Skip to content

Commit c1c3d0b

Browse files
committed
wi195539 xdr mdc rn
1 parent ab06782 commit c1c3d0b

File tree

7 files changed

+111
-95
lines changed

7 files changed

+111
-95
lines changed

articles/defender-for-cloud/concept-integration-365.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
---
2-
title: Alerts and incidents in Microsoft Defender XDR (Preview)
2+
title: Alerts and incidents in Microsoft Defender XDR
33
description: Learn about the benefits of receiving Microsoft Defender for Cloud's alerts in Microsoft Defender XDR
44
ms.topic: conceptual
5-
ms.date: 11/29/2023
5+
ms.date: 01/03/2024
66
---
77

8-
# Alerts and incidents in Microsoft Defender XDR (Preview)
8+
# Alerts and incidents in Microsoft Defender XDR
99

10-
Microsoft Defender for Cloud is now integrated with Microsoft Defender XDR (Preview). This integration allows security teams to access Defender for Cloud alerts and incidents within the Microsoft Defender Portal. This integration provides richer context to investigations that span cloud resources, devices, and identities.
10+
Microsoft Defender for Cloud is now integrated with Microsoft Defender XDR. This integration allows security teams to access Defender for Cloud alerts and incidents within the Microsoft Defender Portal. This integration provides richer context to investigations that span cloud resources, devices, and identities.
1111

1212
The partnership with Microsoft Defender XDR allows security teams to get the complete picture of an attack, including suspicious and malicious events that happen in their cloud environment. Security teams can accomplish this goal through immediate correlations of alerts and incidents.
1313

articles/defender-for-cloud/connect-azure-subscription.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect your Azure subscriptions
33
description: Learn how to connect your Azure subscriptions to Microsoft Defender for Cloud
44
ms.topic: install-set-up-deploy
5-
ms.date: 11/23/2023
5+
ms.date: 01/03/2024
66
ms.custom: mode-other
77
---
88

@@ -95,7 +95,7 @@ If you want to disable any of the plans, toggle the individual plan to **off**.
9595
> [!TIP]
9696
> To enable Defender for Cloud on all subscriptions within a management group, see [Enable Defender for Cloud on multiple Azure subscriptions](onboard-management-group.md).
9797
98-
## Integrate with Microsoft Defender XDR (Preview)
98+
## Integrate with Microsoft Defender XDR
9999

100100
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft Defender Portal. No further steps are needed.
101101

articles/defender-for-cloud/quickstart-onboard-aws.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ title: Connect your AWS account
33
description: Defend your AWS resources by using Microsoft Defender for Cloud.
44
ms.topic: install-set-up-deploy
55
ms.custom: devx-track-linux
6-
ms.date: 11/23/2023
6+
ms.date: 01/03/2024
77
---
88

99
# Connect your AWS account to Microsoft Defender for Cloud
@@ -276,7 +276,7 @@ To view all the active recommendations for your resources by resource type, use
276276
277277
:::image type="content" source="./media/quickstart-onboard-aws/aws-resource-types-in-inventory.png" alt-text="Screenshot of AWS options in the asset inventory page's resource type filter." lightbox="media/quickstart-onboard-aws/aws-resource-types-in-inventory.png":::
278278
279-
## Integrate with Microsoft Defender XDR (Preview)
279+
## Integrate with Microsoft Defender XDR
280280
281281
When you enable Defender for Cloud, Defender for Cloud alerts are automatically integrated into the Microsoft Defender Portal. No further steps are needed.
282282

articles/defender-for-cloud/quickstart-onboard-gcp.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect your GCP project
33
description: Defend your GCP resources by using Microsoft Defender for Cloud.
44
ms.topic: install-set-up-deploy
5-
ms.date: 11/23/2023
5+
ms.date: 01/03/2024
66
---
77

88
# Connect your GCP project to Microsoft Defender for Cloud
@@ -234,7 +234,7 @@ To view all the active recommendations for your resources by resource type, use
234234

235235
:::image type="content" source="./media/quickstart-onboard-gcp/gcp-resource-types-in-inventory.png" alt-text="Screenshot of GCP options in the asset inventory page's resource type filter." lightbox="media/quickstart-onboard-gcp/gcp-resource-types-in-inventory.png":::
236236

237-
## Integrate with Microsoft Defender XDR (Preview)
237+
## Integrate with Microsoft Defender XDR
238238

239239
When you enable Defender for Cloud, Defender for Cloud alerts are automatically integrated into the Microsoft Defender Portal. No further steps are needed.
240240

articles/defender-for-cloud/quickstart-onboard-machines.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -2,7 +2,7 @@
22
title: Connect on-premises machines
33
description: Learn how to connect your non-Azure machines to Microsoft Defender for Cloud.
44
ms.topic: install-set-up-deploy
5-
ms.date: 11/23/2023
5+
ms.date: 01/03/2024
66
ms.custom: mode-other
77
---
88

@@ -147,7 +147,7 @@ To verify that your machines are connected:
147147

148148
![Defender for Cloud icon for an Azure Arc-enabled server.](./media/quickstart-onboard-machines/arc-enabled-machine-icon.png) Azure Arc-enabled server
149149

150-
## Integrate with Microsoft Defender XDR (Preview)
150+
## Integrate with Microsoft Defender XDR
151151

152152
When you enable Defender for Cloud, Defender for Cloud's alerts are automatically integrated into the Microsoft Defender Portal. No further steps are needed.
153153

articles/defender-for-cloud/release-notes-archive.md

Lines changed: 82 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: A description of what's new and changed in Microsoft Defender for C
44
author: dcurwin
55
ms.author: dacurwin
66
ms.topic: reference
7-
ms.date: 01/02/2024
7+
ms.date: 01/03/2024
88
---
99

1010
# Archive for what's new in Defender for Cloud?
@@ -17,6 +17,87 @@ This page provides you with information about:
1717
- Bug fixes
1818
- Deprecated functionality
1919

20+
## July 2023
21+
22+
Updates in July include:
23+
24+
|Date |Update |
25+
|----------|----------|
26+
| July 31 | [Preview release of containers Vulnerability Assessment powered by Microsoft Defender Vulnerability Management (MDVM) in Defender for Containers and Defender for Container Registries](#preview-release-of-containers-vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management-mdvm-in-defender-for-containers-and-defender-for-container-registries) |
27+
| July 30 | [Agentless container posture in Defender CSPM is now Generally Available](#agentless-container-posture-in-defender-cspm-is-now-generally-available) |
28+
| July 20 | [Management of automatic updates to Defender for Endpoint for Linux](#management-of-automatic-updates-to-defender-for-endpoint-for-linux) |
29+
| July 18 | [Agentless secrets scanning for virtual machines in Defender for servers P2 & Defender CSPM](#agentless-secrets-scanning-for-virtual-machines-in-defender-for-servers-p2--defender-cspm) |
30+
| July 12 | [New Security alert in Defender for Servers plan 2: Detecting Potential Attacks leveraging Azure VM GPU driver extensions](#new-security-alert-in-defender-for-servers-plan-2-detecting-potential-attacks-leveraging-azure-vm-gpu-driver-extensions) |
31+
| July 9 | [Support for disabling specific vulnerability findings](#support-for-disabling-specific-vulnerability-findings) |
32+
| July 1 | [Data Aware Security Posture is now Generally Available](#data-aware-security-posture-is-now-generally-available) |
33+
34+
### Preview release of containers Vulnerability Assessment powered by Microsoft Defender Vulnerability Management (MDVM) in Defender for Containers and Defender for Container Registries
35+
36+
July 31, 2023
37+
38+
We're announcing the release of Vulnerability Assessment (VA) for Linux container images in Azure container registries powered by Microsoft Defender Vulnerability Management (MDVM) in Defender for Containers and Defender for Container Registries. The new container VA offering will be provided alongside our existing Container VA offering powered by Qualys in both Defender for Containers and Defender for Container Registries, and include daily rescans of container images, exploitability information, support for OS and programming languages (SCA) and more.
39+
40+
This new offering will start rolling out today, and is expected to be available to all customers by August 7.
41+
42+
For more information, see [Container Vulnerability Assessment powered by MDVM](agentless-vulnerability-assessment-azure.md) and [Microsoft Defender Vulnerability Management (MDVM)](/microsoft-365/security/defender-vulnerability-management/defender-vulnerability-management).
43+
44+
### Agentless container posture in Defender CSPM is now Generally Available
45+
46+
July 30, 2023
47+
48+
Agentless container posture capabilities are now Generally Available (GA) as part of the Defender CSPM (Cloud Security Posture Management) plan.
49+
50+
Learn more about [agentless container posture in Defender CSPM](concept-agentless-containers.md).
51+
52+
### Management of automatic updates to Defender for Endpoint for Linux
53+
54+
July 20, 2023
55+
56+
By default, Defender for Cloud attempts to update your Defender for Endpoint for Linux agents onboarded with the `MDE.Linux` extension. With this release, you can manage this setting and opt-out from the default configuration to manage your update cycles manually.
57+
58+
Learn how to [manage automatic updates configuration for Linux](integration-defender-for-endpoint.md#manage-automatic-updates-configuration-for-linux).
59+
60+
### Agentless secrets scanning for virtual machines in Defender for servers P2 & Defender CSPM
61+
62+
July 18, 2023
63+
64+
Secrets scanning is now available as part of the agentless scanning in Defender for Servers P2 and Defender CSPM. This capability helps to detect unmanaged and insecure secrets saved on virtual machines in Azure or AWS resources that can be used to move laterally in the network. If secrets are detected, Defender for Cloud can help to prioritize and take actionable remediation steps to minimize the risk of lateral movement, all without affecting your machine's performance.
65+
66+
For more information about how to protect your secrets with secrets scanning, see [Manage secrets with agentless secrets scanning](secret-scanning.md).
67+
68+
### New security alert in Defender for Servers plan 2: detecting potential attacks leveraging Azure VM GPU driver extensions
69+
70+
July 12, 2023
71+
72+
This alert focuses on identifying suspicious activities leveraging Azure virtual machine **GPU driver extensions** and provides insights into attackers' attempts to compromise your virtual machines. The alert targets suspicious deployments of GPU driver extensions; such extensions are often abused by threat actors to utilize the full power of the GPU card and perform cryptojacking.
73+
74+
| Alert Display Name <br> (Alert Type) | Description | Severity | MITRE Tactic |
75+
|---------|---------|---------|---------|
76+
| Suspicious installation of GPU extension in your virtual machine (Preview) <br> (VM_GPUDriverExtensionUnusualExecution) | Suspicious installation of a GPU extension was detected in your virtual machine by analyzing the Azure Resource Manager operations in your subscription. Attackers might use the GPU driver extension to install GPU drivers on your virtual machine via the Azure Resource Manager to perform cryptojacking. | Low | Impact |
77+
78+
For a complete list of alerts, see the [reference table for all security alerts in Microsoft Defender for Cloud](alerts-reference.md).
79+
80+
### Support for disabling specific vulnerability findings
81+
82+
July 9, 2023
83+
84+
Release of support for disabling vulnerability findings for your container registry images or running images as part of agentless container posture. If you have an organizational need to ignore a vulnerability finding on your container registry image, rather than remediate it, you can optionally disable it. Disabled findings don't affect your secure score or generate unwanted noise.
85+
86+
Learn how to [disable vulnerability assessment findings on Container registry images](disable-vulnerability-findings-containers.md).
87+
88+
### Data Aware Security Posture is now Generally Available
89+
90+
July 1, 2023
91+
92+
Data-aware security posture in Microsoft Defender for Cloud is now Generally Available. It helps customers to reduce data risk, and respond to data breaches. Using data-aware security posture you can:
93+
94+
- Automatically discover sensitive data resources across Azure and AWS.
95+
- Evaluate data sensitivity, data exposure, and how data flows across the organization.
96+
- Proactively and continuously uncover risks that might lead to data breaches.
97+
- Detect suspicious activities that might indicate ongoing threats to sensitive data resources
98+
99+
For more information, see [Data-aware security posture in Microsoft Defender for Cloud](concept-data-security-posture.md).
100+
20101
## June 2023
21102

22103
Updates in June include:

0 commit comments

Comments
 (0)