Browse

apis

Browse every api record currently available in the local reference.

api

Microsoft Defender for Endpoint APIs

Microsoft Defender for Endpoint APIs expose endpoint alerts, devices, machine actions, indicators, vulnerability management, software inventory, recommendations, scores, remediation tasks, files, users, and advanced query operations.

api

Microsoft Defender for Endpoint Indicators API

The Microsoft Defender for Endpoint indicators API manages custom indicators of compromise for endpoint enforcement and alerting, including batch import for custom threat intelligence ingestion into Defender for Endpoint.

api

Microsoft Graph Security API

The Microsoft Graph Security API is the unified Microsoft Graph surface for security alerts, incidents, actions, threat submissions, identity security data, and related security operations workflows across supported Microsoft security providers.

api

Legacy Microsoft Defender XDR APIs

The legacy Microsoft Defender XDR API surface covers Defender XDR incidents and advanced hunting endpoints under api.security.microsoft.com. Microsoft Graph Security API is the forward-looking replacement for advanced hunting integrations, and Microsoft says the older advanced hunting endpoints stop returning data on February 1, 2027.

api

Microsoft Sentinel REST API

The Microsoft Sentinel REST API manages Sentinel resources such as incidents, analytics rules, data connectors, bookmarks, and entity information.

api

Azure Monitor Logs Ingestion API

The Azure Monitor Logs Ingestion API sends custom JSON log records through a Data Collection Rule stream into a Log Analytics workspace used by Microsoft Sentinel.

api

Microsoft Sentinel Threat Intelligence Upload API

The Microsoft Sentinel threat intelligence upload API imports custom threat intelligence STIX objects, including indicators, attack patterns, threat actors, identities, and relationships, into a Sentinel workspace without requiring a data connector.