Forum Discussion

mohan_infosec's avatar
mohan_infosec
Brass Contributor
Sep 11, 2021

Microsoft defender API

Hello community, I have one question. We are using alienvault otx to get IOC of domains/IP's. It's huge data and every platform will have some limitations of blocking these IOC's. For example, In Microsoft defender, we can only block 15k per tenant. We are usually taking these IOC and checking in virustotal to see if it is already detected by a firewall, Microsoft defender to avoid adding duplicates. How you guys are handling this situation? Is there any way to do automation using graph API to check if it is already detected by the defender?

No RepliesBe the first to reply

Resources