{"repo":"msdirtbag/MDEAutomator","free":true,"listed":false,"github":"https://github.com/msdirtbag/MDEAutomator","clone":"git clone https://github.com/msdirtbag/MDEAutomator.git","description":"PowerShell-based Automation of Defender for Endpoint","language":"Python","stars":197,"topics":["azure-functions","bicep","defender","defender-for-endpoint","edr","powershell","app-service","graph"],"license":"GPL-3.0","category":"workflow-automation","readme_excerpt":"MDEAutomator MDEAutomator is designed to support incident response activities in Microsoft Defender for Endpoint (MDE) environments. It leverages Azure serverless componets in a private virtual network and Federated App Registration + UMI (FIC/Workload Identity) authentication for enhanced security. --- Core Components - MDEAutomator PowerShell Module A comprehensive PowerShell module providing cmdlets for Microsoft Defender for Endpoint operations, including advanced authentication, profile management, live response automation, response action orchestration, custom detection management, advanced hunting query execution, and threat indicator lifecycle management. - MDEAutomator A serverless orchestration platform for large-scale response action automation, distributed Live Response command execution across endpoint fleets, and programmatic deployment of PowerShell configuration scripts to Microsoft Defender for Endpoint managed devices. Dispatcher- Isolate Device, Collect Investigation Package, Run Antivirus Scan, Restrict App Execution, Stop & Quarantine File Orchestator- Run Live Response Script, Collect File, Put File, Upload file to Live Response Library Profiles- Active & Passive - Threat Intelligence Manager A threat indicator orchestration system providing automated lifecycle management for diverse indicator types including hashes, network infrastructure indicators (IPs, URLs, domains), and code signing certificates within Microsoft Defender for Endpoint. Features stre","default_branch":null,"files":null,"tree":[],"storefront":"/r/msdirtbag","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/msdirtbag/MDEAutomator/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}