Skip to content

Commit 12a1890

Browse files
committed
finishing draft
1 parent c9c40d8 commit 12a1890

File tree

1 file changed

+46
-8
lines changed

1 file changed

+46
-8
lines changed

unified-secops-platform/transition.md

Lines changed: 46 additions & 8 deletions
Original file line numberDiff line numberDiff line change
@@ -70,15 +70,15 @@ The following content is relevant for security engineers on a SecOps team that's
7070
- [Microsoft Sentinel data connectors](/azure/sentinel/connect-data-sources?tabs=defender-portal)
7171
- Experience in the Defender portal:
7272
- [Visibility of connectors used by the unified security operations platform](/azure/sentinel/microsoft-sentinel-defender-portal)
73-
- [Defender for Cloud](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed>
74-
- [DLP data](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed>
73+
- [Defender for Cloud](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed-->
74+
- [DLP data](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed-->
7575

7676
- **Automation**: [Automation in the Microsoft Defender portal](/azure/sentinel/automation/automation#automation-in-the-microsoft-defender-portal)
7777

7878
- **Ecosystem**: Distribute content across workspaces using one of the following methods:
7979

8080
- [Deploy content as code from your repository](/azure/sentinel/ci-cd)
81-
- [Microsoft Defender multitenant management](../mto-overview.md)
81+
- [Microsoft Defender multitenant management](mto-overview.md)
8282

8383
- **SOC optimization**: [Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json&tabs=defender-portal)
8484

@@ -93,19 +93,57 @@ The following content is relevant for security analysts or security managers on
9393

9494
- **Incident and alert management**
9595

96-
- **Attack disruption**
96+
The streamlined incident triage workflow in the Defender portal may require some retraining of analysts and updates to existing SOC processes. For example, incidents may now contain multiple cross-security domain alerts, reducing the number of required analysts and potentially combining tier 1 and tier 2 analysts.
97+
98+
- [Alert correlation and incident merging in the Microsoft Defender portal](/defender-xdr/alerts-incidents-correlation?view=o365-worldwide)
99+
100+
- **Attack disruption**:
101+
102+
- [Automatic attack disruption](/defender-xdr/automatic-attack-disruption)
103+
- [Details and results of an automatic attack disruption action](/defender-xdr/autoad-results)
104+
- [Exclude assets from automated responses](/defender-xdr/automatic-attack-disruption-exclusions)
97105

98106
- **Advanced hunting**
99107

108+
- [Advanced hunting with Microsoft Sentinel data in Microsoft Defender](/defender-xdr/advanced-hunting-microsoft-defender)
109+
- [Microsoft Sentinel in the Microsoft Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
110+
100111
- **Entities and user and entity behavior analytics (UEBA)**
101112

102-
- **Case management**
113+
- [Advanced threat detection with UEBA](/azure/sentinel/identify-threats-with-entity-behavior-analytics)
114+
- [Enable UEBA](/azure/sentinel/enable-entity-behavior-analytics?tabs=defender)
115+
- [Microsoft Sentinel UEBA reference](/azure/sentinel/ueba-reference)
116+
- [Investigate users](/defender-xdr/investigate-users)
117+
- [Device entity pages](/defender-xdr/entity-page-device)
118+
- [Global search](/defender-xdr/microsoft-365-defender-portal#global-search)
119+
120+
- **Case management**: [Manage cases in Microsoft's unified security operations platform](/unified-secops-platform/cases-overview)
121+
122+
- **Security Copilot integration**:
123+
124+
- [Summarize incidents](/microsoft-365/security/defender/security-copilot-m365d-incident-summary)
125+
- [Summarize identities](/defender-xdr/security-copilot-defender-identity-summary)
126+
- [Use guided response](/microsoft-365/security/defender/security-copilot-m365d-guided-response)
127+
- [Analyze files](/microsoft-365/security/defender/copilot-in-defender-file-analysis)
128+
- [Analyze scripts and codes](/microsoft-365/security/defender/security-copilot-m365d-script-analysis)
129+
- [Create incident reports](/microsoft-365/security/defender/security-copilot-m365d-create-incident-report)
130+
- [Generate KQL queries for hunting](/microsoft-365/security/defender/advanced-hunting-security-copilot)
131+
- [Summarize device information](/microsoft-365/security/defender/copilot-in-defender-device-summary)
132+
133+
- **Threat intelligence**: Extra features are available in the Defender portal with unified SecOps, including:
134+
135+
- [Threat analytics](/defender-xdr/threat-analytics)
136+
- [Intel profiles](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/whats-new-intel-profiles-deliver-crucial-information-context-about-threats/3780076) <!--do we have nothing in docs about this?-->
137+
- [Searching and pivoting with the Intel explorer](/defender/threat-intelligence/searching-and-pivoting)
138+
- [Intel projects](/defender/threat-intelligence/using-projects)
103139

104-
- **Security Copilot integraton**
140+
For more information, see [Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json).
105141

106-
- **Threat intelligence**
142+
- **Visualization and reporting with workbooks**:
107143

108-
- **Visualization and reporting with workbooks**
144+
- [Visualize and monitor your data by using workbooks with Microsoft Sentinel](/azure/sentinel/monitor-your-data?tabs=defender-portal)
145+
- [Azure Workbooks](/azure/azure-monitor/visualize/workbooks-overview)
146+
- [Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json) <!--add bookmark for workbooks related information-->
109147

110148
## Related content
111149

0 commit comments

Comments
 (0)