Additional Microsoft Defender tools and services that provide security across various platforms and environments
Defender XDR alert tuning currently supports conditions where values “aren't case sensitive, and some properties support wildcards.” This allows matching patterns like substrings or simple wildcard expressions, but there is no documented support for explicit startswith or endswith comparators in alert tuning rules.
For scenarios like filtering .deb packages (for example, *.amd64.deb), the recommended approach is to use the existing wildcard capability on the relevant evidence property (for example, file name or path) in the Conditions area of the Tune alert pane. Conditions can be combined with AND/OR and grouping to refine matching logic.
To request startswith/endswith operators as a product enhancement, the appropriate path is to submit feedback through the Microsoft Defender portal (Feedback or Help → Give feedback) or via the usual Microsoft support and feedback channels used by the organization. This ensures the feature request is tracked by the Defender product team.
References: