Evidence formats
Microsoft Defender for Endpoint export analysis
Export the device events you already pulled in Defender advanced hunting and drop the CSV or JSON into a case. PastePile maps each record by its ActionType, adds it to the same timeline as your other evidence, and runs the Windows compromise pack. Hunts come back as Defender KQL you can paste straight into advanced hunting, alongside Sentinel KQL, Splunk SPL, Elastic ES|QL and Sigma.
What you can upload
- Defender for Endpoint advanced hunting results exported as CSV
- The same results as JSON, including fields Defender nests as JSON inside a column
What PastePile checks
- The Windows compromise checks, applied to the process, registry and network events in the export
- Entities pulled out of the export: hosts, accounts, processes, addresses and domains
- Correlation with EVTX, Sysmon and sign-in evidence in the same case
Every finding cites the records behind it and states what it does not establish. Statistical signals are reported as rarity within your upload and never become findings. ATT&CK mappings describe what a behavior resembles, not proof that an adversary was present.
What it does not do
- A complete Defender XDR incident bundle is not a supported import
- Only the rows you exported are analyzed; PastePile does not query your Defender tenant
Try it
Browse the synthetic demo cases to see a finished investigation without an account. When you are ready, create an account and compare plans.