You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/defender-experts-report.md
+8-7Lines changed: 8 additions & 7 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,7 +19,7 @@ ms.collection:
19
19
- tier1
20
20
- essentials-manage
21
21
ms.topic: conceptual
22
-
ms.date: 10/30/2024
22
+
ms.date: 02/07/2025
23
23
---
24
24
25
25
# Understand the Defender Experts for Hunting report in Microsoft Defender XDR
@@ -38,15 +38,15 @@ To view the report in your Microsoft Defender portal, go to **Reports**, select
38
38
39
39
Refer to the following screenshot of a sample report:
40
40
41
-

41
+
:::image type="content" source="media/defender-experts-hunting-report.png" alt-text="Screenshot of Defender Experts for hunting report." lightbox="media/defender-experts-hunting-report.png":::
42
42
43
43
## Identify prevalent threats and other potential attack entry points
44
44
45
45
Signals from Microsoft Defender XDR and investigations by Defender Experts for Hunting help identify suspicious activities in your environment. Significant threat activities will have corresponding [Defender Experts Notifications](onboarding-defender-experts-for-hunting.md#receive-defender-experts-notifications), which also provide recommendations to remediate and defend your organization.
46
46
47
47
The report provides you with the total number of Defender Experts Notifications our experts have sent for your chosen period:
48
48
49
-

49
+
:::image type="content" source="media/report-top-section-dens.png" alt-text="Screenshot of the top section of the report showing the number of threats identified." lightbox="media/report-top-section-dens.png":::
50
50
51
51
To view these notifications, select **View Defender Experts Notifications**. This button redirects you to the Microsoft Defender XDR incidents page. Defender Expert for Hunting alerts or Defender Experts Notifications are labeled with **Defender Experts**.
52
52
@@ -61,20 +61,21 @@ You can filter the activities displayed in the table by choosing any of the foll
-**All activities** – Displays all true positive, benign true positive, and false positive activities.
63
63
64
-

64
+
:::image type="content" source="/defender/media/defender-experts/threat-categories-filter.png" alt-text="Screenshot of the top section of the Threat categories section showing the dropdown menu." lightbox="/defender/media/defender-experts/threat-categories-filter.png":::
65
65
66
66
If an activity has a related Defender Expert Notification, its corresponding icon also appears under the activity name.
67
-
Selecting an identified suspicious activity opens a flyout panel detailing the impacted devices and users:
68
67
69
-

68
+
Selecting an identified suspicious activity opens a flyout panel detailing the impacted devices and users:
69
+
70
+
:::image type="content" source="media/suspicious-activity-detail-panel.png" alt-text="Screenshot of a flyout panel displaying a list of devices impacted by a detected suspicious activity." lightbox="media/suspicious-activity-detail-panel.png":::
70
71
71
72
If applicable, the page also provides links to view related Defender Expert Notifications.
72
73
73
74
## Know and understand the security weak spots in your environment
74
75
75
76
The **Top trending suspicious activities** section of the report identifies up to 20 suspicious activities that were consistently observed in your environment in the last three months, sorted based on their severity rating and frequency of occurrence:
76
77
77
-

78
+
:::image type="content" source="/defender/media/defender-experts/top-trending-suspicious-activities.png" alt-text="Screenshot of the Top trending suspicious activities section of the report." lightbox="/defender/media/defender-experts/top-trending-suspicious-activities.png":::
78
79
79
80
By showing the most critical and frequently observed activities, you can assess and evaluate their impact and develop strategies to prevent or mitigate potential threats to your environment
0 commit comments