Skip to content

Commit e7bce7e

Browse files
authored
Update articles/sentinel/incident-investigation.md
PR review: Corrected Acrolinx issue
1 parent 2158c28 commit e7bce7e

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

articles/sentinel/incident-investigation.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,7 +14,7 @@ appliesto:
1414

1515
Microsoft Sentinel gives you a complete, full-featured case management platform for investigating and managing security incidents. **Incidents** are Microsoft Sentinel’s name for files that contain a complete and constantly updated chronology of a security threat, whether it’s individual pieces of evidence (alerts), suspects and parties of interest (entities), insights collected and curated by security experts and AI/machine learning models, or comments and logs of all the actions taken in the course of the investigation.
1616

17-
The incident investigation experience in Microsoft Sentinel begins with the **Incidents** page—a experience designed to give you everything you need for your investigation in one place. The key goal of this experience is to increase your SOC’s efficiency and effectiveness, reducing its mean time to resolve (MTTR).
17+
The incident investigation experience in Microsoft Sentinel begins with the **Incidents** page—an experience designed to give you everything you need for your investigation in one place. The key goal of this experience is to increase your SOC’s efficiency and effectiveness, reducing its mean time to resolve (MTTR).
1818

1919
This article describes Microsoft Sentinel's incident investigation and case management capabilities and features in the Azure portal, taking you through the phases of a typical incident investigation while presenting all the displays and tools available to you to help you along.
2020

0 commit comments

Comments
 (0)