MSFT Defender Reporting - Content Pack
Description
About Content Packs: FileWave is immensely powerful, but can be daunting when it comes to stitching the various components together. Content packs are meant to give you a leg-up in creating distributable content and are also a great way to learn by example! Each content pack is meant to be a "whole solution", putting together all of the pieces of FileWave to accomplish a goal.
About This Content Pack: This FileWave Content Pack focuses on reporting insteadon ofMicrosoft distributableDefender content,Compliance, and gives you some really great reportingcustom field data and a dashboard built on standardthe inventoryvery datasame to show overallDefender FileWaveis systembehaving andin environmentyour status.environment. The purpose of this pack is provide the information you need to proactively manage your environment and is comprised of all of the contents listed below:
What You Get in this Content Pack
This content pack provides:
Reports (aka Inventory Queries):
Reports are a great way of measuring the effectiveness of distributing content, and can be used for all sorts of compliance purposes as well. Trust, but verify is what reports are all about. In this pack we have included the following reports:
-
-
ActiveMSFTClients:Defender Information:ListAofreportallincludingdevicesdatathat have checked in withinfrom thepastcustom30fieldsdayslisted Android Devices:List of all Android devices enrolledChrome Browsers:Software inventory report on Chrome browser versions installedChromeOS Devices:List of all Chromebook devices enrolledFileset Report Last 7 Days:A list of all fileset content deployed within the last 7 daysFileset Types:A summary report on all FilesetsFileWave Client Versions:Reports on the versions of the FileWave clientbelow formacOSevery Mac and Windowsdevicesdevice. Firefox(YouVersions:maySoftwarewantinventoryto further edit this reportontoFirefoxonlybrowserlookversionsatinstalled"Last iOSConnected"&fortvOSaDevices:certainListtimeofrangealltoiOS/iPadOS/tvOSmakedevicessureenrolledyou macOSareDevices:onlyListreportingof all macOS devices enrolledMissing iOS Patches:A list of all missing iOS patches by deviceMissing macOS Patches:A list of missing patchescompliance onmacOS"active"devicesMissing Windows Patches:A list of missing patches on Windows devicesUpstream Host:This report shows what booster/server the clients are reporting intoVPP Licenses Low:Shows all VPP licenses that are below 10 available licensesWindows Devices:List of all Windows devices enrolleddevices.)
-
Dashboards:
Dashboards build upon reports and are an incredibly powerful tool for showing aggregated data in charts and graphs. This pack provides the following dashboard:
-
-
FileWave OverviewDefender Dashboard: Agreatcollection ofout of-the-boxcompliance chartsand inventory meant tothat give youansummaryeagle-eyeandviewdetailofinformationhowonthingsDefenderarehealth,goingthreatinstatus, and overall compliance to yourenvironment.security standards.
-
Ingredients
-
FileWave Central Admin & Credentials
- Base64 API Token
- Content Pack:
(Only one of the following is needed, based on your admin device's OS platform)
Windows Content Pack | Windows Content Pack Download |
macOS Content Pack (ARM based) |
On macOS, we need to use curl to download so that Gatekeeper doesn't quarantine the import application. You can copy and paste the following into Terminal.app...the example provided downloads import_pack.zip to the desktop
|
macOS Content Pack (Intel based) |
On macOS, we need to use curl to download so that Gatekeeper doesn't quarantine the import application. You can copy and paste the following into Terminal.app...the example provided downloads import_pack.zip to the desktop
|
Directions
-
Download the appropriate content pack above (based on your admin device's platform) and unzip it
- Run the user_interface tool in the user_interface folder, using appropriate credentials for your environment (check out our overview article on importing content packs here)
- Once completed, verify the new content in your system (and import the dashboard)
Sample Screenshots
Notes
Note that you can freely edit any of the content in this content pack. We do recommend reviewing each of the types of content as provided first though so that you can get a feel for how things "fit together" before modification.