{"repo":"akefallonitis/xdrlograider","free":true,"listed":false,"github":"https://github.com/akefallonitis/xdrlograider","clone":"git clone https://github.com/akefallonitis/xdrlograider.git","description":"Microsoft Sentinel data connector for Microsoft Defender XDR portal-internal audit endpoints. Self-hosted Azure Function App ingesting events into custom Log Analytics tables via cookie auth with transparent SSO refresh. Per-Category typed schema · dynamic per-tenant capability discovery · Sentinel V3 marketplace integration.","language":"PowerShell","stars":13,"topics":[],"license":"MIT","category":"self-hosted-apps","readme_excerpt":"XdrLogRaider An open-source Microsoft Sentinel data connector for the Microsoft Defender XDR portal-internal endpoints — the audit, reporting, configuration, and posture surfaces that have no public REST API equivalent. Shipped surface: v0.1.0 ships 123 read-only operations across 11 Defender categories into 11 typed Sentinel tables — see the operation catalogue (generated, always current). Each operation dynamically capability-gates (F18) and lights up only on a tenant that licenses the underlying product. Disclaimer: XdrLogRaider reads Defender XDR portal-internal (undocumented) APIs — these are unsupported by Microsoft and may change or break without notice. Use at your own risk; this is not a Microsoft product. Why this exists Microsoft Defender XDR documents three public API surfaces: Advanced Hunting, Incidents, and Streaming. Everything else — Action Center history, Configuration changes, Exposure Management posture, Identity dormant-account audits, Threat Analytics enrichments, and similar — lives behind the portal's internal /apiproxy/ HTTP surface with no Microsoft-supported export path. Security teams that need bulk audit and reporting coverage of those surfaces have nothing standardized to deploy. This connector closes that gap. It runs as a self-hosted Azure Function App in the customer's subscription, authenticates as a dedicated service account, and ingests Defender XDR portal-internal responses into custom Log Analytics tables that Sentinel queries natively. P","default_branch":null,"files":null,"tree":[],"storefront":"/r/akefallonitis","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/akefallonitis/xdrlograider/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}