I developed PowerShell scripts for Microsoft Defender for Endpoint (DfE/MDE) Live Response to collect security logs, run investigation commands and inspect network connections or listening services. A shell-like command workflow extended the actions available during an endpoint investigation, while on-demand checks retrieved the device’s current Defender status and configuration.
I also scripted collection of running services and Windows Run-registry entries, feeding the results into agent-assisted review for possible persistence indicators. This brought endpoint artefacts into a repeatable investigation workflow, where the output could be examined alongside the wider incident context.
My KQL functions added Microsoft Entra ID sign-in summaries, VPN IP-to-user and host attribution, and visibility of accounts already disabled by Defender. I paired these tools with analyst runbooks for authentication attacks, Pass-the-Ticket, unwanted software, reconnaissance and Sysmon health, and contributed standards for recording evidence, root cause, impact and response.
Alongside the custom tooling, I enabled Microsoft Defender Attack Disruption for automatic account disabling. That contribution configured the product’s native containment capability; Microsoft provides the disruption logic, while I developed the collection and investigation scripts.
Closer to the work
Services and Run-registry persistence signals
The persistence checks collected running-service information and Windows Run-registry entries, then passed those artefacts to an agent for review. The workflow surfaced potential persistence signals for investigation and brought the relevant endpoint evidence together for examination alongside the wider incident context.
Open this detail ↗Live Response commands and current Defender state
My Live Response scripts covered security-log collection, command execution and network/listening-service inspection. I also developed on-demand retrieval of Defender status and configuration. These checks let an investigation use live endpoint state alongside centrally available EDR telemetry.
Open this detail ↗Native automated account containment
I enabled Microsoft Defender Attack Disruption and its automatic account-disablement capability. This was configuration of a native response feature. The KQL used to identify accounts Defender had disabled was an investigation query, separate from the product’s containment action.
Open this detail ↗Queries and investigation standards
The reusable KQL covered Entra sign-in context, VPN address attribution and Defender account actions. Analyst runbooks explained how to investigate NTLM/Kerberos brute force, Pass-the-Ticket, unwanted software, reconnaissance and Sysmon health. Investigation standards and review criteria covered triage evidence, root cause, impact and response actions.
Open this detail ↗Skills established through this work