Microsoft Defender for Endpoint is an enterprise endpoint detection and response (EDR) platform built into the Microsoft 365 Defender suite. It uses behavioral sensors, cloud-based analytics, and Microsoft’s threat intelligence to detect, investigate, and respond to advanced threats across Windows, macOS, Linux, iOS, and Android devices.
How it works
Connects via direct API (microsoft_atp) to pull endpoint detection telemetry from the Defender console.
Data ingested
EDR alerts, process/device telemetry, threat detections
Frequently asked questions
You connect Expel to Microsoft Defender for Endpoint through a direct API integration, which lets Workbench ingest Defender alerts automatically once your tenant is authorized. Expel’s engineering team configures the connection during onboarding, then verifies alert flow before Defender data is included in active monitoring and Expel’s custom detection logic.
Expel adds custom detections built on top of Defender’s native telemetry, correlation across other connected tools, and analyst-led investigation in Workbench, Expel’s operations platform. Rather than replacing Defender for Endpoint, Expel extends it, mapping detection logic to the MITRE ATT&CK framework and reducing the alert triage burden on internal teams.
Expel’s integration pulls alerts from Microsoft Defender for Endpoint directly into Workbench through an API connection, where Expel analysts investigate them alongside signals from other connected tools. Expel also writes custom detections layered on top of Defender’s native alerts, extending coverage beyond what Defender’s built-in alerting identifies on its own.
Expel goes beyond Defender for Endpoint’s native alerting by ingesting its alerts into Workbench and layering custom detections mapped to the MITRE ATT&CK framework on top of Defender’s raw telemetry. Native alerting flags events; Expel’s approach adds investigation, correlation with other tools, and response, rather than leaving that work to your internal team.
Expel reduces false positives by 66% through AI-driven detections applied across the Microsoft environment, including Defender for Endpoint. That reduction comes from correlating Defender’s native alerts with other telemetry in Workbench and applying custom detection logic, rather than forwarding every raw Defender alert to your team for manual review.
