Endpoint Agent Health Status Report

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Content Index


This query will provide a report of many of the best practice configurations for Defender ATP deployment. Special Thanks to Gilad Mittelman for the initial inspiration and concept. Any tests which are reporting "BAD" as a result imply that the associated capability is not configured per best practice recommendation.

Attribute Value
Type Hunting Query
Solution GitHub Only
ID 64c0f54f-9a8d-4630-95c8-aa2751e5da0c
Tactics Misconfiguration
Required Connectors MicrosoftThreatProtection
Source View on GitHub

Tables Used

This content item queries data from the following tables:

Table Transformations Ingestion API Lake-Only
DeviceTvmSecureConfigurationAssessment ?

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · 📊

Back to Hunting Queries