Microsoft Defender XDR
General

Step 5. Develop and test use cases

In brief

The article’s metadata and several passages were updated, including clarification of the SOC Oversight team’s role and streamlined wording for use-case workflow and testing guidance.

What Defender admins need to know

Administrators may find the guidance clearer when defining, prioritizing, and testing SOC use cases.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Step 5. Develop and test use cases

The recommended methods to deploy Microsoft Defender XDR in your Security Operations Center (SOC) depends on the SOC team's current set of tools, processes, and skill set. Maintaining cyber hygiene across platforms can be challenging because of the vast amount of data coming from dozens if not hundreds of security sources.

Security tools are interrelated. Turning on one feature in a security technology or changing a process may in turn break another. For this reason, Microsoft recommends that your SOC team formalize a method for defining and prioritizing use cases. Use cases help define requirements and test processes for SOC operations across various teams. ItA formalized use-case method creates a methodology for capturing metrics to determine if the right roles and mix of tasks are aligned to the right team with the right skill set.

Develop and formalize use case process

The SOC should define a high-level standard and process for developing use cases, which would be regulated by the SOC Oversight team.team—the group responsible for governing SOC standards and cross-functional coordination. The SOC Oversight team should work with your business, IT, legal, HR, and other groups to prioritize use cases for the SOC that will eventually make their way into the SOC team's runbooks and playbooks. Priority of use cases are based on objectives, such as compliance or privacy.

SOC Oversight activities related to use case development include:

:::image type="content" source="media/integrate-microsoft-365-defender-secops-use-cases/use-case-decision-process.png" alt-text="The use-case decision process" lightbox="media/integrate-microsoft-365-defender-secops-use-cases/use-case-decision-process.png":::

Once a high-level use case standard has been defined and approved, the next step is to create and test an actual use case. The new phishing variant and threat and vulnerability scanning examples illustrate this process.the process for creating and testing a use case.

Use case example 1: New phishing variant

Invoke the use case workflow for example 1

OnceAfter the story board has beenstoryboard is approved, the next step is to invoke the use case workflow. Here's an example process for an anti-phishing campaign.

:::image type="content" source="media/integrate-microsoft-365-defender-secops-use-cases/example-detailed-use-case-workflow-phishing.png" alt-text="A detailed use case workflow for an anti-phishing campaign" lightbox="media/integrate-microsoft-365-defender-secops-use-cases/example-detailed-use-case-workflow-phishing.png":::

|Engineering & SecOps Teams|High impact and critical vulnerabilities in assets are remediated according to policy|SecOps engineers, SOC analysts: Vulnerability & Compliance, Security Engineering|Defined process for categorizing High Risk and Critical Vulnerabilities|Microsoft Defender Vulnerability Management Dashboards|Defender for Endpoint has identified high impact, high alert devices with no remediation plan or implementation of Microsoft recommended activity|Add a workflow for notifying asset owners when remediation activity is required within 30 days per policy; Implement a ticketing system to notify asset owners of remediation steps.|N| |Monitoring Teams|Threat and vulnerability status is reported via company intranet portal|Tier 2 SOC analyst|Auto-generated reports from Microsoft Defender XDR showing remediation progress of assets|Investigate alerts in Microsoft Defender XDR

Secure Score monitoring|No views or dashboard reports being communicated to asset owners regarding threat and vulnerability status of assets.|Create automation script to populate status of high risk and critical asset vulnerability remediation to the organization.|N|

In these example use cases, theuse case testing revealed several gaps in the SOC team's requirements that were established as baselines for the responsibilities of each team. The use case checklist can be as comprehensive as needed to ensure that the SOC team is prepared for the Microsoft Defender XDR integration with new or existing SOC requirements. Since this is an iterative process, the use case development process and the use case output content naturally serve to update and mature the SOC's runbooks with lessons learned.

Update production runbooks and playbooks