Skip to content

Commit 6914190

Browse files
committed
Final
1 parent 05299f1 commit 6914190

File tree

1 file changed

+12
-2
lines changed

1 file changed

+12
-2
lines changed

defender-xdr/manage-incidents.md

Lines changed: 12 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -46,8 +46,8 @@ This article shows you how to perform various incident management tasks associat
4646

4747
**[Incident investigation and resolution:](#incident-investigation-and-resolution)**
4848

49-
- [Specify an incident's classification](#specify-the-incidents-classification).
5049
- [Resolve an incident](#resolve-an-incident).
50+
- [Specify an incident's classification](#specify-the-incidents-classification).
5151
- [Add comments to an incident](#add-comments-to-an-incident).
5252

5353
**[Incident logging and reporting:](#incident-logging-and-reporting)**
@@ -186,7 +186,11 @@ Incidents begin life with a status of **Active**. When you're working on an inci
186186

187187
## Incident investigation and resolution
188188

189-
The following management tasks are closely associated with incident resolution, though they can be performed at any time.
189+
The following management tasks are closely associated with incident investigation and resolution, though they can be performed at any time.
190+
191+
- [Resolve an incident](#resolve-an-incident).
192+
- [Specify an incident's classification](#specify-the-incidents-classification).
193+
- [Add comments to an incident](#add-comments-to-an-incident).
190194

191195
### Resolve an incident
192196

@@ -247,6 +251,12 @@ All comments are added to the historical events of the incident. You can see the
247251

248252
## Incident logging and reporting
249253

254+
The following management tasks can be associated with auditing and reporting on incident investigations, though they can be performed at any time.
255+
256+
- [Edit the incident name](#edit-the-incident-name).
257+
- Assess the activity audit and add comments in the [Activity log](#view-the-activity-log-of-an-incident).
258+
- [Export incident data to PDF](#export-incident-data-to-pdf).
259+
250260
### Edit the incident name
251261

252262
Microsoft Defender automatically assigns a name based on alert attributes such as the number of endpoints affected, users affected, detection sources or categories. The incident name allows you to quickly understand the scope of the incident. For example: *Multi-stage incident on multiple endpoints reported by multiple sources.*

0 commit comments

Comments
 (0)