defender-tvm
Installation
SKILL.md
Microsoft Defender TI & Vulnerability Management
This skill covers two complementary capabilities:
- Microsoft Defender Vulnerability Management (MDVM) — risk-based vulnerability management for endpoints (Windows, macOS, Linux, mobile), firmware, browser extensions, certificates, and security baselines.
- Microsoft Defender Threat Intelligence (Defender TI / MDTI) — Microsoft's finished-intel and raw-IOC product for adversary tracking, infrastructure pivoting, and threat hunting enrichment.
Both feed Defender XDR and Sentinel.
When to use
- Prioritizing patching/remediation across a large endpoint estate.
- Measuring exposure score and security baseline drift.
- Hunting and responding to threats with adversary intel and infrastructure data.
- Enriching SIEM alerts with intel profiles and indicator context.