Security Incident Response integration with Microsoft Defender for Endpoint
Investigate and remediate security incidents in one place.
Install Trend
View Install Data
| Date | Install Count | Change |
|---|---|---|
| 2026-09-09 | 0 | - |
| 134 days of no change | ||
| 2026-04-27 | 83 | -83 |
| 163 days of no change | ||
| 2025-11-14 | 81 | +2 |
| 1 days of no change | ||
| 2025-11-12 | 80 | +1 |
| 14 days of no change | ||
| 2025-10-28 | 79 | +1 |
| 5 days of no change | ||
| 2025-10-22 | 78 | +1 |
| 5 days of no change | ||
| 2025-10-16 | 77 | +1 |
| 9 days of no change | ||
| 2025-10-06 | 76 | +1 |
| 2025-10-05 | 75 | +1 |
| 10 days of no change | ||
| 2025-09-24 | 74 | +1 |
| 1 days of no change | ||
| 2025-09-22 | 73 | +1 |
| 10 days of no change | ||
| 2025-09-11 | 72 | +1 |
| 2025-09-10 | 71 | +1 |
| 5 days of no change | ||
| 2025-09-04 | 70 | +1 |
| 1 days of no change | ||
| 2025-09-02 | 69 | +1 |
| 11 days of no change | ||
| 2025-08-21 | 68 | +1 |
| 30 days of no change | ||
| 2025-07-21 | 67 | +1 |
| 15 days of no change | ||
| 2025-07-05 | 66 | +1 |
| 32 days of no change | ||
| 2025-06-02 | 65 | +1 |
| 2025-06-01 | 64 | +1 |
| 13 days of no change | ||
| 2025-05-18 | 63 | +1 |
| 19 days of no change | ||
| 2025-04-28 | 62 | +1 |
| 27 days of no change | ||
| 2025-03-31 | 61 | +1 |
| 21 days of no change | ||
| 2025-03-09 | 60 | +1 |
| 3 days of no change | ||
| 2025-03-05 | 59 | +1 |
| 2025-03-04 | 58 | +1 |
| 32 days of no change | ||
| 2025-01-30 | 57 | +1 |
| 3 days of no change | ||
| 2025-01-26 | 56 | +1 |
| 23 days of no change | ||
| 2025-01-02 | 55 | +1 |
| 63 days of no change | ||
| 2024-10-30 | 53 | +2 |
About
The Microsoft Defender for Endpoint enables organizations to proactively inspect, analyze, and contain known and unknown threats on any endpoint.
The Security Incident Response integration with Microsoft Defender for Endpoint makes it easier and more efficient for Security Analysts to investigate and remediate security incidents without having to navigate between tools. You can use network containment to perform remediation actions on the endpoints, implement profiles to gather specific details about the host, and perform actions on the endpoint.
Key Features
- Perform host enrichment actions to gather more information about the endpoint such as host details and user details.
- Perform Enterprise Security Search to sight potential malicious observables across endpoints, and take remediation actions.
- Retrieve machine details that accessed various observables as a part of the security incident analysis.
- Perform remediation actions on endpoints like Run Anti-virus scan, Restrict app execution, Removing app restriction, Stop and Quarantine a file.
- Create or update indicators in Microsoft Defender for Endpoint.