Skip to content

Commit 07c6851

Browse files
committed
GA for go hunt and export to pdf
1 parent 3336bf6 commit 07c6851

File tree

3 files changed

+10
-9
lines changed

3 files changed

+10
-9
lines changed

defender-xdr/investigate-incidents.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -84,7 +84,9 @@ From the graph, you can:
8484

8585
- Hunt for entity information of a device, file, IP address, or URL.
8686

87-
The *go hunt* option takes advantage of the [advanced hunting](advanced-hunting-go-hunt.md) feature to find relevant information about an entity. The *go hunt* query checks relevant schema tables for any events or alerts involving the specific entity you're investigating. You can select any of the options to find relevant information about the entity:
87+
### Go hunt
88+
89+
The ***go hunt*** action takes advantage of the [advanced hunting](advanced-hunting-go-hunt.md) feature to find relevant information about an entity. The *go hunt* query checks relevant schema tables for any events or alerts involving the specific entity you're investigating. You can select any of the options to find relevant information about the entity:
8890

8991
- See all available queries – the option returns all available queries for the entity type you're investigating.
9092
- All Activity – the query returns all activities associated with an entity, providing you with a comprehensive view of the incident's context.
@@ -96,7 +98,7 @@ The resulting logs or alerts can be linked to an incident by selecting a results
9698

9799
:::image type="content" source="/defender/media/investigate-incidents/fig2-gohunt-attackstory.png" alt-text="Highlighting the link to incident option in go hunt query results" lightbox="/defender/media/investigate-incidents/fig2-gohunt-attackstory.png":::
98100

99-
If the incident or related alerts were the result of an analytics rule you've set, you can also select **Run query** to see other related results.
101+
If the incident or related alerts were the result of an analytics rule you've set, you can also select ***Run query*** to see other related results.
100102

101103
## Summary
102104

defender-xdr/manage-incidents.md

Lines changed: 1 addition & 6 deletions
Original file line numberDiff line numberDiff line change
@@ -18,7 +18,7 @@ ms.topic: conceptual
1818
search.appverid:
1919
- MOE150
2020
- MET150
21-
ms.date: 08/21/2024
21+
ms.date: 11/13/2024
2222
appliesto:
2323
- Microsoft Defender XDR
2424
- Microsoft Sentinel in the Microsoft Defender portal
@@ -147,11 +147,6 @@ You can also add your own comments using the comment box available within the ac
147147

148148
## Export incident data to PDF
149149

150-
> [!IMPORTANT]
151-
> Some information in this article relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
152-
>
153-
> The export incident data feature is currently available to Microsoft Defender XDR and Microsoft unified security operations center (SOC) platform customers with the Microsoft Copilot for security license.
154-
155150
You can export an incident's data to PDF through the **Export incident as PDF** function and save it into PDF format. This function allows security teams to review an incident's details offline at any given time.
156151

157152
The incident data exported includes the following information:

defender-xdr/whats-new.md

Lines changed: 5 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ ms.service: defender-xdr
66
ms.author: diannegali
77
author: diannegali
88
ms.localizationpriority: medium
9-
ms.date: 10/17/2024
9+
ms.date: 11/13/2024
1010
manager: dansimp
1111
audience: ITPro
1212
ms.collection:
@@ -29,6 +29,10 @@ For more information on what's new with other Microsoft Defender security produc
2929

3030
You can also get product updates and important notifications through the [message center](https://admin.microsoft.com/Adminportal/Home#/MessageCenter).
3131

32+
## November 2024
33+
34+
- (GA) Microsoft Defender XDR customers can now export incident data to PDF. Use the exported data to easily capture and share incident data to other stakeholders. For details, see **[Export incident data to PDF](manage-incidents.md#export-incident-data-to-pdf)**.
35+
- (GA) The [***go hunt***](investigate-incidents.md#go-hunt) action from the attack story graph and the **last update time** column in the [incident queue](incident-queue.md#incident-queue) are now generally available.
3236

3337
## October 2024
3438

0 commit comments

Comments
 (0)