You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: unified-secops-platform/transition.md
+46-8Lines changed: 46 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -70,15 +70,15 @@ The following content is relevant for security engineers on a SecOps team that's
70
70
-[Microsoft Sentinel data connectors](/azure/sentinel/connect-data-sources?tabs=defender-portal)
71
71
- Experience in the Defender portal:
72
72
-[Visibility of connectors used by the unified security operations platform](/azure/sentinel/microsoft-sentinel-defender-portal)
73
-
-[Defender for Cloud](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed>
74
-
-[DLP data](/azure/sentinel/microsoft-sentinel-defender-portal) <!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed>
73
+
-[Defender for Cloud](/azure/sentinel/microsoft-sentinel-defender-portal)<!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed-->
74
+
-[DLP data](/azure/sentinel/microsoft-sentinel-defender-portal)<!--add bookmarks for data connector specifics, also add content there re mdc and dlp items. that's on ed-->
75
75
76
76
-**Automation**: [Automation in the Microsoft Defender portal](/azure/sentinel/automation/automation#automation-in-the-microsoft-defender-portal)
77
77
78
78
-**Ecosystem**: Distribute content across workspaces using one of the following methods:
79
79
80
80
-[Deploy content as code from your repository](/azure/sentinel/ci-cd)
-**SOC optimization**: [Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json&tabs=defender-portal)
84
84
@@ -93,19 +93,57 @@ The following content is relevant for security analysts or security managers on
93
93
94
94
-**Incident and alert management**
95
95
96
-
-**Attack disruption**
96
+
The streamlined incident triage workflow in the Defender portal may require some retraining of analysts and updates to existing SOC processes. For example, incidents may now contain multiple cross-security domain alerts, reducing the number of required analysts and potentially combining tier 1 and tier 2 analysts.
97
+
98
+
-[Alert correlation and incident merging in the Microsoft Defender portal](/defender-xdr/alerts-incidents-correlation?view=o365-worldwide)
-[Intel profiles](https://techcommunity.microsoft.com/blog/defenderthreatintelligence/whats-new-intel-profiles-deliver-crucial-information-context-about-threats/3780076)<!--do we have nothing in docs about this?-->
137
+
-[Searching and pivoting with the Intel explorer](/defender/threat-intelligence/searching-and-pivoting)
For more information, see [Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json).
105
141
106
-
-**Threat intelligence**
142
+
-**Visualization and reporting with workbooks**:
107
143
108
-
-**Visualization and reporting with workbooks**
144
+
-[Visualize and monitor your data by using workbooks with Microsoft Sentinel](/azure/sentinel/monitor-your-data?tabs=defender-portal)
-[Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json)<!--add bookmark for workbooks related information-->
0 commit comments