Skip to content

[meta] Update Microsoft Defender XDR integration to Leverage Native Cloud Security Workflows #14558

@kcreddy

Description

@kcreddy

As part of effort to leverage Cloud Security workflows such as Elastic CSPM and CNVM for 3rd party integrations, the vulnerabilities data from Microsoft Defender XDR (formerly M365 Defender) needs to be enriched just like previous enhancements for Wiz, Qualys VMDR, and Rapid7 InsighVM.

For this work, the m365_defender.vulnerability data stream which ingests exported vulnerabilities of assets must be enriched to support Elastic CNVM workflow.

Tasks:

Metadata

Metadata

Assignees

Type

No type
No fields configured for issues without a type.

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions