Run MDE Antivirus - Alert Triggered

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Content Index


This playbook will run a antivirus (full) scan on the machine in Microsoft Defender for Endpoint. It is triggered by an alert in Microsoft Sentinel.

Attribute Value
Type Playbook
Solution MicrosoftDefenderForEndpoint
Source View on GitHub

Logic App Connectors

This playbook uses 2 Logic App connectors / built-in actions:

Connector / Action Type Connections Actions
azuresentinel Managed 1 4
wdatp Managed 1 2
Action parameters (URLs, paths, function IDs)

azuresentinel (Managed)

Action Method Endpoint Other
Entities_-_Get_Hosts post /entities/host
Add_comment_to_incident_(V3) post /Incidents/Comment
Add_comment_to_incident_(V3)_1 post /Incidents/Comment
Alert_-_Get_incident get /Incidents/subscriptions/@{encodeURIComponent(triggerBody()?['WorkspaceSubscriptionId'])}/resourceGroups/@{encodeURIComponent(triggerBody()?['WorkspaceResourceGroup'])}/workspaces/@{encodeURIComponent(triggerBody()?['WorkspaceId'])}/alerts/@{encodeURIComponent(triggerBody()?['SystemAlertId'])}

wdatp (Managed)

Action Method Endpoint Other
Machines_-_Get_list_of_machines get /api/machines
Actions_-_Run_antivirus_scan post /api/machines/@{encodeURIComponent(variables('MDEDeviceId'))}/runAntiVirusScan

Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊

Back to Playbooks · Back to MicrosoftDefenderForEndpoint