Skip to content

Commit 5f668a3

Browse files
authored
Merge pull request #2314 from batamig/unified-soc-opt
adding what's new for unified soc opts - USX docs
2 parents 3968cd0 + 5146896 commit 5f668a3

File tree

2 files changed

+31
-1
lines changed

2 files changed

+31
-1
lines changed

unified-secops-platform/TOC.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@
7070
- name: Automated investigation and response in Microsoft Defender XDR
7171
href: /defender-xdr/m365d-autoir?toc=/unified-secops-platform/toc.json&bc=/unified-secops-platform/breadcrumb/toc.json
7272
- name: Optimize your security operations
73-
href: /azure/sentinel/soc-optimization/soc-optimization-access?toc=/unified-secops-platform/toc.json&bc=/unified-secops-platform/breadcrumb/toc.json
73+
href: /azure/sentinel/soc-optimization/soc-optimization-access?toc=/unified-secops-platform/toc.json&bc=/unified-secops-platform/breadcrumb/toc.json&tabs=defender-portal
7474
- name: Manage your unified SOC
7575
items:
7676
- name: Manage multiple tenants

unified-secops-platform/whats-new.md

Lines changed: 30 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -20,6 +20,36 @@ ms.topic: concept-article
2020

2121
This article lists recent features added into Microsoft's unified SecOps platform within the Microsoft Defender portal, and new features in related services that provide an enhanced user experience in the platform.
2222

23+
## January 2024
24+
25+
[SOC optimization updates for unified coverage management](#soc-optimization-updates-for-unified-coverage-management)
26+
27+
### SOC optimization updates for unified coverage management
28+
29+
In workspaces enabled for unified security operations, SOC optimziations now support both SIEM and XDR data, with detection coverage from across Microsoft Defender services.
30+
31+
In the Defender portal, the **SOC optimizations** and **MITRE ATT&CK** pages also now provide extra functionality for threat-based coverage optimiations to help you understand the impact of the recommendations on your environment and help you prioritize which to implement first.
32+
33+
Enhancements on the SOC optimizations **Overview** page include:
34+
35+
- A **High**, **Medium**, or **Low** score for your current detection coverage. This sort of scoring can help you decide which recommendations to prioritize at a glance.
36+
- An indication of the number of active Microsoft Defender products (services) out of all available products. This helps you understand whether there's a whole product that you're missing in your environment.
37+
38+
Optimizations on an optimization details side pane, shown when you drill down to a specific optimization, include:
39+
40+
- Detailed coverage analysis, including the number of user-defined detections, response actions, and products you have active
41+
- Detailed spider charts that show your coverage across different threat categories, for both user-defined and out-of-the-box detections.
42+
- An option to jump to the specific threat scenario in the **MITRE ATT&CK** page instead of viewing MITRE ATT&CK coverage only in the side pane.
43+
- An option to **View full threat scenario** to drill down to even further details about the security products and detections available to provide security coverage in your environment.
44+
45+
Enhancements for **MITRE ATT&CK** functionality include:
46+
47+
- A new toggle to view coverage by threat scenario. If you've jumped to the **MITRE ATT&CK** page from either a recommendation details side pane or from the **View full threat scenario** page, the **MITRE ATT&CK** page is pre-filtered for your threat scenario.
48+
49+
- The technique details pane, shown on the side when you select a specific MITRE ATT&CK technique, now shows the number of active detections out of all available detections for that technique.
50+
51+
For more information, see [Optimize your security operations](/azure/sentinel/soc-optimization/soc-optimization-access?toc=%2Funified-secops-platform%2Ftoc.json&bc=%2Funified-secops-platform%2Fbreadcrumb%2Ftoc.json&tabs=defender-portal) and [Understand security coverage by the MITRE ATT&CK framework](/azure/sentinel/mitre-coverage).
52+
2353
## December 2024
2454

2555
- [New SOC optimization recommendations based on similar organizations (Preview)](#new-soc-optimization-recommendations-based-on-similar-organizations-preview)

0 commit comments

Comments
 (0)