Skip to main content
Retrieve a list of indicators that have communicated with Microsoft Defender for Endpoint cloud. The following permissions are required to run this action:
  • Ti.ReadWrite
  • Ti.ReadWrite.All
External DocumentationTo learn more, visit the Microsoft Defender for Endpoint documentation.

Parameters

Example Output

Workflow Library Example

List Indicators with Microsoft Defender for Endpoint and Send Results Via Email
Workflow LibraryPreview this Workflow on desktop