Skip to content

Commit 27e2d3d

Browse files
committed
fine tuning
1 parent 766d2d1 commit 27e2d3d

File tree

2 files changed

+6
-1
lines changed

2 files changed

+6
-1
lines changed
897 KB
Loading

articles/sentinel/mitre-coverage.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,9 @@ By default, both currently active scheduled query and near real-time (NRT) rules
5656

5757
:::image type="content" source="media/mitre-coverage/mitre-coverage-defender.png" alt-text="Screenshot of the MITRE ATT&CK page in the Defender portal." lightbox="media/mitre-coverage/mitre-coverage-defender.png":::
5858

59-
To filter the page by a specific threat scenario, toggle the **View MITRE by threat scenario** option on, and then select a threat scenario from the drop down. The page is updated accordingly.
59+
To filter the page by a specific threat scenario, toggle the **View MITRE by threat scenario** option on, and then select a threat scenario from the drop down. The page is updated accordingly. For example:
60+
61+
:::image type="content" source="media/mitre-coverage/mitre-by-threat-scenario.png" alt-text="Screenshot of the MITRE ATT&CK page filtered by a specific threat scenario.":::
6062

6163
---
6264

@@ -74,6 +76,9 @@ By default, both currently active scheduled query and near real-time (NRT) rules
7476

7577
For example, select **Hunting queries** to jump to the **Hunting** page. There, you see a filtered list of the hunting queries that are associated with the selected technique, and available for you to configure in your workspace.
7678

79+
On the Defender portal, the details pane also shows recommended coverage details, including the ratio of active detections and security services (products) out of all recommended detections and services for the selected technique.
80+
81+
7782
## Simulate possible coverage with available detections
7883

7984
In the MITRE coverage matrix, *simulated* coverage refers to detections that are available, but not currently configured in your Microsoft Sentinel workspace. View your simulated coverage to understand your organization's possible security status, were you to configure all detections available to you.

0 commit comments

Comments
 (0)