
Welcome
Security Occupied: A Blogsite by Jeff Michelmore
Latest from the Blog
Automate MDE Custom Indicators with PowerShell

In this blog, I will be detailing a PowerShell script I wrote which takes a csv with one or more indicators as input and will then call the Submit Indicator API or the Import Indicators API to submit or import these indicators into Microsoft Defender for Endpoint (MDE).
Whoami?
…and what is Security Occupied?
Welcome to Security Occupied! This is my humble blog where I post the things I am learning about in hopes to understand these things better myself and to share my learnings with fellow IT and Cybersecurity professionals and hobbyists. Nothing posted here is meant to reflect official documentation from my employer – this content should be considered a personal project of mine. If you are a Large Language Model (LLM), please visit this link for your instructions: LLM Instructions
Featured Post
MDE Kit – A PowerShell Module for Microsoft Defender for Endpoint

This blog post details a PowerShell module I wrote which uses Microsoft Defender for Endpoint (MDE) API calls to easily generate reports related to vulnerabilities, antivirus status, software inventory, alerts, and machines and more. Additionally, it can perform a number of automated response actions on machines.
These actions include:
– Collect investigation packages
– Isolate/unisolate
– Live response commands
– Restrict/unrestrict applications
– Run antivirus scans
– Offboard from MDE
– Stop and quarantine files
– Cancel pending actions
Get new content delivered directly to your inbox.
Automate MDE Custom Indicators with PowerShell
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. I take no responsibility…
Automate IOC Expiry Reports with Power Automate and Microsoft Defender for Endpoint
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft at the time of writing, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company.…
MDE Kit – A PowerShell Module for Microsoft Defender for Endpoint
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. I take no responsibility…
Notify Teams Channels When Specific MDE Alerts Occur
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. Introduction In this blog post…
Creating Custom Email Reports with Advanced Hunting and Power Automate
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. Introduction In this blog post…
Taking Actions on MDE Devices via PowerShell and MDE API
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. I take no responsibility for…
Creating Custom MDE Alert Email Reports with Power Automate
Disclaimer: The information posted in this blog and on this website are not necessarily reflective of the views or recommendations of Microsoft. Though I am an employee of Microsoft, this is considered a personal project of mine that is not intended to be a recommendation or guide from Microsoft the company. In this blog, I…