You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-endpoint/aggregated-reporting.md
+11-8Lines changed: 11 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -12,7 +12,7 @@ ms.collection:
12
12
- tier3
13
13
ms.topic: article
14
14
search.appverid: met150
15
-
ms.date: 03/04/2025
15
+
ms.date: 10/20/2025
16
16
appliesto:
17
17
- Microsoft Defender for Endpoint Plan 2
18
18
---
@@ -33,13 +33,16 @@ When aggregated reporting is turned on, you can query for a summary of all suppo
33
33
34
34
The following requirements must be met before turning on aggregated reporting:
35
35
36
-
- Defender for Endpoint Plan 2 license
37
36
- Permissions to enable advanced features
38
37
39
-
Aggregated reporting supports the following:
40
38
41
-
- Client version: Windows version 24H and later
42
-
- Operating systems: Windows 11 (22H2, Enterprise), Windows 10 (20H2, 21H1, 21H2), Windows Server 2019 and later, Windows Server version 20H2 or Azure Stack HCI OS, version 23H2 and later
39
+
### Supported operating systems:
40
+
41
+
- Windows 10 (20H2, 21H1, 21H2)
42
+
- Windows 11 (22H2, Enterprise)
43
+
- Windows Server 2019 and later
44
+
- Windows Server version 20H2 or Azure Stack HCI OS, version 23H2 and later
45
+
- Client version: Windows version 24H and later
43
46
44
47
## Turn on aggregated reporting
45
48
@@ -77,9 +80,9 @@ To query new data with aggregated reports:
77
80
3. When necessary, create new custom rules to incorporate new action types.
78
81
4. Go to the **Advanced Hunting** page and query the new data.
79
82
80
-
Here is an example of advanced hunting query results with aggregated reports.
83
+
Here is an example of advanced hunting query results with aggregated reports.
81
84
82
-
:::image type="content" source="/defender-endpoint/media/reports/aggregated-reporting/sample-results-aggregated-reports-small.png" alt-text="Screenshot of advanced hunting query results with aggregated reports." lightbox="/defender-endpoint/media/reports/aggregated-reporting/sample-results-aggregated-reports.png":::
85
+
:::image type="content" source="/defender-endpoint/media/reports/aggregated-reporting/sample-results-aggregated-reports-small.png" alt-text="Screenshot of advanced hunting query results with aggregated reports." lightbox="/defender-endpoint/media/reports/aggregated-reporting/sample-results-aggregated-reports.png":::
Copy file name to clipboardExpand all lines: defender-endpoint/amsi-on-mdav.md
+11-8Lines changed: 11 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -5,7 +5,7 @@ author: batamig
5
5
ms.author: bagol
6
6
manager: bagol
7
7
ms.reviewer: yongrhee
8
-
ms.date: 12/05/2024
8
+
ms.date: 10/20/2025
9
9
appliesto:
10
10
- Microsoft Defender for Endpoint Plan 1
11
11
- Microsoft Defender for Endpoint Plan 2
@@ -29,11 +29,6 @@ ai-usage: ai-assisted
29
29
# Anti-malware Scan Interface (AMSI) integration with Microsoft Defender Antivirus
30
30
31
31
32
-
**Platforms**:
33
-
34
-
- Windows 10 and newer
35
-
- Windows Server 2016 and newer
36
-
37
32
Microsoft Defender for Endpoint utilizes the anti-malware Scan Interface (AMSI) to enhance protection against fileless malware, dynamic script-based attacks, and other nontraditional cyber threats. This article describes the benefits of AMSI integration, the types of scripting languages it supports, and how to enable AMSI for improved security.
38
33
39
34
## What is fileless malware?
@@ -67,9 +62,12 @@ Microsoft Defender Antivirus blocks most malware using generic, heuristic, and b
67
62
- Detecting and remediating WMI persistence techniques by scanning the WMI repository, both periodically and whenever anomalous behavior is observed
68
63
- Detecting reflective DLL injection through enhanced memory scanning techniques and behavioral monitoring
69
64
70
-
## Why AMSI?
65
+
## Prerequisites
71
66
72
-
AMSI provides a deeper level of inspection for malicious software that employs obfuscation and evasion techniques on Windows' built-in scripting hosts. By integrating AMSI, Microsoft Defender for Endpoint offers extra layers of protection against advanced threats.
67
+
### Supported operating systems
68
+
69
+
- Windows 10 and later
70
+
- Windows Server 2016 and later
73
71
74
72
### Supported Scripting Languages
75
73
@@ -84,6 +82,11 @@ If you use Microsoft 365 Apps, AMSI also supports JavaScript, VBA, and XLM.
84
82
85
83
AMSI doesn't currently support Python or Perl.
86
84
85
+
## Why AMSI?
86
+
87
+
AMSI provides a deeper level of inspection for malicious software that employs obfuscation and evasion techniques on Windows' built-in scripting hosts. By integrating AMSI, Microsoft Defender for Endpoint offers extra layers of protection against advanced threats.
88
+
89
+
87
90
### Enabling AMSI
88
91
89
92
To enable AMSI, you need to enable script scanning. See [Configure scanning options for Microsoft Defender Antivirus](configure-advanced-scan-types-microsoft-defender-antivirus.md).
Retrieves a specific live response command result by its index.
42
-
43
-
## Limitations
44
-
45
-
1. Rate limitations for this API are 100 calls per minute and 1500 calls per
46
-
hour.
47
-
48
-
## Minimum requirements
38
+
## Prerequisites
49
39
50
-
Before you can initiate a session on a device, make sure you fulfill the following requirements:
40
+
Devices must be running one of the following versions of Windows:
51
41
52
-
-**Verify that you're running a supported version of Windows**.
42
+
### Supported operating systems
53
43
54
-
Devices must be running one of the following versions of Windows
55
-
56
-
-**Windows 11**
44
+
- Windows 11
57
45
58
-
-**Windows 10**
46
+
- Windows 10
59
47
-[Version 1909](/windows/whats-new/whats-new-windows-10-version-1909) or later
60
48
-[Version 1903](/windows/whats-new/whats-new-windows-10-version-1903) with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)
61
49
-[Version 1809 (RS 5)](/windows/whats-new/whats-new-windows-10-version-1809) with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818)
62
50
-[Version 1803 (RS 4)](/windows/whats-new/whats-new-windows-10-version-1803) with [KB4537795](https://support.microsoft.com/help/4537795/windows-10-update-kb4537795)
63
51
-[Version 1709 (RS 3)](/windows/whats-new/whats-new-windows-10-version-1709) with [KB4537816](https://support.microsoft.com/help/4537816/windows-10-update-kb4537816)
64
52
65
-
-**Windows Server 2019 - Only applicable for Public preview**
53
+
- Windows Server 2019 - Only applicable for Public preview
66
54
- Version 1903 or (with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)) later
67
55
- Version 1809 (with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818))
68
-
69
-
-**Windows Server 2022**
70
56
71
-
-**Windows Server 2025**
72
-
-**Azure Stack HCI OS, version 23H2 and later**
57
+
- Windows Server 2022 and later
58
+
59
+
- Azure Stack HCI OS, version 23H2 and later
60
+
61
+
## API description
62
+
63
+
Retrieves a specific live response command result by its index.
64
+
65
+
## Limitations
66
+
67
+
1. Rate limitations for this API are 100 calls per minute and 1500 calls per
@@ -42,11 +40,11 @@ See [Overview of automated investigations](../automated-investigations.md) for m
42
40
43
41
1. Rate limitations for this API are 50 calls per hour.
44
42
45
-
## Requirements for AIR
43
+
## Prerequisites
46
44
47
-
Your organization must have Defender for Endpoint see:[Minimum requirements for Microsoft Defender for Endpoint](../minimum-requirements.md).
45
+
Your organization must have Defender for Endpoint, see [Minimum requirements for Microsoft Defender for Endpoint](../minimum-requirements.md).
48
46
49
-
Currently, AIR only supports the following OS versions:
47
+
### Supported operating systems
50
48
51
49
- Windows 11
52
50
- Windows 10, version [1803](/windows/release-information/status-windows-10-1809-and-windows-server-2019) or later
@@ -67,8 +65,8 @@ Delegated (work or school account)|Alert.ReadWrite|'Read and write alerts'
67
65
> [!NOTE]
68
66
> When obtaining a token using user credentials:
69
67
>
70
-
> - The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](../user-roles.md) for more information)
71
-
> - The user needs to have access to the device, based on device group settings (See [Create and manage device groups](../machine-groups.md) for more information)
68
+
> - The user needs to have at least the following role permission: 'Active remediation actions' (See [Create and manage roles](../user-roles.md) for more information).
69
+
> - The user needs to have access to the device, based on device group settings (See [Create and manage device groups](../machine-groups.md) for more information).
72
70
>
73
71
> Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.
Before you can initiate a session on a device, make sure you fulfill the following requirements:
41
+
42
+
### Supported operating systems
43
+
44
+
- Windows 11
45
+
46
+
- Windows 10
47
+
-[Version 1909](/windows/whats-new/whats-new-windows-10-version-1909) or later
48
+
-[Version 1903](/windows/whats-new/whats-new-windows-10-version-1903) with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)
49
+
-[Version 1809 (RS 5)](/windows/whats-new/whats-new-windows-10-version-1809) with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818)
50
+
-[Version 1803 (RS 4)](/windows/whats-new/whats-new-windows-10-version-1803) with [KB4537795](https://support.microsoft.com/help/4537795/windows-10-update-kb4537795)
51
+
-[Version 1709 (RS 3)](/windows/whats-new/whats-new-windows-10-version-1709) with [KB4537816](https://support.microsoft.com/help/4537816/windows-10-update-kb4537816)
52
+
53
+
- Windows Server 2019 - Only applicable for Public preview
54
+
- Version 1903 or (with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)) later
55
+
- Version 1809 (with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818))
56
+
57
+
- Windows Server 2022 and later
58
+
59
+
- Azure Stack HCI OS, version 23H2 and later
60
+
61
+
- macOS [(requires other configuration profiles)](../microsoft-defender-endpoint-mac.md)
62
+
- 13 (Ventura)
63
+
- 12 (Monterey)
64
+
- 11 (Big Sur)
65
+
66
+
- Linux servers
67
+
- [Supported Linux distributions](../mde-linux-prerequisites.md#supported-linux-distributions)
68
+
39
69
## API description
40
70
41
71
Runs a sequence of live response commands on a device
@@ -60,42 +90,10 @@ Runs a sequence of live response commands on a device
60
90
61
91
8. Multiple live response sessions can't be executed on the same machine (if live response action is already running, subsequent requests are responded to with HTTP 400 - ActiveRequestAlreadyExists).
62
92
63
-
> [!NOTE]
64
-
> Live response actions initiated from the Device page aren't available in the `machineactions` API.
65
-
66
-
## Minimum Requirements
67
-
68
-
Before you can initiate a session on a device, make sure you fulfill the following requirements:
69
-
70
-
-**Verify that you're running a supported Windows, macOS, or Linux version**.
71
-
72
-
Devices must be running one of the following:
73
-
74
-
-**Windows 11**
75
-
76
-
-**Windows 10**
77
-
-[Version 1909](/windows/whats-new/whats-new-windows-10-version-1909) or later
78
-
-[Version 1903](/windows/whats-new/whats-new-windows-10-version-1903) with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)
79
-
-[Version 1809 (RS 5)](/windows/whats-new/whats-new-windows-10-version-1809) with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818)
80
-
-[Version 1803 (RS 4)](/windows/whats-new/whats-new-windows-10-version-1803) with [KB4537795](https://support.microsoft.com/help/4537795/windows-10-update-kb4537795)
81
-
-[Version 1709 (RS 3)](/windows/whats-new/whats-new-windows-10-version-1709) with [KB4537816](https://support.microsoft.com/help/4537816/windows-10-update-kb4537816)
82
-
83
-
-**Windows Server 2019 - Only applicable for Public preview**
84
-
- Version 1903 or (with [KB4515384](https://support.microsoft.com/help/4515384/windows-10-update-kb4515384)) later
85
-
- Version 1809 (with [KB4537818](https://support.microsoft.com/help/4537818/windows-10-update-kb4537818))
86
-
87
-
-**Windows Server 2022**
88
-
89
-
-**Windows Server 2025**
90
-
-**Azure Stack HCI OS, version 23H2 and later**
93
+
> [!NOTE]
94
+
> Live response actions initiated from the Device page aren't available in the `machineactions` API.
91
95
92
-
-**macOS**[(requires other configuration profiles)](../microsoft-defender-endpoint-mac.md)
93
-
- 13 (Ventura)
94
-
- 12 (Monterey)
95
-
- 11 (Big Sur)
96
96
97
-
-**Linux servers**
98
-
-[Supported Linux distributions](../mde-linux-prerequisites.md#supported-linux-distributions)
0 commit comments