Microsoft Defender
Collection of Microsoft Defender security APIs for threat protection, endpoint security, and security operations.
APIs
Microsoft Defender for Endpoint API
API for endpoint detection and response, threat and vulnerability management, and automated investigation and remediation.
Microsoft Defender for Cloud Apps API
Cloud Access Security Broker (CASB) API for discovering, investigating, and governing cloud apps.
Microsoft Defender Threat Intelligence API
Access threat intelligence data, indicators of compromise (IOCs), and threat analytics.
Microsoft Graph Security API
Unified API for Microsoft security products including Defender alerts, secure scores, and security actions.
Microsoft Defender for Office 365 API
API for email and collaboration protection including anti-phishing, anti-malware, and safe attachments.
Microsoft Defender XDR API
Unified extended detection and response API for automating workflows based on shared incident and advanced hunting tables across Microsoft security products.
Microsoft Defender for Cloud REST API
REST API for unified security management and advanced threat protection across hybrid cloud workloads in Azure, other clouds, and on-premises.
Microsoft Defender for Identity API
API for identity-based attack detection and investigation across on-premises Active Directory and hybrid environments, with sensor management via Microsoft Graph.