You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/managing-and-responding-alerts.md
+9-9Lines changed: 9 additions & 9 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -23,7 +23,7 @@ When triaging security alerts, you should prioritize alerts based on their alert
23
23
24
24
1. Navigate to **Microsoft Defender for Cloud** > **Security alerts**.
25
25
26
-
:::image type="content" source="media/managing-and-responding-alerts/overview-page-alerts-links.png" alt-text="Screenshot that shows how the security alerts page from Microsoft Defender for Cloud's overview page looks.":::
26
+
:::image type="content" source="media/managing-and-responding-alerts/overview-page-alerts-links.png" alt-text="Screenshot that shows the security alerts page from Microsoft Defender for Cloud's overview page.":::
27
27
28
28
1. (Optional) Filter the alerts list with any of the relevant filters. You can add extra filters with the **Add filter** option.
29
29
@@ -48,7 +48,7 @@ Each alert contains information regarding the alert that assists you in your inv
48
48
- Affected resources
49
49
- Kill chain intent of the activity on the MITRE ATT&CK matrix (if applicable)
50
50
51
-
1.For more detailed information that can help you investigate the suspicious activity, select**View full details**.
51
+
1.Select**View full details**.
52
52
53
53
The right pane includes the **Alert details** tab containing further details of the alert to help you investigate the issue: IP addresses, files, processes, and more.
54
54
@@ -61,9 +61,9 @@ Each alert contains information regarding the alert that assists you in your inv
61
61
-*Trigger automated response* - provides the option to trigger a logic app as a response to this security alert
62
62
-*Suppress similar alerts* - provides the option to suppress future alerts with similar characteristics if the alert isn’t relevant for your organization
:::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Screenshot that shows the options available in the Take action tab.":::
65
65
66
-
For further details contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
66
+
For further details, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
67
67
68
68
## Change the status of multiple security alerts at once
69
69
@@ -73,7 +73,7 @@ The alerts list includes checkboxes so you can handle multiple alerts at once. F
73
73
74
74
In this example, the alerts with severity of `Informational` for the resource `ASC-AKS-CLOUD-TALK` are selected.
75
75
76
-
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-filter.png" alt-text="Screenshot of filtering the alerts to show related alerts.":::
76
+
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-filter.png" alt-text="Screenshot that shows how to filter alerts to show related alerts.":::
77
77
78
78
1. Use the checkboxes to select the alerts to be processed.
79
79
@@ -83,7 +83,7 @@ The alerts list includes checkboxes so you can handle multiple alerts at once. F
83
83
84
84
1. Use the **Change status** options to set the desired status.
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" alt-text="Screenshot of the security alerts take action tab.":::
87
87
88
88
The alerts shown in the current page have their status changed to the selected value.
89
89
@@ -95,7 +95,7 @@ After investigating a security alert, you can respond to the alert from within M
95
95
96
96
1. Open the **Take action** tab to see the recommended responses.
97
97
98
-
:::image type="content" source="./media/managing-and-responding-alerts/alert-details-take-action.png" alt-text="Security alerts take action tab." lightbox="./media/managing-and-responding-alerts/alert-details-take-action.png":::
98
+
:::image type="content" source="./media/managing-and-responding-alerts/alert-details-take-action.png" alt-text="Screenshot of the security alerts take action tab." lightbox="./media/managing-and-responding-alerts/alert-details-take-action.png":::
99
99
100
100
1. Review the **Mitigate the threat** section for the manual investigation steps necessary to mitigate the issue.
101
101
@@ -109,15 +109,15 @@ After investigating a security alert, you can respond to the alert from within M
109
109
110
110
1. When you complete the investigation into the alert and responded in the appropriate way, change the status to **Dismissed**.
111
111
112
-
:::image type="content" source="./media/managing-and-responding-alerts/set-status-dismissed.png" alt-text="Setting an alert's status":::
112
+
:::image type="content" source="./media/managing-and-responding-alerts/set-status-dismissed.png" alt-text="Screenshot of the alert's status drop down menu":::
113
113
114
114
The alert is removed from the main alerts list. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
115
115
116
116
1. We encourage you to provide feedback about the alert to Microsoft:
117
117
1. Marking the alert as **Useful** or **Not useful**.
118
118
1. Select a reason and add a comment.
119
119
120
-
:::image type="content" source="./media/managing-and-responding-alerts/alert-feedback.png" alt-text="Provide feedback to Microsoft on the usefulness of an alert.":::
120
+
:::image type="content" source="./media/managing-and-responding-alerts/alert-feedback.png" alt-text="Screenshot of the provide feedback to Microsoft window which allows you to select the usefulness of an alert.":::
121
121
122
122
> [!TIP]
123
123
> We review your feedback to improve our algorithms and provide better security alerts.
0 commit comments