
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
This repository documents how deployment of Microsoft Defender for Endpoint on a Windows 11 device, including onboarding via local script, enabling device discovery, configuring Log4j2 detection (CVE-2021-44228), and validating incident response workflows.
Key Features
✅ Local script onboarding for Windows 10/11
🔍 Standard device discovery setup
🧨 Log4j2 vulnerability detection
📈 Alert validation and incident response
📋 Remediation workflow using Defender tools
Project Objectives
✔️ Deploy Microsoft Defender for Endpoint across Windows 10/11 environment.
✔️ Configure device discovery and threat detection capabilities.
✔️ Enable Log4j2 vulnerability detection (CVE-2021-44228).
✔️ Validate deployment through test detection scenarios.
✔️ Establish incident response workflows
System Requirements
✔️ Windows 11 Pro/Enterprise (latest updates applied)
✔️ Microsoft 365 E3/E5 or Microsoft Defender for Endpoint Plan 1/2 license
✔️ Administrative privileges on target devices
✔️ Network connectivity to Microsoft cloud services
Required Permissions
✔️ Global Administrator or Security Administrator in Microsoft 365
✔️ Local Administrator rights on Windows 11 devices
✔️ Access to Microsoft 365 Defender portal
*Phase 1: Initial Setup and Configuration
1.1 Access Microsoft 365 Defender Portal
✅ Navigate to https://security.microsoft.com
✅ Sign in with administrative credentials
✅ Verify licensing and service availability
1.2 Configure Device Discovery Settings
Navigate to Device Discovery:
✅ Settings → Endpoints → Device discovery
Configure Standard Discovery:
✅ Select "Standard discovery" option
✅ Enable network device discovery
✅ Set discovery frequency to recommended settings
✅ Configure network credentials if required
✅Save Configuration:
✅Apply settings and wait for confirmation
✅Verify discovery scope covers target network segments
1.3 Enable Log4j2 Detection
Access Advanced Features:
✅ Settings → Endpoints → Advanced features
Enable CVE-2021-44228 Detection:
❌ Toggle "Custom network indicators" to ON
❌ Enable "Live response" for advanced investigation
❌ Activate "Automated investigation and remediation"
Configure Detection Rules:
✅ Navigate to Hunting → Advanced hunting
✅ Verify Log4j2 detection queries are active
✅ Customize detection sensitivity if needed
Phase 2: Device Onboarding Process
2.1 Generate Onboarding Script
Navigate to Onboarding Section:
✅ Settings → Endpoints → Device management → Onboarding
Select Deployment Method:
✅ Choose "Local Script" as deployment method
✅ Select Windows 10/11 as operating system
✅ Click "Download onboarding package"
Script Details:
✔️ File name: GatewayWindowsDefenderATPOnboardingScript.cmd
✔️ Contains unique organization-specific configuration
✔️Valid for 30 days from generation
2.2 Deploy Script to Windows 11 Device
Prepare Target Device:
powershell # Open elevated Command Prompt as Administrator
cd C:\Path\To\Script
Execute Onboarding Script:
cmd # Run the onboarding script GatewayWindowsDefenderATPOnboardingScript.cmd
Verify Service Status:
powershell # Check Windows Defender ATP service Get-Service -Name "Sense"
Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows Advanced Threat Protection"
2.3 Validate Device Onboarding
Check Device Status in Portal:
✔️ Navigate to Assets → Devices
✔️ Locate newly onboarded Windows 10/11 device
✔️ Verify status shows as "Active" as shown below
✔️ Confirm last seen timestamp is recent
Device Information Validation:
✔️ Computer name matches target device
✔️ Operating system shows Windows 11
✔️ Risk level initially shows as "medium" (due to the tested script executed)
✔️ Onboarding status: "Successfully onboarded"
Phase 3: Test Detection and Validation
3.1 Generate Test Detection Script
Create a PowerShell script to simulate suspicious activity:
"powershell# Save as TestDetection.ps1
Write-Host "Starting MDE Test Detection..." -ForegroundColor Yellow
$testCommand = "powershell.exe -ExecutionPolicy Bypass -WindowStyle Hidden -Command "Get-Process""
Write-Host "Executing test command: $testCommand" -ForegroundColor Green
Invoke-Expression $testCommand
$testUrl = "https://www.microsoft.com" $testPath = "$env:TEMP\test_download.txt" try { Invoke-WebRequest -Uri $testUrl -OutFile $testPath -UseBasicParsing Write-Host "Test file downloaded to: $testPath" -ForegroundColor Green Remove-Item $testPath -Force -ErrorAction SilentlyContinue } catch { Write-Host "Download test completed with expected behavior" -ForegroundColor Yellow }
try { Get-ItemProperty -Path "HKLM:\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" | Out-Null Write-Host "Registry access test completed" -ForegroundColor Green } catch { Write-Host "Registry test encountered expected restrictions" -ForegroundColor Yellow }
Write-Host "MDE Test Detection completed. Check Microsoft 365 Defender portal for alerts." -ForegroundColor Cyan "
*3.2 Execute Test Detection
Run Test Script:
powershell # Open PowerShell as Administrator
Set-ExecutionPolicy -ExecutionPolicy Bypass -Scope Process .\TestDetection.ps1
Alternative Command Line Test:
cmd # Simple command line test for detection echo "Test detection for MDE" > %TEMP%\mde_test.txt powershell.exe -Command "Get-Content $env:TEMP\mde_test.txt" del %TEMP%\mde_test.txt
3.3 Monitor for Alert Generation Expected Timeline: Alerts typically appear within 5-15 minutes Monitoring Steps:
✔️ Keep the Microsoft 365 Defender portal open
✔️ Refresh the incidents page periodically
✔️ Look for new alerts related to the test device
4.1 Navigate to Incidents and Alerts
Access Investigation Interface:
❌ Investigation & response → Incidents & alerts → Incidents
Locate Test Alert:
❌ Filter by affected device name
❌ Sort by "Last update time" (newest first)
❌ Look for incidents with "Low" or "Medium" severity
4.2 Expand and Review Alert Details
Alert Information Review:
❌ Alert Title: Note the detection name