You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/sentinel/incident-investigation.md
+5-5Lines changed: 5 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -37,7 +37,7 @@ Microsoft Sentinel incidents give you tools to help your Security Operations (Se
37
37
-**SOC managers and engineers** can develop these task lists and have them automatically apply to different groups of incidents as appropriate, or across the board.
38
38
-**SOC analysts** can then access the assigned tasks within each incident, marking them off as they’re completed.
39
39
40
-
Analysts can also manually add tasks to their open incidents, either as self-reminders or for the benefit of other analysts who may collaborate on the incident (for example, due to a shift change or escalation).
40
+
Analysts can also manually add tasks to their open incidents, either as self-reminders or for the benefit of other analysts who may collaborate on the incident (for example, due to a shift change or escalation).
41
41
42
42
For more information, see [Use tasks to manage incidents in Microsoft Sentinel in the Azure portal](incident-tasks.md).
43
43
@@ -108,7 +108,7 @@ Next, having the broad outlines of what happened (or is still happening), and ha
108
108
109
109
Microsoft Sentinel automatically asks the big questions about the entities in your incident and shows the top answers in the **Top insights** widget, visible on the right side of the incident details page. This widget shows a collection of insights based on both machine-learning analysis and the curation of top teams of security experts.
110
110
111
-
These are a specially selected subset of the insights that appear on [entity pages](entity-pages.md#entity-insights), but in this context, insights for all the entities in theincident are presented together, giving you a more complete picture of what's happening. The full set of insights appears on the **Entities tab**, for each entity separately&mdashsee below.
111
+
These are a specially selected subset of the insights that appear on [entity pages](entity-pages.md#entity-insights), but in this context, insights for all the entities in the incident are presented together, giving you a more complete picture of what's happening. The full set of insights appears on the **Entities tab**, for each entity separately—see below.
112
112
113
113
The **Top insights** widget answers questions about the entity relating to its behavior in comparison to its peers and its own history, its presence on watchlists or in threat intelligence, or any other sort of unusual occurrence relating to it.
114
114
@@ -130,7 +130,7 @@ Select an entity in the list to open a side panel with information based on the
130
130
131
131
-**Insights** contains answers to questions about the entity relating to its behavior in comparison to its peers and its own history, its presence on watchlists or in threat intelligence, or any other sort of unusual occurrence relating to it.
132
132
133
-
These answers are the results of queries defined by Microsoft security researchers that provide valuable and contextual security information on entities, based on data from a collection of sources.
133
+
These answers are the results of queries defined by Microsoft security researchers that provide valuable and contextual security information on entities, based on data from a collection of sources.
134
134
135
135
Depending on the entity type, you can take a number of further actions from this side panel, including:
136
136
@@ -153,7 +153,7 @@ Depending on the entity type, you can take a number of further actions from this
153
153
|**Azure resource**|✔|||
154
154
|**IoT device**|✔|||
155
155
156
-
\* For entities for which the **Add to TI** or **Run playbook** actions are available, you can take those actions right from the **Entities** widget in the **Overview tab**, neverleaving the incident page.
156
+
\* For entities for which the **Add to TI** or **Run playbook** actions are available, you can take those actions right from the **Entities** widget in the **Overview tab**, never leaving the incident page.
157
157
158
158
### Incident logs
159
159
@@ -165,7 +165,7 @@ These results are displayed in the Logs (log analytics) screen that appears here
165
165
166
166
## Organized records with incidents
167
167
168
-
In the interests of transparency, accountability, and continuity, you’ll want a record of all the actions that have been taken on the incident – whether by automated processes or by people. The incident **activity log** shows you all of these activities. You can also see any comments that have been made and add your own.
168
+
In the interests of transparency, accountability, and continuity, you’ll want a record of all the actions that have been taken on the incident—whether by automated processes or by people. The incident **activity log** shows you all of these activities. You can also see any comments that have been made and add your own.
169
169
170
170
The activity log is constantly auto-refreshing, even while open, so you can see changes to it in real time.
Copy file name to clipboardExpand all lines: articles/sentinel/investigate-incidents.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -84,7 +84,7 @@ The **Overview** tab contains the following widgets, each of which represents an
84
84
85
85
The **Entities** tab shows you the complete list of entities in the incident, which are also shown in the **Entities** widget on the **Overview** page. When you select an entity in the widget, you're directed here to see the entity's full dossier—its identifying information, a timeline of its activity (both within and outside the incident), and the full set of insights about the entity, just as you would see in its full entity page, but limited to the time frame appropriate to the incident.
86
86
87
-
## Reconstruct the timeline of attacker activity
87
+
## Reconstruct the timeline of the attack story
88
88
89
89
The **Incident timeline** widget shows you the timeline of alerts and [bookmarks](bookmarks.md) in the incident, which can help you reconstruct the timeline of attacker activity.
0 commit comments