Skip to content

Commit 5e46379

Browse files
committed
updated preview features
1 parent 7e37d9b commit 5e46379

File tree

1 file changed

+8
-1
lines changed

1 file changed

+8
-1
lines changed

defender-xdr/investigate-incidents.md

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -84,6 +84,11 @@ From the graph, you can:
8484

8585
- Hunt for entity information of a device, file, IP address, URL, user, email, mailbox, or cloud resource.
8686

87+
> [!IMPORTANT]
88+
> Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.
89+
90+
### Go hunt (Preview)
91+
8792
The ***go hunt*** option takes advantage of the [advanced hunting](advanced-hunting-go-hunt.md) feature to find relevant information about an entity. The *go hunt* query checks relevant schema tables for any events or alerts involving the specific entity you're investigating. You can select any of the options to find relevant information about the entity:
8893

8994
- See all available queries – the option returns all available queries for the entity type you're investigating.
@@ -98,7 +103,9 @@ The resulting logs or alerts can be linked to an incident by selecting a results
98103

99104
If the incident or related alerts were the result of an analytics rule you've set, you can also select ***Run query*** to see other related results.
100105

101-
(Preview) The incident graph also contains information about **critical attack paths**. These paths allows security analysts to identify what other entities an attacker is likely to target next. To view an attack path, you can click on an entity and select **View attack path**.
106+
### Critical attack path (Preview)
107+
108+
The incident graph also contains information about **critical attack paths**. These paths allows security analysts to identify what other entities an attacker is likely to target next. To view an attack path, you can click on an entity and select **View attack path**.
102109

103110
Attack paths are available for entities with the **critical asset** tag.
104111

0 commit comments

Comments
 (0)