BluSapphire
Ctrlk
  • 01_Introduction
  • 02_Unified Cyber Defense Platform
  • 03_The Stack
  • 04_Features and capabilities
  • 05_Operations
  • 06_Architecture
  • 07_Integration
  • 08_Use cases
  • 09_CaseHub
  • 10_Active-Defense-Services
  • 11_Data-Pipeline-Manager (DPM)
  • 12_Deployment / Log Forwarding
    • Log Forwarding (on-prem) - How To
    • Cloud Log Forwarding
      • Akamai WAF
      • Azure Sentinel
      • AWS Cloud Logs
      • Configuring Mimecast for Log Collection via API
      • Cisco Umbrella
      • Cisco Duo
      • Cisco AMP
      • Cisco CES
      • SOPHOS AV
      • CROWDSTRIKE
      • Microsoft Defender ATP
        • Enable SIEM integration in Microsoft Defender ATP
        • Assign permissions to the WindowsDefenderATPSiemConnector application
    • BluArmour Pre-Deployment Checklist & Roll out Process
    • Deploy BluArmour via SCCM
    • BluGenie GPO for Service Account, WinRM and WMI
    • Mirror / SPAN port configuration
    • Average LogSize by LogSource
    • Windows Package Installation
    • Linux Package Installation
  • 13_MITRE ATT&CK
  • 14_BluArmour Endpoint Protection
  • 15_BluGenie
  • 16_Best Practices
  • 17_Threat Hunt
  • 18_Taxonomy
  • 19_Product Videos
  • 20_M-SOC_Self Service Portal
  • Customer Self Service Portal
  • Appendix A
  • 21_Incident Response
Powered by GitBook
On this page
  1. 12_Deployment / Log Forwarding
  2. Cloud Log Forwarding

Microsoft Defender ATP

Enable SIEM integration in Microsoft Defender ATPAssign permissions to the WindowsDefenderATPSiemConnector application
PreviousCROWDSTRIKENextEnable SIEM integration in Microsoft Defender ATP