Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
This playbook automates endpoint response actions in Microsoft Defender for Endpoint (MDE) when SpyCloud breach data identifies compromised machines.
| Attribute | Value |
|---|---|
| Type | Playbook |
| Solution | SpyCloud Enterprise Protection CCF |
| Source | View on GitHub |
This playbook uses 4 Logic App connectors / built-in actions:
| Connector / Action | Type | Connections | Actions |
|---|---|---|---|
azuresentinel |
Managed | 1 | 5 |
office365 |
Managed | 1 | 1 |
wdatp |
Managed | 1 | 3 |
http |
Built-in | 0 | 4 |
azuresentinel (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Entities_-_Get_Hosts | post | /entities/host |
— |
| Create_incident | put | [concat('/Incidents/subscriptions/', subscription().subscriptionId, '/resourceGroups/', resourceGroup().name, '/workspaces/', parameters('Workspace_Name'))] |
— |
| Entities_-_Get_DNS | post | /entities/dnsresolution |
— |
| Entities_-_Get_IPs | post | /entities/ip |
— |
| Entities_-_Get_URLs | post | /entities/url |
— |
office365 (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Send_an_email_(V2) | post | /v2/Mail |
— |
wdatp (Managed)| Action | Method | Endpoint | Other |
|---|---|---|---|
| Machines_-_Get_single_machine | get | /api/machines/@variables('host_name') |
— |
| Actions_-_Isolate_machine | post | /api/machines/@{encodeURIComponent(body('Machines_-_Get_single_machine')?['id'])}/isolate |
— |
| Machines_-_Tag_machine | post | /api/machines/@{encodeURIComponent(body('Machines_-_Get_single_machine')?['id'])}/tags |
— |
http (Built-in)| Action | Method | Endpoint | Other |
|---|---|---|---|
| GetAccessToken | POST | @concat(variables('loginUrl'), parameters('TenantID'), '/oauth2/v2.0/token') |
— |
| Log_ingestion | POST | @variables('log_ingestion_api') |
— |
| Auth_MDE | POST | @concat(variables('loginUrl'), parameters('TenantID'), '/oauth2/v2.0/token') |
— |
| HTTP_-_Create_Indicator | POST | https://api.security.microsoft.com/api/indicators/import |
— |
📄 Source: SpyCloud_MDE_Automation/readme.md
This playbook automates endpoint response actions in Microsoft Defender for Endpoint (MDE) when SpyCloud breach data identifies compromised machines.
Capabilities
Spycloud_MDE_LogsV2_CLSpycloud_MDE_LogsV2_CL (Section 2.2)azuredeploy.json)office365, WindowsDefenderATP, and azuresentinel API connections created by the deploymentAll other settings are workflow parameters, baked into the Logic App with default values. After the playbook is deployed, update them with your own values:
SpyCloud_MDE_Automation playbook — or go directly to the Logic App resource in the Azure Portal| Parameter | Type | Default | Description |
|---|---|---|---|
| Isolate_Machine | Bool | false | Enables automatic machine isolation in Defender for Endpoint |
| Machine_Tag_Value | String | (empty) | Tag value applied to affected machines |
| Save_IOCs_Defender | Bool | false | Enables submitting IOCs to Defender Threat Intelligence |
| IOC_Expiration_Days | Int | 30 | Days before a submitted IOC expires in Defender |
| Spycloud_Defender_DCE_Endpoint | String | (empty) | DCE Logs Ingestion Endpoint URL |
| Spycloud_Defender_DCE_Immutable_ID | String | (empty) | DCR Immutable ID for Spycloud_MDE_LogsV2_CL |
| TenantID | String | (empty) | Azure Tenant ID |
| ClientID | String | (empty) | App Registration Client ID |
| Client_Secret | String | (empty) | App Registration Client Secret |
| Ingestion_Table_Name | String | Spycloud_MDE_LogsV2_CL | Custom Log Analytics table for playbook logs |
| create_incident_in_sentinel | Bool | false | Enables automatic Sentinel incident creation |
| Workspace_Name | String | Your workspace name | Log Analytics Workspace name |
| Defender_IOC_Action_Type | String | Alert | IOC action in Defender, e.g. Alert, Warn, Block, Audit, or AlertAndBlock |
| notification_email | String | (empty) | Notification email address(es), semicolon-separated |
After saving workflow parameters, confirm SpyCloud_MDE_Automation shows status Enabled and check Run History for immediate failures.
Browse: 🏠 · Solutions · Connectors · Methods · Tables · Content · Parsers · ASIM Parsers · ASIM Products · Logic Apps · 📊
↑ Back to Playbooks · Back to SpyCloud Enterprise Protection CCF