How to import bulk indicators to Microsoft defender security center

%3CLINGO-SUB%20id%3D%22lingo-sub-2346709%22%20slang%3D%22en-US%22%3EHow%20to%20import%20bulk%20indicators%20to%20Microsoft%20defender%20security%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2346709%22%20slang%3D%22en-US%22%3E%3CP%3EHello%2C%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20new%20in%20Microsoft%2C%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20trying%20to%20import%20IoC's%20using%20a%20CSV%20file%20to%20%22Microsoft%20Defender%20Security%20Center%20-%26gt%3B%20Indicators%22.%3C%2FP%3E%3CP%3EI%20know%20how%20to%20do%20a%20single%20hash%2C%20but%20I'm%20looking%20for%20bulk%20import.%20sample%20file%20is%20not%20very%20hlepful.%3C%2FP%3E%3CP%3EAny%20suggestions!!%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2346772%22%20slang%3D%22en-US%22%3ERe%3A%20How%20to%20import%20bulk%20indicators%20to%20Microsoft%20defender%20security%20center%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2346772%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F818175%22%20target%3D%22_blank%22%3E%40Sohel%3C%2FA%3E%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20just%20went%20through%20this%20process%20this%20morning.%20In%20the%20same%20page%20where%20you%20add%20the%20single%20entry%20by%20selecting%20%22Add%20Item%22%2C%20you'll%20find%20to%20the%20left%20the%20option%20%22Import%22%2C%20this%20will%20give%20you%20the%20option%20to%20upload%20a%20CSV%20file%20with%20all%20the%20entries%20you%20want%20and%20the%20important%20part%2C%20is%20that%20you'll%20find%2C%20at%20the%20bottom%20of%20the%20side%20window%20that%20opened%2C%20a%20Download%20sample%20CSV%20file.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThe%20file%20by%20itself%20is%20pretty%20descriptive%2C%20but%20in%20the%20documentation%20%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoft-365%2Fsecurity%2Fdefender-endpoint%2Findicator-manage%3Fview%3Do365-worldwide%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Epage%3C%2FA%3E%20you%20will%20also%20find%20which%20fields%20are%20required%2Foptional.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHope%20this%20helps.%3C%2FP%3E%3C%2FLINGO-BODY%3E
New Contributor

Hello, 

I'm new in Microsoft, 

I'm trying to import IoC's using a CSV file to "Microsoft Defender Security Center -> Indicators".

I know how to do a single hash, but I'm looking for bulk import. sample file is not very hlepful.

Any suggestions!!

 

Thanks.

 

 

 

 

 

1 Reply

Hi @Sohel,

 

I just went through this process this morning. In the same page where you add the single entry by selecting "Add Item", you'll find to the left the option "Import", this will give you the option to upload a CSV file with all the entries you want and the important part, is that you'll find, at the bottom of the side window that opened, a Download sample CSV file.

 

The file by itself is pretty descriptive, but in the documentation page you will also find which fields are required/optional.

 

Hope this helps.