Quickly investigate Microsoft Defender XDR endpoint alerts by auto-building a full process lineage and correlating evidence. The workflow queries process, network, file, and device events around the alert window, generates a rich HTML report with related alerts, and can auto-attach it to a Torq case for streamlined triage.
Use Cases
Function , Threat Hunting
Workflow Breakdown
Compute time window (before/after alert).
Query DeviceProcessEvents, Alert Evidence, Network Events, File Events, Device Events, and Related Alerts.
Build and clean process lineage tree using MSTICPy.
Generate an HTML process tree report.
Optionally attach the HTML report to a Torq case (if torq_case_id is provided).
Vendors
Scripting, Utils, Microsoft 365, Torq Cases
