Incident-response retainer support required a collection tool to reach the endpoint, gather its output and return that material to the response team. I built scripts around Microsoft Defender for Endpoint (DfE/MDE) Live Response to automate that sequence for Windows and Linux.
The workflow deployed the retainer’s collector, executed it on the endpoint and uploaded the resulting output through a secured link. It connected the collection tool’s endpoint work to the evidence handover in a repeatable operation.
My contribution was the orchestration around the collector: deployment, execution and transfer. This gave the retainer team a defined route to receive the collected material for the next stage of incident analysis.
Closer to the work
Windows and Linux collection
I built the Live Response collection workflow for Windows and Linux endpoints. In each case, the automation handled deployment and execution of the incident-response retainer’s collection tool.
Open this detail ↗Deployment through evidence transfer
The workflow connected three steps: deploy the collector, run it and upload its output. I automated that sequence through Defender Live Response so the collection request could progress from the endpoint to the retainer team.
Open this detail ↗Secured upload link
The collected output was uploaded through a secured link as part of the scripted sequence. That transfer delivered the material for the retainer’s incident-response work.
Open this detail ↗Skills established through this work