You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/tutorial-security-incident.md
+9-6Lines changed: 9 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,14 +4,14 @@ description: In this tutorial, you'll learn how to triage security alerts and de
4
4
ms.assetid: 181e3695-cbb8-4b4e-96e9-c4396754862f
5
5
ms.topic: tutorial
6
6
ms.custom: ignite-2022
7
-
ms.date: 11/09/2021
7
+
ms.date: 01/08/2023
8
8
---
9
9
10
10
# Tutorial: Triage, investigate, and respond to security alerts
11
11
12
12
Microsoft Defender for Cloud continuously analyzes your hybrid cloud workloads using advanced analytics and threat intelligence to alert you about potentially malicious activities in your cloud resources. You can also integrate alerts from other security products and services into Defender for Cloud. Once an alert is raised, swift action is needed to investigate and remediate the potential security issue.
13
13
14
-
In this tutorial, you will learn how to:
14
+
In this tutorial, you'll learn how to:
15
15
16
16
> [!div class="checklist"]
17
17
> * Triage security alerts
@@ -21,7 +21,9 @@ In this tutorial, you will learn how to:
21
21
If you don't have an Azure subscription, create a [free account](https://azure.microsoft.com/free/) before you begin.
22
22
23
23
## Prerequisites
24
-
To step through the features covered in this tutorial, you must have Defender for Cloud's enhanced security features enabled. You can try these at no cost. To learn more, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/). The quickstart [Get started with Defender for Cloud](get-started.md) walks you through how to upgrade.
24
+
To step through the features covered in this tutorial, you must have Defender for Cloud's enhanced security features enabled. To learn more about Defender for Cloud's pricing, see the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/).
25
+
26
+
The quickstart, [Get started with Defender for Cloud](get-started.md) walks you through the upgrade process.
25
27
26
28
27
29
## Triage security alerts
@@ -78,7 +80,7 @@ After you've investigated a security alert and understood its scope, you can res
78
80
79
81
:::image type="content" source="./media/tutorial-security-incident/set-status-dismissed.png" alt-text="Setting an alert's status":::
80
82
81
-
This removes the alert from the main alerts list. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
83
+
The alert is then removed from the main list of alerts. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
82
84
83
85
1. We encourage you to provide feedback about the alert to Microsoft:
84
86
1. Marking the alert as **Useful** or **Not useful**.
@@ -89,7 +91,7 @@ After you've investigated a security alert and understood its scope, you can res
89
91
> [!TIP]
90
92
> We review your feedback to improve our algorithms and provide better security alerts.
91
93
92
-
## End the tutorial
94
+
## CLean up resources
93
95
94
96
Other quickstarts and tutorials in this collection build upon this quickstart. If you plan to continue to work with subsequent quickstarts and tutorials, keep automatic provisioning and Defender for Cloud's enhanced security features enabled.
95
97
@@ -115,7 +117,8 @@ If you don't plan to continue, or you want to disable either of these features:
115
117
> Disabling extensions does not remove the Log Analytics agent from Azure VMs that already have the agent, but does limits security monitoring for your resources.
116
118
117
119
## Next steps
118
-
In this tutorial, you learned about Defender for Cloud features to be used when responding to a security alert. For related material see:
120
+
121
+
In this tutorial, you learned about Defender for Cloud features to be used when responding to a security alert. For related material, see:
119
122
120
123
-[Respond to Microsoft Defender for Key Vault alerts](defender-for-key-vault-usage.md)
121
124
-[Security alerts - a reference guide](alerts-reference.md)
0 commit comments