A new way to bring NetClean risk intelligence into Microsoft environments
Organizations using Microsoft Defender for Endpoint and Microsoft Sentinel have another way to put NetClean risk intelligence to work — without deploying additional NetClean endpoint software.
Using Microsoft Defender’s data collection capabilities, file activity can be collected through the existing Microsoft environment and relevant file hashes forwarded to the NetClean File Analysis API for matching against our risk intelligence.
Build on the Microsoft environment already in place
For organizations already using Microsoft Defender for Endpoint and Sentinel, the approach provides a practical path to NetClean risk intelligence while building on existing security infrastructure.
The flow is straightforward:
Matches can then be incorporated into existing Sentinel workflows, including incidents, alerts and response processes. This allows organizations to add NetClean risk intelligence while continuing to work within their established Microsoft security environment.
File activity analyzed against NetClean risk intelligence
The approach uses file activity collected by Microsoft Defender for Endpoint, including files being created, modified, renamed or deleted. Relevant file hashes can then be forwarded from Sentinel to the NetClean File Analysis API for matching against NetClean risk intelligence.
This provides visibility into file movement and presence, rather than confirmed viewing or consumption of content. For organizations requiring dedicated endpoint detection designed to identify content consumption, NetClean File Detection for Endpoints provides that deeper level of visibility.
Together, these approaches give organizations different ways to put NetClean risk intelligence to work depending on their existing environment and requirements.
Designed to fit existing security workflows
The exact implementation and scope depend on the customer environment, including which devices, folders and file activity are included in the collection.
For organizations using Microsoft Defender for Endpoint and Microsoft Sentinel, this provides another way to integrate NetClean risk intelligence into security operations without introducing additional NetClean endpoint software.
Interested in exploring how this could fit into your environment?
Contact our team to learn more about using Microsoft Defender and Sentinel together with the NetClean File Analysis API.
Share article