Skip to content

Commit 39da4ab

Browse files
committed
sanity
1 parent 2b7d2a9 commit 39da4ab

File tree

2 files changed

+4
-4
lines changed

2 files changed

+4
-4
lines changed
128 Bytes
Loading

unified-secops-platform/respond-threats-overview.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -29,7 +29,7 @@ In the Defender portal, unified support for incident correlation and integrated
2929

3030
### Incident correlation
3131

32-
In the Defender portal, related alerts from across multiple attack surfaces are grouped into a single incident, improving the efficiency of incident response. Correlating alerts from various sources such as endpoints, identities, email, and cloud workloads helps security teams gain a holistic view of an attack campaign. This comprehensive perspective allows analysts to understand the full scope of an incident, identify the root cause, and determine the most effective remediation actions.
32+
Related alerts from across multiple attack surfaces are grouped into a single incident in the Defender portal, improving the efficiency of incident response. Correlating alerts from various sources such as endpoints, identities, email, and cloud workloads helps security teams gain a holistic view of an attack campaign. This comprehensive perspective allows analysts to understand the full scope of an incident, identify the root cause, and determine the most effective remediation actions.
3333

3434
The following image shows a sample collection of alerts collected into a single incident in the Defender portal. In this example, alerts from Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender XDR, Microsoft Defender for Office 365, and Microsoft Sentinel are all included in the same incident.
3535

@@ -43,7 +43,7 @@ Threat intelligence integrates across Defender portal services to enrich alerts
4343

4444
Continuous updates to threat intelligence feeds keep security teams ahead of emerging threats and improve the organization's overall resilience.
4545

46-
The following image shows an example of the incidents related to a **Human-operated ransomware** Threat analytics report in the **Threat intelligence** area of the Defender portal.
46+
The following image shows an example of the incidents related to a **Human-operated ransomware** threat analytics report in the **Threat intelligence** area of the Defender portal.
4747

4848
:::image type="content" source="media/respond-threats-overview/threat-analytics.png" alt-text="Screenshot of a list of related incidents to a specific threat." lightbox="media/respond-threats-overview/threat-analytics.png":::
4949

@@ -91,7 +91,7 @@ Guided responses are shown together with other Copilot recommendations, as actio
9191

9292
The following image shows a sample of the **Guided response** section of the Copilot pane for a specific incident. If you have a lot of recommended actions to sort through, select the **Status** filter to show only some of the actions at a time
9393

94-
:::image type="content" source="media/respond-threats-overview/guided-response.png" alt-text="Screenshot of the Guided response section of the Copilot pane for a specific incident.":::
94+
:::image type="content" source="media/respond-threats-overview/guided-response.png" alt-text="Screenshot of the Guided response section of the Copilot pane for a specific incident." border="false":::
9595

9696
For more information, see [Triage and investigate incidents with guided responses from Microsoft Copilot in Microsoft Defender](/defender-xdr/security-copilot-m365d-guided-response).
9797

@@ -108,7 +108,7 @@ For more information, see:
108108

109109
## Microsoft Sentinel threat response features
110110

111-
Microsoft Sentinel provides cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) features for intelligent security analytics and threat intelligence across the enterprise. This section describes how Microsoft Sentinel features add to your threat detection and response capabilities.
111+
Microsoft Sentinel provides cloud-native Security Information and Event Management (SIEM) and Security Orchestration, Automation, and Response (SOAR) features for intelligent security analytics and threat intelligence across the enterprise. This section describes how Microsoft Sentinel features add to your response capabilities.
112112

113113
### Automation rules
114114

0 commit comments

Comments
 (0)