Skip to content

Commit 18d13dd

Browse files
edit based on review
1 parent 3db4e5d commit 18d13dd

File tree

1 file changed

+5
-4
lines changed

1 file changed

+5
-4
lines changed

unified-secops-platform/whats-new.md

Lines changed: 5 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -33,21 +33,22 @@ Microsoft Sentinel-powered threat intelligence has moved in the Defender portal
3333

3434
:::image type="content" source="media/whats-new/intel-management-navigation.png" alt-text="Screenshot showing new menu placement for Microsoft Sentinel threat intelligence.":::
3535

36-
Along with the new location, the enhanced management interface brings a streamlined process for creating individual threat intel with these key features:
36+
Along with the new location, the management interface streamlines the creation and curation of threat intel with these key features:
3737

3838
- Define relationships as you create new STIX objects.
3939
- Curate existing threat intelligence with the new relationship builder.
40-
- Quickly create multiple objects by using the duplicate feature to copy the metadata from a new or existing threat intel object.
40+
- Create multiple objects quickly by copying common metadata from a new or existing TI object with the duplicate feature.
41+
- Use advanced search to sort and filter your threat intelligence objects without even writing a Log Analytics query.
4142

42-
Use advanced search to sort and filter your threat intelligence objects without even writing a Log Analytics query. For more information, see the following articles:
43+
For more information, see the following articles:
4344

4445
- [Uncover adversaries with threat intelligence in Microsoft's unified SecOps platform](threat-intelligence-overview.md)
4546
- [New STIX objects in Microsoft Sentinel](https://techcommunity.microsoft.com/blog/microsoftsentinelblog/announcing-public-preview-new-stix-objects-in-microsoft-sentinel/4369164)
4647
- [Understand threat intelligence](/azure/sentinel/understand-threat-intelligence#create-and-manage-threat-intelligence)
4748

4849
### Case management (Preview)
4950

50-
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that CMSK supports.
51+
Case management is the first installment of an end-to-end solution that provides seamless management of your security work. SecOps teams maintain security context, work more efficiently and respond faster to attacks when they manage case work without leaving the Defender portal. Here's the initial set of scenarios and features that case management supports.
5152

5253
- Define your own case workflow with custom status values
5354
- Assign tasks to collaborators and configure due dates

0 commit comments

Comments
 (0)