Indicators of Compromise (IoC) for Mobile devices in Defender for Endpoint
Indicator of compromise (IoCs) is an essential feature in every endpoint protection solution. This capability gives SecOps the ability to set a list of indicators for detection and for blocking. Back in August'21, I had published a blog on ' Creating custom Network Indicator rules in Defender for Endpoint '. As part of the MDE configuration series, I wanted to cover the creation of IoC for mobile devices as well. Now for IoC to work, devices need to be onboarded on MDE and it is no different for mobile devices. You can head over to my posts from February'22 to check out the onboarding process for both iOS and Android mobile devices. One thing to note here is that as of writing this blog, only IPs & URLs\domains under IoC are supported for mobile devices at this point. When creating a new indicator (IoC), one or more of the following actions are available: Allow – the IoC will be allowed to run on your devices. Audit – an alert will be triggered when the IoC runs. ...