Reader small image

You're reading from  Microsoft Defender for Endpoint in Depth

Product typeBook
Published inMar 2023
PublisherPackt
ISBN-139781804615461
Edition1st Edition
Right arrow
Authors (3):
Paul Huijbregts
Paul Huijbregts
author image
Paul Huijbregts

With almost 20 years of industry experience and relevant certifications, Paul Huijbregts has a long history of working with customers across the world leveraging his passion for (Microsoft) security solutions – and being brutally honest about them. After joining Microsoft in 2016 and engaging regularly with Defender for Endpoint teams, Paul moved to Redmond (together with his wife and kids) to join them and become a product manager – in the middle of the pandemic (October 2020). Here, he is on what is called the “Platforms” team, working on solutions across operating systems and environments, focusing primarily on server endpoints and security management. His motto is: “I drink beer and I know Microsoft security things.”
Read more about Paul Huijbregts

Joe Anich
Joe Anich
author image
Joe Anich

Joe Anich has 15 years of experience in the IT industry ranging from endpoint management with a focus on SCCM and Intune to endpoint security and incident response. Currently working on Microsoft's Detection and Response Team (DART), he works closely with customers during critical moments. Working in incident response has given Joe insight into SOC operations and how to help teams around the world improve their security posture as a whole. Outside of work, Joe enjoys running around the house with his 2-year-old son playing “chase me.” Fun fact: During the late 90s, Joe could be found at the roller-skating rink most Friday nights, gliding around the rink with a super rope in hand, maybe in JNCOs or Lee Pipes, vibing to 90s hip hop.
Read more about Joe Anich

Justen Graves
Justen Graves
author image
Justen Graves

Justen Graves is a security engineer with 14 years of IT experience. Most of his career has been focused on endpoint enablement and security, with the last 4 years spent at Microsoft. Currently working in Microsoft's Cyber Defense Operations Center, their internal SOC, he uses tools such as Microsoft Defender for Endpoint every day to defend corporate Microsoft from attack. Justen has a BS in cybersecurity and an MBA. He holds many industry certifications, including CISSP, PMP, and GSEC, and several Microsoft certifications, including Azure Solutions Architect Expert and Enterprise Administrator Expert. Starting his career at Walmart and managing to never relocate, he resides in Northwest Arkansas with his wife and three children.
Read more about Justen Graves

View More author details
Right arrow

Tips and tricks from the experts

Here are some handy tips and tricks we’ve collected, with some help from the community:

  • Use https://security.microsoft.com/preferences2 to go straight to the MDE settings in the portal.
  • If you are using command-line utilities to troubleshoot, you can use the pipe character to output to the clipboard:
    "c:\Program Files\Windows Defender\MpCmdRun.exe" -ValidateMapsConnection | clip
  • https://gpsearch.azurewebsites.net/ is a great resource to look up Defender settings and their descriptions.
  • @NathanMcNulty shared the following:
    • Learning KQL is one of the highest ROI things you can do:
          // Find ingestion delay
          | extend IngestTime = ingestion_time()
          | project-reorder TimeGenerated,IngestTime
    • The API is incredible, use it
    • Live Response can download and execute applications if you wrap them with scripts ;)
  • @rakidbrahman shared the following: Device tags from...
lock icon
The rest of the page is locked
Previous PageNext Page
You have been reading a chapter from
Microsoft Defender for Endpoint in Depth
Published in: Mar 2023Publisher: PacktISBN-13: 9781804615461

Authors (3)

author image
Paul Huijbregts

With almost 20 years of industry experience and relevant certifications, Paul Huijbregts has a long history of working with customers across the world leveraging his passion for (Microsoft) security solutions – and being brutally honest about them. After joining Microsoft in 2016 and engaging regularly with Defender for Endpoint teams, Paul moved to Redmond (together with his wife and kids) to join them and become a product manager – in the middle of the pandemic (October 2020). Here, he is on what is called the “Platforms” team, working on solutions across operating systems and environments, focusing primarily on server endpoints and security management. His motto is: “I drink beer and I know Microsoft security things.”
Read more about Paul Huijbregts

author image
Joe Anich

Joe Anich has 15 years of experience in the IT industry ranging from endpoint management with a focus on SCCM and Intune to endpoint security and incident response. Currently working on Microsoft's Detection and Response Team (DART), he works closely with customers during critical moments. Working in incident response has given Joe insight into SOC operations and how to help teams around the world improve their security posture as a whole. Outside of work, Joe enjoys running around the house with his 2-year-old son playing “chase me.” Fun fact: During the late 90s, Joe could be found at the roller-skating rink most Friday nights, gliding around the rink with a super rope in hand, maybe in JNCOs or Lee Pipes, vibing to 90s hip hop.
Read more about Joe Anich

author image
Justen Graves

Justen Graves is a security engineer with 14 years of IT experience. Most of his career has been focused on endpoint enablement and security, with the last 4 years spent at Microsoft. Currently working in Microsoft's Cyber Defense Operations Center, their internal SOC, he uses tools such as Microsoft Defender for Endpoint every day to defend corporate Microsoft from attack. Justen has a BS in cybersecurity and an MBA. He holds many industry certifications, including CISSP, PMP, and GSEC, and several Microsoft certifications, including Azure Solutions Architect Expert and Enterprise Administrator Expert. Starting his career at Walmart and managing to never relocate, he resides in Northwest Arkansas with his wife and three children.
Read more about Justen Graves