stored.%20My%20CISO%20is%20interested%20in%20a%20concise%20report%20about%20development%20of%20vulnerability%20numbers.%20I%20have%20to%20Group%20this%20by%20device%20groups%20and%20associated%20risks%20etc.%20So%20I%20need%20a%20table%20that%20I%20can%20link%20with%20the%20inventory%20etc...%3C%2FP%3E%3CP%3EIs%20there%20an%20API%20-%20url%20with%20this%20information%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Occasional Contributor

Hello, 

I was wondering where the information for "originally impacted devices" column in the "Event Timeline"is stored. My CISO is interested in a concise report about development of vulnerability numbers. I have to Group this by device groups and associated risks etc. So I need a table that I can link with the inventory etc...

Is there an API - url with this information?

2 Replies
What i'll usually do here is to import the data through the OData APIs & Advanced Hunting Queries into PowerBI to present the numbers. I'm not sure that you can fetch originally impacted devices from the Event Timeline, but you sure can fetch the vulnerabilitys and make nice reports of it. That could be a way for you, of course, you need a bit of knowledge of how you present the data in BI and some Advanced Hunting Queries. https://docs.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-atp/api-power... There's also some templates, don't really know if they fit your needs: https://github.com/microsoft/MicrosoftDefenderForEndpoint-PowerBI
Hi Axel,
Thank you for your answer.
I already built some nice looking reports with the API and BI.
The only riddle to be solved is : How I "can fetch originally impacted devices from the Event Timeline"...