Skip to content

Commit 285dfe2

Browse files
author
David Curwin
committed
UI changes
1 parent d696832 commit 285dfe2

9 files changed

+11
-21
lines changed

articles/defender-for-cloud/disable-vulnerability-findings-containers.md

Lines changed: 1 addition & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -36,8 +36,7 @@ Disable rules apply per recommendation, for example, to disable [CVE-2017-17512]
3636
3737
To create a rule:
3838

39-
1. From the recommendations detail page for [Container registry images should have vulnerability findings resolved powered by Microsoft Defender Vulnerability Management](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9) or [Running container images should have vulnerability findings resolved powered by Microsoft Defender Vulnerability Management
40-
](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/e9acaf48-d2cf-45a3-a6e7-3caa2ef769e0), select **Disable rule**.
39+
1. From the recommendations detail page for [Container registry images should have vulnerability findings resolved powered by Microsoft Defender Vulnerability Management](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9) or [Containers running in Azure should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/e9acaf48-d2cf-45a3-a6e7-3caa2ef769e0), select **Disable rule**.
4140

4241
1. Select the relevant scope.
4342

Loading
47.5 KB
Loading
-6.37 KB
Loading
Loading
-9.38 KB
Loading
Loading

articles/defender-for-cloud/view-and-remediate-vulnerabilities-for-images.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ If you are using Defender CSPM, first review and remediate vulnerabilities expos
2727

2828
**To view vulnerabilities for a specific cluster, do the following:**
2929

30-
1. Open the **Recommendations** page, using the **>** arrow to open the sub-levels. If issues were found, you'll see the recommendation [Containers running in Azure should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/e9acaf48-d2cf-45a3-a6e7-3caa2ef769e0). Select the recommendation.
30+
1. In Defender for Cloud, open the **Recommendations** page. If issues were found, you'll see the recommendation [Containers running in Azure should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/e9acaf48-d2cf-45a3-a6e7-3caa2ef769e0). Select the recommendation.
3131

3232
:::image type="content" source="media/view-and-remediate-vulnerabilities-for-images-running-on-aks/running-image-recommendation-line.png" alt-text="Screenshot showing the recommendation line for running container images should have vulnerability findings resolved." lightbox="media/view-and-remediate-vulnerabilities-for-images-running-on-aks/running-image-recommendation-line.png":::
3333

@@ -71,7 +71,6 @@ Use these steps to remediate each of the affected images found either in a speci
7171
1. Check the recommendations page for the recommendation [Running container images should have vulnerability findings resolved](https://portal.azure.com/#view/Microsoft_Azure_Security_CloudNativeCompute/KubernetesRuntimeVisibilityRecommendationDetailsBlade/assessmentKey/41503391-efa5-47ee-9282-4eff6131462c).
7272
1. If the recommendation still appears and the image you've handled still appears in the list of vulnerable images, check the remediation steps again.
7373

74-
## Next steps
74+
## Next step
7575

7676
- Learn how to [view and remediate vulnerabilities for registry images](view-and-remediate-vulnerability-assessment-findings.md).
77-
- Learn more about the Defender for Cloud [Defender plans](defender-for-cloud-introduction.md#protect-cloud-workloads)

articles/defender-for-cloud/view-and-remediate-vulnerability-assessment-findings.md

Lines changed: 8 additions & 16 deletions
Original file line numberDiff line numberDiff line change
@@ -20,11 +20,11 @@ If you are using Defender CSPM, first review and remediate vulnerabilities expos
2020

2121
## View vulnerabilities on a specific container registry
2222

23-
1. Open the **Recommendations** page, using the **>** arrow to open the sublevels. If issues were found, you'll see the recommendation [Container images in Azure registry should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9). Select the recommendation.
23+
1. In Defender for Cloud, open the **Recommendations** page. If issues were found, you'll see the recommendation [Container images in Azure registry should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9). Select the recommendation.
2424

2525
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/open-recommendations-page.png" alt-text="Screenshot showing the line for recommendation container registry images should have vulnerability findings resolved." lightbox="media/view-and-remediate-vulnerability-assessment-findings/open-recommendations-page.png":::
2626

27-
1. The recommendation details page opens with additional information. This information includes the list of registries with vulnerable images ("affected resources") and the remediation steps. Select the affected registry.
27+
1. The recommendation details page opens with additional information. This information includes the list of registries with vulnerable images ("Resource") and the remediation steps. Select the affected registry.
2828

2929
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/select-registry.png" alt-text="Screenshot showing the recommendation details and affected registries." lightbox="media/view-and-remediate-vulnerability-assessment-findings/select-registry.png":::
3030

@@ -44,32 +44,24 @@ If you are using Defender CSPM, first review and remediate vulnerabilities expos
4444

4545
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/image-details.png" alt-text="Screenshot showing the details of the finding on the specific image." lightbox="media/view-and-remediate-vulnerability-assessment-findings/image-details.png":::
4646

47+
You can also group recommendations by title. This is useful when you want to remediate a recommendation that is affecting multiple resources caused by a specific security issue. For more information, see [Group recommendations by title](review-security-recommendations.md#group-recommendations-by-title).
48+
4749
## View images affected by a specific vulnerability
4850

4951
1. Open the **Recommendations** page. If issues were found, you'll see the recommendation [Container images in Azure registry should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9). Select the recommendation.
5052

5153
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/open-recommendations-page.png" alt-text="Screenshot showing the line for recommendation container registry images should have vulnerability findings resolved." lightbox="media/view-and-remediate-vulnerability-assessment-findings/open-recommendations-page.png":::
5254

53-
1. The recommendation details page opens with additional information. This information includes the list of vulnerabilities impacting the images. Select the specific vulnerability.
55+
1. The recommendation details page opens with additional information. Select the **Findings** tab to see the list of vulnerabilities impacting the images. Select a specific vulnerability.
5456

5557
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/select-specific-vulnerability.png" alt-text="Screenshot showing the list of vulnerabilities impacting the images." lightbox="media/view-and-remediate-vulnerability-assessment-findings/select-specific-vulnerability.png":::
5658

57-
1. The vulnerability finding details pane opens. This pane includes a detailed description of the vulnerability, images affected by that vulnerability, and links to external resources to help mitigate the threats, affected resources, and information on the software version that contributes to [resolving the vulnerability](#remediate-vulnerabilities).
59+
1. The vulnerability finding details pane opens. This pane includes a detailed description of the vulnerability, images affected by that vulnerability, and links to external resources to help mitigate the threats, affected resources, and information on the software version that contributes to resolving the vulnerability.
5860

5961
:::image type="content" source="media/view-and-remediate-vulnerability-assessment-findings/specific-vulnerability-details.png" alt-text="Screenshot showing the list of images impacted by the vulnerability." lightbox="media/view-and-remediate-vulnerability-assessment-findings/specific-vulnerability-details.png":::
6062

61-
## Remediate vulnerabilities
62-
63-
Use these steps to remediate each of the affected images found either in a specific cluster or for a specific vulnerability:
64-
65-
1. Follow the steps in the remediation section of the recommendation pane.
66-
1. When you've completed the steps required to remediate the security issue, replace each affected image in your registry or replace each affected image for a specific vulnerability:
67-
1. Build a new image (including updates for each of the packages) that resolves the vulnerability according to the remediation details.
68-
1. Push the updated image to trigger a scan and delete the old image. It might take up to 24 hours for the previous image to be removed from the results, and for the new image to be included in the results.
69-
70-
1. Check the recommendations page for the recommendation [Container images in Azure registry should have vulnerability findings resolved](https://portal.azure.com/#blade/Microsoft_Azure_Security/RecommendationsBlade/assessmentKey/33422d8f-ab1e-42be-bc9a-38685bb567b9).
71-
If the recommendation still appears and the image you've handled still appears in the list of vulnerable images, check the remediation steps again.
63+
For information on how to remediate the vulnerabilities, see [Remediate recommendations](implement-security-recommendations.md).
7264

73-
## Next step
65+
## Next steps
7466

7567
- Learn how to [view and remediate vulnerabilities for images running on Kubernetes clusters](view-and-remediate-vulnerabilities-for-images.md).

0 commit comments

Comments
 (0)