Skip to content

Commit 2a0db77

Browse files
committed
final fixes
1 parent 0db74ea commit 2a0db77

File tree

1 file changed

+9
-9
lines changed

1 file changed

+9
-9
lines changed

articles/defender-for-cloud/managing-and-responding-alerts.md

Lines changed: 9 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ When triaging security alerts, you should prioritize alerts based on their alert
2323

2424
1. Navigate to **Microsoft Defender for Cloud** > **Security alerts**.
2525

26-
:::image type="content" source="media/managing-and-responding-alerts/overview-page-alerts-links.png" alt-text="Screenshot that shows how the security alerts page from Microsoft Defender for Cloud's overview page looks.":::
26+
:::image type="content" source="media/managing-and-responding-alerts/overview-page-alerts-links.png" alt-text="Screenshot that shows the security alerts page from Microsoft Defender for Cloud's overview page.":::
2727

2828
1. (Optional) Filter the alerts list with any of the relevant filters. You can add extra filters with the **Add filter** option.
2929

@@ -48,7 +48,7 @@ Each alert contains information regarding the alert that assists you in your inv
4848
- Affected resources
4949
- Kill chain intent of the activity on the MITRE ATT&CK matrix (if applicable)
5050

51-
1. For more detailed information that can help you investigate the suspicious activity, select **View full details**.
51+
1. Select **View full details**.
5252

5353
The right pane includes the **Alert details** tab containing further details of the alert to help you investigate the issue: IP addresses, files, processes, and more.
5454

@@ -61,9 +61,9 @@ Each alert contains information regarding the alert that assists you in your inv
6161
- *Trigger automated response* - provides the option to trigger a logic app as a response to this security alert
6262
- *Suppress similar alerts* - provides the option to suppress future alerts with similar characteristics if the alert isn’t relevant for your organization
6363

64-
:::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Take action tab.":::
64+
:::image type="content" source="./media/managing-and-responding-alerts/alert-take-action.png" alt-text="Screenshot that shows the options available in the Take action tab.":::
6565

66-
For further details contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
66+
For further details, contact the resource owner to verify whether the detected activity is a false positive. You can also, investigate the raw logs generated by the attacked resource.
6767

6868
## Change the status of multiple security alerts at once
6969

@@ -73,7 +73,7 @@ The alerts list includes checkboxes so you can handle multiple alerts at once. F
7373

7474
In this example, the alerts with severity of `Informational` for the resource `ASC-AKS-CLOUD-TALK` are selected.
7575

76-
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-filter.png" alt-text="Screenshot of filtering the alerts to show related alerts.":::
76+
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-filter.png" alt-text="Screenshot that shows how to filter alerts to show related alerts.":::
7777

7878
1. Use the checkboxes to select the alerts to be processed.
7979

@@ -83,7 +83,7 @@ The alerts list includes checkboxes so you can handle multiple alerts at once. F
8383

8484
1. Use the **Change status** options to set the desired status.
8585

86-
:::image type="icon" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" border="false":::
86+
:::image type="content" source="media/managing-and-responding-alerts/processing-alerts-bulk-change-status.png" alt-text="Screenshot of the security alerts take action tab.":::
8787

8888
The alerts shown in the current page have their status changed to the selected value.
8989

@@ -95,7 +95,7 @@ After investigating a security alert, you can respond to the alert from within M
9595

9696
1. Open the **Take action** tab to see the recommended responses.
9797

98-
:::image type="content" source="./media/managing-and-responding-alerts/alert-details-take-action.png" alt-text="Security alerts take action tab." lightbox="./media/managing-and-responding-alerts/alert-details-take-action.png":::
98+
:::image type="content" source="./media/managing-and-responding-alerts/alert-details-take-action.png" alt-text="Screenshot of the security alerts take action tab." lightbox="./media/managing-and-responding-alerts/alert-details-take-action.png":::
9999

100100
1. Review the **Mitigate the threat** section for the manual investigation steps necessary to mitigate the issue.
101101

@@ -109,15 +109,15 @@ After investigating a security alert, you can respond to the alert from within M
109109

110110
1. When you complete the investigation into the alert and responded in the appropriate way, change the status to **Dismissed**.
111111

112-
:::image type="content" source="./media/managing-and-responding-alerts/set-status-dismissed.png" alt-text="Setting an alert's status":::
112+
:::image type="content" source="./media/managing-and-responding-alerts/set-status-dismissed.png" alt-text="Screenshot of the alert's status drop down menu":::
113113

114114
The alert is removed from the main alerts list. You can use the filter from the alerts list page to view all alerts with **Dismissed** status.
115115

116116
1. We encourage you to provide feedback about the alert to Microsoft:
117117
1. Marking the alert as **Useful** or **Not useful**.
118118
1. Select a reason and add a comment.
119119

120-
:::image type="content" source="./media/managing-and-responding-alerts/alert-feedback.png" alt-text="Provide feedback to Microsoft on the usefulness of an alert.":::
120+
:::image type="content" source="./media/managing-and-responding-alerts/alert-feedback.png" alt-text="Screenshot of the provide feedback to Microsoft window which allows you to select the usefulness of an alert.":::
121121

122122
> [!TIP]
123123
> We review your feedback to improve our algorithms and provide better security alerts.

0 commit comments

Comments
 (0)