Skip to content

Commit 5e1fd28

Browse files
committed
added cloud resource subsection
1 parent 0c269f3 commit 5e1fd28

File tree

3 files changed

+8
-0
lines changed

3 files changed

+8
-0
lines changed

defender-xdr/investigate-incidents.md

Lines changed: 8 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -169,6 +169,14 @@ The **Apps** view lists all the apps identified to be part of or related to the
169169

170170
You can select the check mark for an app to see a list of active alerts. Select the app name to see additional details on the Explorer page for Defender for Cloud Apps.
171171

172+
### Cloud resources
173+
174+
The **Cloud resources** view lists all the cloud resources identified to be part of or related to the incident. Here's an example.
175+
176+
:::image type="content" source="/defender/media/investigate-incidents/incident-assets-cloudresource-small.png" alt-text="The Cloud resources page for an incident in the Microsoft Defender portal." lightbox="/defender/media/investigate-incidents/incident-assets-cloudresource.png":::
177+
178+
You can select the check mark for a cloud resource to see the resource's details and a list of active alerts. Select *Open cloud resource page* to see additional details and to view its full details in Microsoft Defender for Cloud.
179+
172180
## Investigations
173181

174182
The **Investigations** tab lists all the [automated investigations](m365d-autoir.md) triggered by alerts in this incident. Automated investigations will perform remediation actions or wait for analyst approval of actions, depending on how you configured your automated investigations to run in Defender for Endpoint and Defender for Office 365.
72.8 KB
Loading
220 KB
Loading

0 commit comments

Comments
 (0)