Microsoft Security Tech Accelerator
Dec 06 2023, 07:00 AM - 12:00 PM (PST)
Microsoft Tech Community

Service installation alerts

Copper Contributor

Hi all,

Can Defender for endpoint create an alert when a new service is installed?

1 Reply
Yes. The DeviceEvents table includes the ServiceInstalled action type