Skip to content

Commit 7a70c7a

Browse files
committed
Learn Editor: Update indicators-overview.md
1 parent 60bfed4 commit 7a70c7a

File tree

1 file changed

+2
-3
lines changed

1 file changed

+2
-3
lines changed

defender-endpoint/indicators-overview.md

Lines changed: 2 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -159,10 +159,9 @@ The IoC API schema and the threat IDs in Advanced Hunting are updated to align w
159159

160160
Microsoft Store apps cannot be blocked by Microsoft Defender because they're signed by Microsoft.
161161

162-
Customers might experience issues with alerts for IoCs. The following scenarios are situations where alerts aren't created or are created with inaccurate information. Each issue is investigated by our engineering team.
162+
Customers might experience issues with alerts for IoCs. The following scenarios are situations where alerts aren't created or are created with inaccurate information.
163163

164-
- **Block indicators**: Generic alerts with informational severity only are created. Custom alerts (that is, custom title and severity) aren't fired in these cases.
165-
- **Warn indicators**: Generic alerts and custom alerts are possible in this scenario; however, the results aren't deterministic due to an issue with the alert detection logic. In some cases, customers might see a generic alert, whereas a custom alert might show in other cases.
164+
- **Block and Warn indicators**: Generic alerts with informational severity only are created. Custom alerts (that is, custom title and severity) aren't fired in these cases.
166165
- **Allow**: No alerts are generated (by design).
167166
- **Audit**: Alerts are generated based on the severity provided by the customer (by design).
168167
- In some cases, alerts coming from EDR detections might take precedence over alerts stemming from antivirus blocks, in which case an information alert is generated.

0 commit comments

Comments
 (0)