Skip to main content

Microsoft Defender for Endpoint

Endpoint Protection

The Microsoft Defender for Endpoint connector integrates with the Microsoft Defender for Endpoint (ATP) REST API to synchronize endpoint inventory and threat-and-vulnerability-management (TVM) data into the Brinqa platform. It retrieves onboarded machines, installed software, and software vulnerabilities, and maps them to hosts, packages, installed packages, vulnerability findings, and vulnerability definitions.

The connector synchronizes the following categories of data:

  • Machines — Onboarded devices from the Defender for Endpoint inventory, mapped to hosts
  • Packages — Distinct software products discovered across machines
  • Installed Packages — Software installations linking a package to the machine it is installed on
  • Vulnerabilities — Per-device software vulnerability findings
  • Vulnerability Definitions — CVE/recommendation definitions behind the vulnerability findings

Category: Endpoint Protection


Data retrieved from Microsoft Defender for Endpoint

Connector ObjectRequiredMaps to Data Model
MachineYesHost
VulnerabilityYesVulnerability
Vulnerability DefinitionYesVulnerability Definition
PackageYesPackage
Installed PackageYesInstalled Package

Model relationships

note

For detailed steps on how to view the data retrieved from Microsoft Defender for Endpoint in the Brinqa Platform, see How to view your data.