Skip to content

Commit 5919e37

Browse files
committed
Update review-detected-threats.md
1 parent fdcf14e commit 5919e37

File tree

1 file changed

+6
-3
lines changed

1 file changed

+6
-3
lines changed

defender-endpoint/review-detected-threats.md

Lines changed: 6 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -59,7 +59,7 @@ You can manage threat detections for any devices that are [enrolled in Microsoft
5959

6060
2. In the navigation pane, select **Endpoint security**.
6161

62-
3. Under **Manage**, select **Antivirus**. You'll see tabs for **Summary**, **Unhealthy endpoints**, and **Active malware**.
62+
3. Under **Manage**, select **Antivirus**. You see tabs for **Summary**, **Unhealthy endpoints**, and **Active malware**.
6363

6464
4. Review the information on the available tabs, and then take action as necessary.
6565

@@ -74,11 +74,14 @@ You can manage threat detections for any devices that are [enrolled in Microsoft
7474

7575
#### In the Microsoft XDR portal > Devices with active malware > Devices with malware detections report, why does the Last update seem to be occurring today?
7676

77-
To see when the malware was detected, you can do the following:
77+
To see when the malware was detected, you can take the following steps:
7878

7979
1. Since this is an integration with Intune, visit [**Intune portal**](https://intune.microsoft.com) and select **Antivirus** and then select **Active malware** tab.
80+
8081
2. Select **Export**.
81-
3. On your device, go to Downloads, and extract the Active malware_YYYY_MM_DD_THH_MM_SS.0123Z.csv.zip.
82+
83+
3. On your device, go to Downloads, and extract the `Active malware_YYYY_MM_DD_THH_MM_SS.0123Z.csv.zip` file.
84+
8285
4. Open the CSV and find the **LastStateChangeDateTime** column to see when malware was detected.
8386

8487
#### In the devices with malware detections report, why can't I see any information about which malware was detected on the device.

0 commit comments

Comments
 (0)