Map the Microsoft Defender for Endpoint indicator types
Map the ServiceNow Observable type with the Microsoft Defender for Endpoint indicator type. This mapping would be used in Observable Enrichment and Create Indicator actions in Microsoft Defender.
Before you begin
Role required: sn_si.admin or sn_si.analyst (read-only)
About this task
In a scenario where the observable type is not mapped to an indicator type, such observables are not eligible for Observable enrichment and indicator creation in Microsoft Defender for Endpoint.
Procedure
- Navigate to Microsoft Defender for Endpoint > Observable-Indicator Mapping.
Image omitted: observable\_indicator\_mapping.png
Map the Microsoft Defender for Endpoint indicator types
Map the Microsoft Defender for Endpoint indicator types
Add or update an Observable type in one of the following ways:
- To add new mapping, click Add Observable Type.
- To update the Observable to the Indicator type mapping, click any existing row.
- To save the mapping, click Update.