Retrieve a list of indicators that have communicated with Microsoft Defender for Endpoint cloud.The following permissions are required to run this action:
The filter to apply on the operation. You can filter by application, createdByDisplayName, expirationTime, generateAlert, title, rbacGroupNames, rbacGroupIds, indicatorValue, indicatorType, creationTimeDateTimeUtc, createdBy, action, and severity.
Limit
The amount of results which will be returned. Max value is 10,000.
Offset
The offset of the item at which to begin the response.