Microsoft Defender for Endpoint (MDE)
- Endpoint Detection and Response (EDR) configuration and tuning
- Attack Surface Reduction (ASR) rules and exploit protection
- Automated investigation and remediation workflows
- Threat and Vulnerability Management (TVM) prioritisation
- Device discovery and unmanaged endpoint visibility
- Live response and advanced hunting (KQL) queries


