# Azure/Microsoft-Defender-for-Cloud

Welcome to the Microsoft Defender for Cloud community repository

Repository: https://github.com/Azure/Microsoft-Defender-for-Cloud
Canonical: https://ross.abutalabs.com/products/microsoft-defender-for-cloud
Homepage: https://azure.microsoft.com/en-us/services/security-center/
Language: PowerShell
License: MIT
License Family: permissive
Last push: 2026-07-09T17:31:42+00:00

## Health v2 (maintenance only)
Score: 73/100 (v2, computed 2026-09-03T02:20:16.233290+00:00)
- activity 91, release rhythm 35, longevity 100
- inputs: {"age_days": 2680, "days_push": 55, "days_rel": null, "gap_med": null, "n_releases_24m": 0}
- flags: no_releases
- formula: round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10)

## Adoption (not part of the score)
Stars 1930, forks 869 (observed 2026-08-28T04:05:56.086705+00:00)

## What it is
The official Microsoft Defender for Cloud community repository containing PowerShell scripts, Azure Policy definitions, Logic App templates, and workbooks for programmatically managing Microsoft Defender for Cloud (formerly Azure Security Center). It provides automations for security recommendations, remediation, and alert response that are not yet built into the product.

## Use cases
- remediate Azure security recommendations programmatically at scale
- automate response to Defender for Cloud security alerts with Logic Apps
- manage Azure Policy custom definitions for security posture
- run scheduled security reports and tasks for Defender for Cloud
- visualize Defender for Cloud data in custom workbooks
- manage Microsoft Defender for Cloud settings via PowerShell

## When to choose
- you use Microsoft Defender for Cloud and need programmatic at-scale management beyond the portal
- you want to automate remediation of security recommendations across many subscriptions
- you need Logic App templates for alert and recommendation response automation
- you want preview security recommendations and community automations before they ship in the product

## When to avoid
- you need a fully supported product with SLA - these community automations are provided as-is
- you are not using Microsoft Defender for Cloud or Azure
- you need a general-purpose security scanning tool rather than Defender for Cloud extensions
- you want a turnkey application rather than scripts, templates, and policy definitions

## Facets
- artifact type: application
- maturity: active
- function: security, workflow-automation, developer-tools, monitoring
- domain: security, cloud-computing
- platform: cloud, windows, cross-platform
- tags: microsoft-defender-for-cloud, azure-security-center, cnapp, cloud-security-posture, logic-apps, azure-policy, powershell-scripts, community-repository, remediation, security-automation, devops, automation

## Member repositories
- Azure/Microsoft-Defender-for-Cloud (main) score 73

## Provenance
- Observed fields: from GitHub, fetched 2026-08-28T04:05:56.086705+00:00.
- Health v2: computed from the inputs above; adoption is never an input.
- Inferred fields (summary, facets, guidance): AI-extracted, prompt v1, taxonomy v1, on 2026-08-30T03:08:43.192540+00:00, confidence not recorded.
  - readme: https://github.com/Azure/Microsoft-Defender-for-Cloud (fetched 2026-08-28T04:05:56.086705+00:00, sha a2b55a773dd2)
  - homepage: https://azure.microsoft.com/en-us/services/security-center/ (fetched 2026-08-29T10:49:33.008635+00:00, sha 8ef60ae352cd)
  - site_page: https://learn.microsoft.com/docs (fetched 2026-08-29T10:49:33.022026+00:00, sha f29800be2b9a)
  - site_page: https://www.microsoft.com/en-us/security/pricing-overview (fetched 2026-08-29T10:49:33.018089+00:00, sha b7f130a8cfbd)
  - site_page: https://learn.microsoft.com/en-us/security (fetched 2026-08-29T10:49:33.020151+00:00, sha b52b0bdd02c8)
  - site_page: https://azure.microsoft.com/en-us/pricing/purchase-options/azure-account?icid=azurefreeaccount (fetched 2026-08-29T10:49:33.023837+00:00, sha 350d6d259255)
  - site_page: https://azure.microsoft.com/en-us/pricing/details/defender-for-cloud?cdn=disable (fetched 2026-08-29T10:49:33.026503+00:00, sha 482304517b26)
  - site_page: https://azure.microsoft.com/en-us/pricing/details/defender-for-cloud (fetched 2026-08-29T10:49:33.030115+00:00, sha 2f141c868eb7)
  - site_page: https://azure.microsoft.com/en-us/pricing/purchase-options/azure-account (fetched 2026-08-29T10:49:33.032361+00:00, sha b824de7b59dc)
- Data as of 2026-08-30T08:39:29.467469+00:00.
