BluSapphire
search
⌘Ctrlk
BluSapphire
  • Release 6.0
    • Release Notes 6.0
    • 01_Unified Platform Architecture
    • 02_What is OnePlatform?
    • 03_DataStreamer
    • 04_AR2 Agentic AI
    • 05_OneAgent
    • 06_What is SIEMless ?
  • Pilot-PoC
    • Proof-Of-Concept / Pilot Guide
  • M-SOC
    • M-SOC_Self Service Portal
  • Older Releases
    • 01_Introduction
    • 02_Unified Cyber Defense Platform
    • 03_The Stack
    • 04_Features and capabilities
    • 05_Operations
    • 06_Architecture
    • 07_Integration
    • 08_Use cases
    • 09_CaseHub
    • 10_Active-Defense-Services
    • 11_1 Data-Pipeline-Manager (DPM)
    • 12_Deployment / Log Forwarding
      • Log Forwarding (on-prem) - How To
      • Cloud Log Forwarding
        • Akamai WAF
        • Azure Sentinel
        • AWS Cloud Logs
        • Configuring Mimecast for Log Collection via API
        • Cisco Umbrella
        • Cisco Duo
        • Cisco AMP
        • Cisco CES
        • SOPHOS AV
        • CROWDSTRIKE
        • Microsoft Defender ATP
          • Enable SIEM integration in Microsoft Defender ATP
          • Assign permissions to the WindowsDefenderATPSiemConnector application
      • BluArmour Pre-Deployment Checklist & Roll out Process
      • Deploy BluArmour via SCCM
      • BluGenie GPO for Service Account, WinRM and WMI
      • Mirror / SPAN port configuration
      • Average LogSize by LogSource
      • Windows Package Installation
      • Linux Package Installation
    • 13_MITRE ATT&CK
    • 14_BluArmour Endpoint Protection
    • 15_BluGenie
  • 16_Best Practices
  • 17_Threat Hunt
  • 18_Taxonomy
  • 19_Product Videos
  • 20_M-SOC_Self Service Portal
  • Customer Self Service Portal
  • Appendix A
  • 21_Incident Response
  • 22_Release 6
gitbookPowered by GitBook
block-quoteOn this pagechevron-down
  1. Older Releaseschevron-right
  2. 12_Deployment / Log Forwardingchevron-right
  3. Cloud Log Forwarding

Microsoft Defender ATP

Enable SIEM integration in Microsoft Defender ATPchevron-rightAssign permissions to the WindowsDefenderATPSiemConnector applicationchevron-right
PreviousCROWDSTRIKEchevron-leftNextEnable SIEM integration in Microsoft Defender ATPchevron-right