Skip to content

Commit 5681e66

Browse files
committed
Rewriting overview
1 parent 7f79616 commit 5681e66

File tree

1 file changed

+4
-2
lines changed

1 file changed

+4
-2
lines changed

defender-xdr/plan-incident-response.md

Lines changed: 4 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -24,11 +24,13 @@ appliesto:
2424

2525
# Plan an incident response workflow in the Microsoft Defender portal
2626

27-
In the Microsoft Defender portal, you can respond to security incidents that are automatically created from alerts. These incidents are collections of related alerts that tell the full story of an attack. The alerts in a single incident might come from all Microsoft security and compliance solutions, as well as from vast numbers of external solutions collected through Microsoft Sentinel and Microsoft Defender for Cloud.
27+
In the Microsoft Defender portal, you can respond to security incidents that are collections of related alerts and tell the full story of an attack.
28+
29+
This article provides a set of steps that you can follow to investigate, analyze, and resolve security incidents in the Microsoft Defender portal, and also maps these steps to your security team's experience level and role.
2830

2931
## Incident response workflow example in the Microsoft Defender portal
3032

31-
Here's a workflow example for responding to incidents in Microsoft 365 with the Microsoft Defender portal.
33+
Here's a workflow example for responding to incidents in the Microsoft Defender portal.
3234

3335
:::image type="content" source="/defender/media/incidents-overview/incidents-example-workflow.png" alt-text="An example of an incident response workflow for the Microsoft Defender portal." lightbox="/defender/media/incidents-overview/incidents-example-workflow.png":::
3436

0 commit comments

Comments
 (0)