Agent skill

Defender For Endpoint

by vinayaklatthe in vinayaklatthe/microsoft-security-skills

Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…

MITAuto-check passedSecurity

Install Defender For Endpoint

skills CLI
$ npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-endpoint -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install vinayaklatthe/microsoft-security-skills defender-for-endpoint --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/vinayaklatthe/microsoft-security-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/defender-for-endpoint .claude/skills/defender-for-endpoint && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
defender-for-endpoint
GitHub stars
175
Token cost
~2.3k tokens
SKILL.md length
1,005 words
Files
1
Skills in repo
50
Repo updated
First seen
Licence
MIT

At a glance

Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…

  • Works in 9 steps: Confirm plan + estate inventory —… → Enable tamper protection everywhere… → Onboard in waves — 100 pilot devices for… → …
  • Non-endpoint Defender workloads (use defender-xdr for cross-workload
  • SKILL.md covers When to use, Pick the plan and the…, Approach and Guardrails, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Defender For Endpoint is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation and remediation (AIR), and live response. Covers Plan 1 vs Plan 2 selection, onboarding paths (Intune, Configuration Manager, GPO, scripts), ASR rule rollout in audit→block, EDR in block mode, tamper protection, device groups and RBAC, and response actions (isolate, restrict, live response). WHEN: Defender for Endpoint…

Its SKILL.md is about 2.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Security, covering Speech recognition and synthesis, Vulnerability scanning and Threat modeling. It works with Microsoft Defender, Linux, macOS and Microsoft Azure. The repository describes itself as: Curated Microsoft Security skills for AI agents - Defender, Sentinel, Entra, Purview, Intune, Security Copilot. The licence is MIT.

When your agent uses it

  • Non-endpoint Defender workloads (use defender-xdr for cross-workload
  • Defender-for-cloud-hardening for Azure resources)

Example prompts

  • “/defender-for-endpoint”

Workflow steps

9 steps, taken from the first numbered list in SKILL.md.

  1. Confirm plan + estate inventory — Inventory devices by OS, management state, and current
  2. Enable tamper protection everywhere first — Before any other policy. Without it,
  3. Onboard in waves — 100 pilot devices for 7 days, then a representative wave (1,000 or
  4. Next-gen AV policy — Real-time protection on, cloud-delivered protection on (High
  5. ASR rules - audit, measure, block — Enable all rules in audit for 14 days. Use the
  6. EDR in block mode — Enable even if Defender AV is primary. If a non-Microsoft AV is
  7. Device groups & RBAC — Build device groups by risk tier (workstation, server, tier-0
  8. Vulnerability management — Prioritise by exposure score + threat insight, not
  9. AIR — Configure remediation level per device group. Workstations = Full, servers =

What it can do on your machine

Read from SKILL.md and the folder at commit 15f16df. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • learn.microsoft.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Defender For Endpoint loads about 2.3k tokens when it runs. Until then it costs about 258 tokens; SKILL.md has 1,005 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~258
When it runs · the whole SKILL.md, loaded when a task matches
~2.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from vinayaklatthe/microsoft-security-skills at commit 15f16df, republished under its MIT licence (© vinayaklatthe). 1,005 words, ~2,307 tokens.

Download SKILL.mdSave it as .claude/skills/defender-for-endpoint/SKILL.md (or your agent's skills folder).
name
defender-for-endpoint
description
Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation and remediation (AIR), and live response. Covers Plan 1 vs Plan 2 selection, onboarding paths (Intune, Configuration Manager, GPO, scripts), ASR rule rollout in audit→block, EDR in block mode, tamper protection, device groups and RBAC, and response actions (isolate, restrict, live response). WHEN: Defender for Endpoint, MDE, MDE onboarding, endpoint EDR, attack surface reduction rules, ASR rules audit mode, next-gen antivirus policy, device isolation, endpoint vulnerability management, EDR block mode, tamper protection, onboard devices to Defender, live response, MDE Plan 1 vs Plan 2, security settings management, MDE for Linux, MDE for macOS, controlled folder access. DO NOT USE for non-endpoint Defender workloads (use defender-xdr for cross-workload, defender-for-cloud-hardening for Azure resources).
license
MIT
metadata.author
Microsoft
metadata.version
0.1.0

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint (MDE) is the enterprise endpoint security platform providing prevention (next-gen AV, ASR), detection and response (EDR), threat & vulnerability management (Defender Vulnerability Management), and automated investigation and remediation (AIR). It feeds the endpoint pillar of Defender XDR.

When to use

Protecting Windows, macOS, Linux, iOS, and Android endpoints. This is the right skill for onboarding decisions, policy design, ASR rollout, EDR tuning, and response action scoping.

Do not use this skill for cross-workload investigation (defender-xdr), Azure resource hardening (defender-for-cloud-hardening), or identity-side detection (defender-for-identity).

Pick the plan and the onboarding path

If you need...Plan / SKUNotes
Next-gen AV, ASR, web/network protection, manual responseMDE Plan 1Bundled with M365 E3 since 2022
EDR, AIR, advanced hunting, custom detections, Threat & Vuln ManagementMDE Plan 2Bundled with M365 E5 / MDE P2
Full vulnerability remediation workflows, browser extension assessmentsDefender Vulnerability Management add-onAdds to P2
Server endpoints (Windows / Linux)MDE for Servers via Defender for CloudPer-server billing, includes MDE P2
EstatePreferred onboarding path
Cloud-managed Windows (Intune-managed)Intune + Security Settings Management
Co-managed (MECM + Intune)Configuration Manager workload slider, then move to Intune
AD-joined only, no MDMGPO onboarding script
Server (Windows/Linux)Defender for Cloud auto-provisioning
macOS / Linux workstationsIntune with MDM enrollment
Air-gapped / one-offLocal script (90-day expiry)

Rule of thumb: if a device exists in Intune, onboard via Intune Security Settings Management - one place to manage AV + ASR + EDR. GPO is the legacy fallback, not the default for new builds.

Approach

  1. Confirm plan + estate inventory — Inventory devices by OS, management state, and current AV. Map to plan/onboarding path table above. Verify: Get-MpComputerStatus on a sample Win11 device shows AMServiceEnabled = True; Intune shows the device as compliant.

  2. Enable tamper protection everywhere first — Before any other policy. Without it, attackers (and well-meaning admins) can disable everything else. Verify: device shows tamper protection On in security.microsoft.com → Settings → Endpoints → Advanced features.

  3. Onboard in waves — 100 pilot devices for 7 days, then a representative wave (1,000 or 10% of estate), then the rest. Watch the Device inventory for stuck devices (Last seen

    24h after onboarding). Verify: device count in MDE matches Intune device count within 5%.

  4. Next-gen AV policy — Real-time protection on, cloud-delivered protection on (High block level for high-risk groups), PUA blocking in audit then block, tamper protection on, network protection in block, controlled folder access in audit (then block on user workstations only - servers break). Verify: Defender configuration management report shows green on these toggles for the pilot group.

  5. ASR rules - audit, measure, block — Enable all rules in audit for 14 days. Use the ASR rules report to see which rules would have blocked what. Move noisy rules to a tighter scope (e.g. exclude line-of-business apps), then block the rest. Verify: ASR rules report shows zero blocks for known-good apps in audit; promote to block one rule per week.

  6. EDR in block mode — Enable even if Defender AV is primary. If a non-Microsoft AV is primary, EDR in block mode is mandatory - it's the only way EDR detections result in automatic remediation. Verify: Device health page shows EDR block mode = On.

  7. Device groups & RBAC — Build device groups by risk tier (workstation, server, tier-0 admin workstation, kiosk). Scope response actions (isolate, live response) per group. Tier-0 admin devices = tightest policy, fewest analysts with response rights.

  8. Vulnerability management — Prioritise by exposure score + threat insight, not raw CVE count. Push remediation tasks to Intune via the integration.

  9. AIR — Configure remediation level per device group. Workstations = Full, servers = Semi (require analyst approval). Review pending actions in the Action Center daily.

Show full SKILL.md (405 more words)Show less

Guardrails

  • Tamper protection before anything else. Without it, every other control is a suggestion.
  • Always pilot ASR rules in audit mode. Some rules (e.g. Block Office from creating child processes) break legitimate macro workflows. 14 days minimum in audit.
  • EDR in block mode is mandatory with third-party AV. Without it, EDR alerts fire but no automatic remediation happens.
  • Don't grant Live Response broadly. It executes arbitrary commands on endpoints. Scope via RBAC to a small response team, audit every session.
  • Device groups drive policy and response. Build them by risk tier, not by department.
  • Don't run dual AV with both active. Either Defender is primary (recommended) or set Defender to passive mode + EDR block mode on.
  • Server onboarding flows through Defender for Cloud. Don't dual-onboard servers via both MDE direct and DfC - causes telemetry duplication.

Common anti-patterns

  • "Tamper protection off because admins need to manage AV locally" - Local management is the threat model. Centralise via Intune; tamper protection on.
  • "All ASR rules to block on day one" - Will break Office macros, legitimate scripts, and installers. Audit 14 days, tune, then block.
  • "We use third-party AV and skipped EDR block mode" - Detections fire but nothing happens. Enable EDR block mode.
  • "Live Response for all SOC analysts" - Live Response = remote shell. Tier-3 only, with audit review.
  • "Onboarded servers via Intune script instead of Defender for Cloud" - Loses Defender for Servers billing/management integration. Always DfC for server onboarding.
  • "Vuln management ranked by CVE count" - 5,000 informational CVEs hide the 3 exploited ones. Sort by exposure score + active threat campaigns.
  • "Controlled folder access on servers" - Breaks application file writes. CFA is for user workstations only.

Example prompts

  • Plan MDE Plan 1 vs Plan 2 for a 10,000-user M365 E3 tenant - what do we lose without P2?
  • Onboard 5,000 Intune-managed Windows 11 devices to MDE with security settings management.
  • Roll out ASR rules safely - audit first, then block. Which rules are safe to block immediately?
  • Enable EDR in block mode with CrowdStrike as primary AV.
  • Design MDE device groups for a 3-tier estate: workstations, servers, tier-0 admin devices.
  • Configure AIR remediation levels - workstations vs servers.
  • Prioritise vulnerability remediation using exposure score and threat insight.
  • Scope Live Response to a 5-person response team with audit logging.

Microsoft Learn

© vinayaklatthe, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/defender-for-endpoint of vinayaklatthe/microsoft-security-skills.

Open the folder on GitHubat commit 15f16df

Compare with similar skills

Defender For Endpoint next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Defender For Endpoint compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Defender For Endpoint this skillvinayaklatthe/microsoft-security-skills175—~2.3kAutomated safety check: PassMIT
Configuring Windows Defender Advanced Settingsmukul975/Anthropic-Cybersecurity-Skills34k—~3.1kAutomated safety check: PassApache-2.0
Recon Osinthypnguyen1209/offensive-claude388—~2.2kAutomated safety check: PassMIT
Remediate Image Cveskubernetes-sigs/cloud-provider-azure294—~3.9kAutomated safety check: PassApache-2.0
Azure External Attack Surface ManagementMicrosoftDocs/Agent-Skills776—~935Automated safety check: PassCC-BY-4.0
Murmurxiaopengde/murmur109—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Configuring Windows Defender Advanced Settings

    mukul975/Anthropic-Cybersecurity-Skills

    Configures Microsoft Defender for Endpoint (MDE) advanced protection settings including attack surface reduction rules, controlled folder access, network protection, and exploit protection.

    34k GitHub stars~3.1k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Recon Osint

    hypnguyen1209/offensive-claude

    A skill your agent uses when mapping a target's external attack surface or gathering OSINT — subdomain enumeration, attack-surface mapping (httpx/katana/JS secrets), subdomain takeover…

    388 GitHub stars~2.2k tokensUpdated 13 days ago
    SecurityAuto-check passed
  • Remediate Image Cves

    kubernetes-sigs/cloud-provider-azure

    Official

    Orchestrate end-to-end CVE remediation for the Linux CCM, CNM, and health-probe-proxy images on cloud-provider-azure master or a release-X.Y branch, including builds, repeated Trivy verification…

    294 GitHub stars~3.9k tokensUpdated 2 days ago
    SecurityAuto-check passed
  • Official

    Expert knowledge for Azure External Attack Surface Management development including configuration.

    776 GitHub stars~935 tokensUpdated 5 days ago
    SecurityAuto-check passed
  • Murmur

    xiaopengde/murmur

    把一段中文(或任意 Whisper 支持语言)的会议/面试录音用本地 Whisper large-v3 转成文本,再清洗成带说话人标签、修过 ASR 错字、分好章节的 markdown 文档(可选再转成 docx)。跨平台(macOS Apple Silicon 用 mlx-whisper,Windows/Linux/Intel Mac 用…

    109 GitHub stars~2.9k tokensUpdated 4 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Local Asr

    ysyecust/lecture-to-notes

    把本地长视频/音频转写成文字稿 + 可选字幕,纯本地(不上传云端),用 sherpa-onnx X-ASR Zipformer transducer 模型(int8 量化、中英双语、自动标点)。已在 macOS Apple Silicon(int8 + AMX,~100× 实时)、Linux ARM64(CPU,~32× 实时)与 Windows(PowerShell…

    273 GitHub stars~1.6k tokensUpdated 8 days ago
    AI & LLM EngineeringAuto-check passed

More from vinayaklatthe/microsoft-security-skills

All 50 skills in this repo
  • API Security Design

    vinayaklatthe/microsoft-security-skills

    Guidance for designing secure APIs on Azure - authentication, authorization, gateway controls, input validation, rate limiting, secret management, and runtime threat detection - aligned to OWASP API…

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure App Service Security

    vinayaklatthe/microsoft-security-skills

    Guidance for securing Azure App Service web apps and APIs — managed identity, Easy Auth with Microsoft Entra ID, network isolation via private endpoints + VNet integration, HTTPS / TLS hardening…

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Arc

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Arc — projecting on-premises, multicloud (AWS/GCP), and edge servers, Kubernetes, and data services into Azure Resource Manager for unified governance, security, and management.

    175 GitHub stars~1.9k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Bastion Jit

    vinayaklatthe/microsoft-security-skills

    Guidance for secure remote VM management in Azure using Azure Bastion combined with Defender for Cloud just-in-time (JIT) VM access.

    175 GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Confidential Computing

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure Confidential Computing — protecting data in use through hardware-based Trusted Execution Environments (TEEs).

    175 GitHub stars~2.4k tokensUpdated 3 mo ago
    Auto-check passed
  • Azure Ddos Protection

    vinayaklatthe/microsoft-security-skills

    Guidance for Azure DDoS Protection — Network Protection (per-VNet) and IP Protection (per public IP) tiers built on the same always-on Microsoft platform.

    175 GitHub stars~2k tokensUpdated 3 mo ago
    Auto-check passed

Questions about Defender For Endpoint

What does Defender For Endpoint do?

Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation…. Defender For Endpoint is an agent skill from vinayaklatthe/microsoft-security-skills. Guidance for Microsoft Defender for Endpoint (MDE) — enterprise endpoint security with next-gen AV, EDR, attack surface reduction (ASR), Defender Vulnerability Management, automated investigation and remediation (AIR), and live response.

When should I use Defender For Endpoint?

Defender For Endpoint fits situations like: non-endpoint Defender workloads (use defender-xdr for cross-workload; defender-for-cloud-hardening for Azure resources).

How do I install Defender For Endpoint in Claude Code?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-endpoint -a claude-code`. Or copy the skill folder (skills/defender-for-endpoint in vinayaklatthe/microsoft-security-skills) into .claude/skills/defender-for-endpoint in your project. Claude Code loads it when a task matches its description.

How do I install Defender For Endpoint in Codex?

Run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-endpoint -a codex`. Or copy the skill folder (skills/defender-for-endpoint in vinayaklatthe/microsoft-security-skills) into .agents/skills/defender-for-endpoint in your project. Codex loads it when a task matches its description.

Can I use Defender For Endpoint in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add vinayaklatthe/microsoft-security-skills --skill defender-for-endpoint -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/defender-for-endpoint, .gemini/skills/defender-for-endpoint, .github/skills/defender-for-endpoint and .opencode/skills/defender-for-endpoint in your project.

What does Defender For Endpoint need to run?

SKILL.md names no scripts, command-line tools or credentials: Defender For Endpoint is instructions for the agent only.

Does Defender For Endpoint access the network?

SKILL.md names 1 domain. As links in the text: learn.microsoft.com. This is read from the text; nothing was executed.

Is Defender For Endpoint safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Defender For Endpoint use?

Defender For Endpoint is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Defender For Endpoint use?

About 2.3k tokens (SKILL.md is roughly 9.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Defender For Endpoint?

Skills that share tags, products or a category with Defender For Endpoint: Configuring Windows Defender Advanced Settings (mukul975/Anthropic-Cybersecurity-Skills, 34k stars), Recon Osint (hypnguyen1209/offensive-claude, 388 stars), Remediate Image Cves (kubernetes-sigs/cloud-provider-azure, 294 stars) and Azure External Attack Surface Management (MicrosoftDocs/Agent-Skills, 776 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Defender For Endpoint?

vinayaklatthe (a GitHub user) maintains it in vinayaklatthe/microsoft-security-skills, which has 175 GitHub stars. The repository holds 50 skills in this directory. The repository was last updated on June 18, 2026.

Source: vinayaklatthe/microsoft-security-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.