Skip to content

Commit d47113f

Browse files
batamigyelevin
andauthored
Apply suggestions from code review
Co-authored-by: Yechiel Levin <[email protected]>
1 parent ddbc51c commit d47113f

File tree

2 files changed

+6
-6
lines changed

2 files changed

+6
-6
lines changed

articles/sentinel/incident-investigation.md

Lines changed: 5 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -37,7 +37,7 @@ Microsoft Sentinel incidents give you tools to help your Security Operations (Se
3737
- **SOC managers and engineers** can develop these task lists and have them automatically apply to different groups of incidents as appropriate, or across the board.
3838
- **SOC analysts** can then access the assigned tasks within each incident, marking them off as they’re completed.
3939

40-
Analysts can also manually add tasks to their open incidents, either as self-reminders or for the benefit of other analysts who may collaborate on the incident (for example, due to a shift change or escalation).
40+
Analysts can also manually add tasks to their open incidents, either as self-reminders or for the benefit of other analysts who may collaborate on the incident (for example, due to a shift change or escalation).
4141

4242
For more information, see [Use tasks to manage incidents in Microsoft Sentinel in the Azure portal](incident-tasks.md).
4343

@@ -108,7 +108,7 @@ Next, having the broad outlines of what happened (or is still happening), and ha
108108

109109
Microsoft Sentinel automatically asks the big questions about the entities in your incident and shows the top answers in the **Top insights** widget, visible on the right side of the incident details page. This widget shows a collection of insights based on both machine-learning analysis and the curation of top teams of security experts.
110110

111-
These are a specially selected subset of the insights that appear on [entity pages](entity-pages.md#entity-insights), but in this context, insights for all the entities in theincident are presented together, giving you a more complete picture of what's happening. The full set of insights appears on the **Entities tab**, for each entity separately&mdashsee below.
111+
These are a specially selected subset of the insights that appear on [entity pages](entity-pages.md#entity-insights), but in this context, insights for all the entities in the incident are presented together, giving you a more complete picture of what's happening. The full set of insights appears on the **Entities tab**, for each entity separately&mdash;see below.
112112

113113
The **Top insights** widget answers questions about the entity relating to its behavior in comparison to its peers and its own history, its presence on watchlists or in threat intelligence, or any other sort of unusual occurrence relating to it.
114114

@@ -130,7 +130,7 @@ Select an entity in the list to open a side panel with information based on the
130130

131131
- **Insights** contains answers to questions about the entity relating to its behavior in comparison to its peers and its own history, its presence on watchlists or in threat intelligence, or any other sort of unusual occurrence relating to it.
132132

133-
These answers are the results of queries defined by Microsoft security researchers that provide valuable and contextual security information on entities, based on data from a collection of sources.
133+
These answers are the results of queries defined by Microsoft security researchers that provide valuable and contextual security information on entities, based on data from a collection of sources.
134134

135135
Depending on the entity type, you can take a number of further actions from this side panel, including:
136136

@@ -153,7 +153,7 @@ Depending on the entity type, you can take a number of further actions from this
153153
| **Azure resource** | &#10004; | | |
154154
| **IoT device** | &#10004; | | |
155155

156-
\* For entities for which the **Add to TI** or **Run playbook** actions are available, you can take those actions right from the **Entities** widget in the **Overview tab**, neverleaving the incident page.
156+
\* For entities for which the **Add to TI** or **Run playbook** actions are available, you can take those actions right from the **Entities** widget in the **Overview tab**, never leaving the incident page.
157157

158158
### Incident logs
159159

@@ -165,7 +165,7 @@ These results are displayed in the Logs (log analytics) screen that appears here
165165

166166
## Organized records with incidents
167167

168-
In the interests of transparency, accountability, and continuity, you’ll want a record of all the actions that have been taken on the incidentwhether by automated processes or by people. The incident **activity log** shows you all of these activities. You can also see any comments that have been made and add your own.
168+
In the interests of transparency, accountability, and continuity, you’ll want a record of all the actions that have been taken on the incident&mdash;whether by automated processes or by people. The incident **activity log** shows you all of these activities. You can also see any comments that have been made and add your own.
169169

170170
The activity log is constantly auto-refreshing, even while open, so you can see changes to it in real time.
171171

articles/sentinel/investigate-incidents.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,7 @@ The **Overview** tab contains the following widgets, each of which represents an
8484

8585
The **Entities** tab shows you the complete list of entities in the incident, which are also shown in the **Entities** widget on the **Overview** page. When you select an entity in the widget, you're directed here to see the entity's full dossier&mdash;its identifying information, a timeline of its activity (both within and outside the incident), and the full set of insights about the entity, just as you would see in its full entity page, but limited to the time frame appropriate to the incident.
8686

87-
## Reconstruct the timeline of attacker activity
87+
## Reconstruct the timeline of the attack story
8888

8989
The **Incident timeline** widget shows you the timeline of alerts and [bookmarks](bookmarks.md) in the incident, which can help you reconstruct the timeline of attacker activity.
9090

0 commit comments

Comments
 (0)