api-evangelist/microsoft-defender
GitHub: api-evangelist/microsoft-defender
Microsoft Defender 全系列安全 API 的聚合索引与规范集合,提供 OpenAPI、Postman Collection 等标准化接口描述,帮助开发者高效集成微软威胁防护体系。
Stars: 0 | Forks: 0
# Microsoft Defender (microsoft-defender)
Microsoft Defender 安全 API 集合,用于威胁防护、端点安全和安全运营。
**APIs.json:** [https://raw.githubusercontent.com/api-evangelist/microsoft-defender/refs/heads/main/apis.yml](https://raw.githubusercontent.com/api-evangelist/microsoft-defender/refs/heads/main/apis.yml)
## 时间戳
- **创建时间:** 2024-01-15
- **修改时间:** 2026-05-19
## API
### Microsoft Defender for Endpoint API
用于端点检测与响应、威胁与漏洞管理以及自动调查和修复的 API。
#### 标签
- EDR
- 端点安全
- 威胁检测
- 漏洞管理
#### 属性
- [文档](https://learn.microsoft.com/en-us/defender-endpoint/api/apis-intro)
- [OpenAPI](openapi/microsoft-defender-for-endpoint-api-openapi.yml) — [OpenAPI 规范](https://spec.openapis.org/oas/latest.html)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
- [JSON Schema](json-schema/microsoft-defender-alert-schema.json) — [JSON Schema](https://json-schema.org/specification)
- [JSON-LD](json-ld/microsoft-defender-context.jsonld) — [JSON-LD](https://www.w3.org/TR/json-ld11/)
- [身份验证](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-create-app-webapp)
- [定价](https://www.microsoft.com/en-us/security/business/endpoint-security/microsoft-defender-endpoint-pricing)
- [API 参考](https://learn.microsoft.com/en-us/defender-endpoint/api/exposed-apis-list)
- [发行说明](https://learn.microsoft.com/en-us/defender-endpoint/api/api-release-notes)
- [管理 API](https://learn.microsoft.com/en-us/defender-endpoint/api/management-apis)
- [警报 API](https://learn.microsoft.com/en-us/defender-endpoint/api/get-alerts)
- [漏洞 API](https://learn.microsoft.com/en-us/defender-endpoint/api/get-all-vulnerabilities)
- [安全建议 API](https://learn.microsoft.com/en-us/defender-endpoint/api/get-security-recommendations)
### Microsoft Defender for Cloud Apps API
云访问安全代理 (CASB) API,用于发现、调查和治理云应用。
#### 标签
- CASB
- 云安全
- 数据保护
- 影子 IT
#### 属性
- [文档](https://learn.microsoft.com/en-us/defender-cloud-apps/api-introduction)
- [身份验证](https://learn.microsoft.com/en-us/defender-cloud-apps/api-authentication)
- [活动 API](https://learn.microsoft.com/en-us/defender-cloud-apps/api-activities)
- [警报 API](https://learn.microsoft.com/en-us/defender-cloud-apps/api-alerts)
- [实体 API](https://learn.microsoft.com/en-us/defender-cloud-apps/api-entities)
- [云发现 API](https://learn.microsoft.com/en-us/defender-cloud-apps/api-discovery)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Defender Threat Intelligence API
访问威胁情报数据、入侵指标 (IOC) 和威胁分析。
#### 标签
- IOC
- 安全情报
- 威胁分析
- 威胁情报
#### 属性
- [文档](https://learn.microsoft.com/en-us/graph/api/resources/security-threatintelligence-overview)
- [API 参考](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview)
- [身份验证](https://learn.microsoft.com/en-us/graph/auth/)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Graph Security API
用于 Microsoft 安全产品(包括 Defender 警报、安全分数和安全操作)的统一 API。
#### 标签
- 警报
- 安全分数
- 安全图
- 威胁防护
#### 属性
- [文档](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview)
- [OpenAPI](https://developer.microsoft.com/en-us/graph/graph-explorer) — [OpenAPI 规范](https://spec.openapis.org/oas/latest.html)
- [SDK](https://learn.microsoft.com/en-us/graph/sdks/sdks-overview)
- [代码示例](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview#common-use-cases)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Defender for Office 365 API
用于电子邮件和协作保护的 API,包括防钓鱼、防恶意软件和安全附件。
#### 标签
- 协作安全
- 电子邮件安全
- 钓鱼保护
- 安全附件
#### 属性
- [文档](https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/defender-for-office-365)
- [威胁防护](https://learn.microsoft.com/en-us/microsoft-365/security/office-365-security/threat-explorer)
- [安全链接](https://learn.microsoft.com/en-us/defender-office-365/safe-links-about)
- [安全附件](https://learn.microsoft.com/en-us/defender-office-365/safe-attachments-about)
- [服务说明](https://learn.microsoft.com/en-us/office365/servicedescriptions/office-365-advanced-threat-protection-service-description)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Defender XDR API
统一的扩展检测与响应 API,用于根据跨 Microsoft 安全产品的共享事件和高级搜寻表自动执行工作流。
#### 标签
- 高级搜寻
- 事件流式处理
- 事件
- 威胁防护
- XDR
#### 属性
- [文档](https://learn.microsoft.com/en-us/defender-xdr/api-overview)
- [API 参考](https://learn.microsoft.com/en-us/defender-xdr/api-supported)
- [身份验证](https://learn.microsoft.com/en-us/defender-xdr/api-access)
- [事件 API](https://learn.microsoft.com/en-us/defender-xdr/api-incident)
- [高级搜寻 API](https://learn.microsoft.com/en-us/defender-xdr/api-advanced-hunting)
- [流式处理 API](https://learn.microsoft.com/en-us/defender-xdr/streaming-api)
- [支持的事件类型](https://learn.microsoft.com/en-us/defender-xdr/supported-event-types)
- [错误代码](https://learn.microsoft.com/en-us/defender-xdr/api-error-codes)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Defender for Cloud REST API
REST API,用于在 Azure、其他云和本地跨混合云工作负载进行统一的安全管理和高级威胁防护。
#### 标签
- Azure 安全
- 云安全
- CSPM
- 安全状况
- 工作负载保护
#### 属性
- [文档](https://learn.microsoft.com/en-us/rest/api/defenderforcloud/)
- [入门指南](https://learn.microsoft.com/en-us/azure/defender-for-cloud/get-started)
- [定价](https://azure.microsoft.com/en-us/pricing/details/defender-for-cloud/)
- [发行说明](https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
### Microsoft Defender for Identity API
用于跨本地 Active Directory 和混合环境的基于身份的攻击检测和调查的 API,通过 Microsoft Graph 进行传感器管理。
#### 标签
- Active Directory
- 身份安全
- 身份威胁检测
- 传感器管理
#### 属性
- [文档](https://learn.microsoft.com/en-us/defender-for-identity/)
- [概述](https://learn.microsoft.com/en-us/defender-for-identity/what-is)
- [架构](https://learn.microsoft.com/en-us/defender-for-identity/architecture)
- [Graph 安全 API](https://learn.microsoft.com/en-us/graph/api/resources/security-api-overview)
- [Postman Collection](collections/microsoft-defender-for-endpoint-api.postman_collection.json) — [Postman Collection 2.1](https://schema.getpostman.com/json/collection/v2.1.0/collection.json)
- [Open Collection](collections/microsoft-defender-for-endpoint-api.opencollection.json) — [Open Collection 1.0](https://schema.opencollection.com/opencollection/v1.0.0.json)
## 通用属性
- [GitHub 组织](https://github.com/MicrosoftDocs)
- [门户](https://security.microsoft.com)
- [文档中心](https://learn.microsoft.com/en-us/microsoft-365/security/)
- [状态页面](https://status.azure.com/)
- [服务条款](https://www.microsoft.com/en-us/legal/terms-of-use)
- [隐私政策](https://privacy.microsoft.com/en-us/privacystatement)
- [开发者更新日志](https://developer.microsoft.com/en-us/changelog)
- [安全博客](https://www.microsoft.com/en-us/security/blog/)
- [Microsoft Graph 资源管理器](https://developer.microsoft.com/en-us/graph/graph-explorer)
- [身份验证概述](https://learn.microsoft.com/en-us/graph/auth/)
- [安全定价概述](https://www.microsoft.com/en-us/security/pricing-overview)
## 维护者
**姓名:** Kin Lane
**邮箱:** kin@apievangelist.com
标签:GPT, Microsoft Defender, PB级数据处理, 威胁防护, 安全运维, 漏洞管理, 终端检测与响应