> For the complete documentation index, see [llms.txt](https://docs.realmjoin.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.realmjoin.com/pt/automacao/runbooks/runbook-references/org/security/add-defender-indicator.md).

# Adicionar indicador do Defender

### Descrição

Cria um novo indicador no Microsoft Defender for Endpoint para permitir ou bloquear um hash de ficheiro, impressão digital de certificado, IP, domínio ou URL específicos. A ação do indicador pode gerar alertas automaticamente para ações de auditoria ou de alertar e bloquear.

### Localização

Organização → Segurança → Adicionar indicador do Defender

**Nome completo do runbook**

rjgit-org\_security\_add-defender-indicator

### Detalhes

| Propriedade         | Valor                              |
| ------------------- | ---------------------------------- |
| Versão              | 1.0.2                              |
| Módulos necessários | RealmJoin.RunbookHelper (>= 0.8.9) |
| Agendável           | não                                |

### Permissões

#### Permissões de aplicação

* **Tipo**: WindowsDefenderATP
  * Ti.ReadWrite.All
    * *Cria o indicador de ameaça (hash, IP, domínio ou URL) via POST /indicators no Defender for Endpoint*

### Parâmetros

#### IndicatorValue

Valor do indicador, como um hash, impressão digital, endereço IP, nome de domínio ou URL.

| Propriedade  | Valor      |
| ------------ | ---------- |
| Obrigatório  | verdadeiro |
| Valor padrão |            |
| Tipo         | String     |

#### IndicatorType

Tipo do valor do indicador.

| Propriedade                | Valor         |
| -------------------------- | ------------- |
| Obrigatório                | verdadeiro    |
| Valor padrão               | FileSha256    |
| Tipo                       | String        |
| Nome de exibição no portal | IndicatorType |

**Opções do portal**

| Opção do portal                  | Valor                 |
| -------------------------------- | --------------------- |
| Hash SHA256 do ficheiro          | FileSha256            |
| Hash SHA1 do ficheiro            | FileSha1              |
| Hash MD5 do ficheiro             | FileMd5               |
| Impressão digital do certificado | CertificateThumbprint |
| Endereço IP                      | IpAddress             |
| Nome de domínio                  | Nome do domínio       |
| Url                              | Url                   |

#### Título

Título da entrada do indicador.

| Propriedade  | Valor      |
| ------------ | ---------- |
| Obrigatório  | verdadeiro |
| Valor padrão |            |
| Tipo         | String     |

#### Descrição

Descrição da entrada do indicador.

| Propriedade  | Valor      |
| ------------ | ---------- |
| Obrigatório  | verdadeiro |
| Valor padrão |            |
| Tipo         | String     |

#### Ação

Ação aplicada ao indicador.

| Propriedade                | Valor      |
| -------------------------- | ---------- |
| Obrigatório                | verdadeiro |
| Valor padrão               | Permitido  |
| Tipo                       | String     |
| Nome de exibição no portal | Ação       |

**Opções do portal**

| Opção do portal     | Valor             |
| ------------------- | ----------------- |
| Alerta              | Alerta            |
| Avisar              | Avisar            |
| Bloquear            | Bloquear          |
| Auditar             | Auditar           |
| Bloquear e remediar | BlockAndRemediate |
| Alertar e bloquear  | AlertAndBlock     |
| Permitido           | Permitido         |

#### Severidade

Severidade usada para o indicador.

| Propriedade                | Valor       |
| -------------------------- | ----------- |
| Obrigatório                | verdadeiro  |
| Valor padrão               | Informativo |
| Tipo                       | String      |
| Nome de exibição no portal | Severidade  |

**Opções do portal**

| Opção do portal | Valor       |
| --------------- | ----------- |
| Informativo     | Informativo |
| Baixa           | Baixa       |
| Média           | Média       |
| Alta            | Alta        |

#### GenerateAlert

Se definido como true, é gerado um alerta quando o indicador corresponde.

| Propriedade  | Valor    |
| ------------ | -------- |
| Obrigatório  | falso    |
| Valor padrão | Falso    |
| Tipo         | Booleano |

[Voltar à visão geral da referência do runbook](/pt/automacao/runbooks/runbook-references.md)


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.realmjoin.com/pt/automacao/runbooks/runbook-references/org/security/add-defender-indicator.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
