July 17, 2023, 9:14 p.m. | /u/Empty_Commercial4221

For [Blue|Purple] Teams in Cyber Defence www.reddit.com

Hi people,

​

I need some help on how to approach the matter: running (automating) a Logic App that not only starts the antivirus scan on an endpoint (using MS Defender) but also updates when the scan is succesfully done / failed for whatever reason.

In most use cases simply starting the av scan is enough, with the idea that potential findings would raise an alert/incident. In my use case, I need to verify the succeeded scan to able to …

amp antivirus app blueteamsec cases defender endpoint logic logic app matter people results running scan updates use cases

Information Security Engineers

@ D. E. Shaw Research | New York City

Technology Security Analyst

@ Halton Region | Oakville, Ontario, Canada

Senior Cyber Security Analyst

@ Valley Water | San Jose, CA

Security Engineer II - Java Fullstack, AWS

@ JPMorgan Chase & Co. | Hyderabad, Telangana, India

Consultant Cybersécurité Industrielle (F-H-X)

@ Bureau Veritas Group | COURBEVOIE, Ile-de-France, FR

Security Engineer II

@ Syniverse | Costa Rica