microsoft-defender-endpoint
Microsoft Defender for Endpoint (MDE) Advanced Hunting authoring guidance — Device*/Email*/Identity* table schemas, Timestamp discipline, ProcessUniqueId vs PID for temporal joins, FileProfile() prevalence enrichment with null handling, AdditionalFields parsing, mandatory output columns for custom detection rules (Timestamp/DeviceId/ReportId), NRT single-table/no-comment constraints, retention boundaries, named-pipe and DGA detection patterns. Always pair with kusto-query-language for language-level optimisation. Use for configurations.defender_for_endpoint blocks in OpenTide MDR objects and Defender-first hypotheses.
Pinned to revision 591443442d56, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/microsoft-defender-endpoint/SKILL.md
- skills/microsoft-defender-endpoint/references/Anti-Patterns.md
Every link opens the file at its source, pinned to the revision this page describes.