Additional Microsoft Defender tools and services that provide security across various platforms and environments
Access Microsoft Defender Advanced Hunting shared queries programmatically
I am trying to automate the creation and management of Advanced Hunting queries for use in the Microsoft Defender portal under the "Investigation & Response -> Hunting -> Advanced Hunting" sidebar items.
There are APIs provided by Azure Management but they only seem to return (or create) the queries under the Microsoft Sentinel folder in that area.
Any queries created outside of the "Microsoft Sentinel" folder are not visible on the APIs.
The picture below highlights the issue. The API's only can return the queries in the RED box. I am unable to see any of the queries with green arrows next to them.
The API being used is: Saved Searches - List By Workspace and its ARM counterpart Microsoft.OperationalInsights workspaces/savedSearches
Using these I am unable to access any query outside the "Microsoft Sentinel" folder.
I have checked both the Defender API (depreciated) and Graph API and neither have endpoints documented that return this data.
Is there some secret endpoint or query string I can use to access these Defender based items.
Outside the scope of this immediate question - I have the same issue with many of the APIs. I am unable to see analytic rules, tuned alerts automation, etc. that were created inside Defender. It is tempting to just use Sentinel for everything - but the Sentinel portal is being depreciated. This leaves me in a poor situation.