Skip to content

Commit 7a8f50a

Browse files
authored
Merge branch 'main' into maccruz-quotaupdates
2 parents 2f0bd07 + 0cbcee0 commit 7a8f50a

File tree

45 files changed

+132
-56
lines changed

Some content is hidden

Large Commits have some content hidden by default. Use the searchbox below for content that may be hidden.

45 files changed

+132
-56
lines changed

defender-endpoint/endpoint-attack-notifications.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,10 @@ ms.collection:
1212
- m365-security
1313
- tier2
1414
ms.topic: conceptual
15+
ms.custom: cx-ean
1516
ms.subservice: edr
1617
search.appverid: met150
17-
ms.date: 08/15/2024
18+
ms.date: 10/30/2024
1819
---
1920

2021
# Endpoint Attack Notifications

defender-endpoint/evaluate-mda-using-mde-security-settings-management.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -12,9 +12,10 @@ ms.collection:
1212
- m365-security
1313
- tier2
1414
ms.topic: conceptual
15+
ms.custom: cx-ean
1516
ms.subservice: edr
1617
search.appverid: met150
17-
ms.date: 05/13/2024
18+
ms.date: 10/30/2024
1819
---
1920

2021
# Evaluate Microsoft Defender Antivirus using Microsoft Defender Endpoint Security Settings Management (Endpoint security policies)

defender-xdr/access-den-graph-api.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -13,8 +13,9 @@ ms.collection:
1313
- m365-security
1414
- tier1
1515
ms.topic: conceptual
16+
ms.custom: cx-dex
1617
search.appverid: met150
17-
ms.date: 08/14/2024
18+
ms.date: 10/30/2024
1819
---
1920

2021
# Access incident notifications using Graph API

defender-xdr/additional-information-xdr.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -16,8 +16,9 @@ ms.collection:
1616
- m365-security
1717
- tier1
1818
ms.topic: conceptual
19+
ms.custom: cx-dex
1920
search.appverid: met150
20-
ms.date: 11/10/2023
21+
ms.date: 10/30/2024
2122
---
2223

2324
# Important considerations for Microsoft Defender Experts for XDR

defender-xdr/advanced-hunting-behaviorentities-table.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ ms.topic: reference
2020
ms.date: 12/29/2023
2121
---
2222

23-
# BehaviorEntities
23+
# BehaviorEntities (Preview)
2424

2525
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2626

@@ -32,6 +32,9 @@ The `BehaviorEntities` table in the [advanced hunting](advanced-hunting-overview
3232
> [!IMPORTANT]
3333
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
3434
35+
> [!IMPORTANT]
36+
> Behaviors feature is now in preview. Have feedback to share? Fill out our [feedback form](https://forms.office.com/r/x0mX5hBkGu).
37+
3538
Behaviors are a type of data in Microsoft Defender XDR based on one or more raw events. Behaviors provide contextual insight into events and can, but not necessarily, indicate malicious activity. [Read more about behaviors](/defender-cloud-apps/behaviors)
3639

3740
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).

defender-xdr/advanced-hunting-behaviorinfo-table.md

Lines changed: 4 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -20,7 +20,7 @@ ms.topic: reference
2020
ms.date: 12/29/2023
2121
---
2222

23-
# BehaviorInfo
23+
# BehaviorInfo (Preview)
2424

2525
[!INCLUDE [Microsoft Defender XDR rebranding](../includes/microsoft-defender.md)]
2626

@@ -36,6 +36,9 @@ The `BehaviorInfo` table in the [advanced hunting](advanced-hunting-overview.md)
3636
> [!IMPORTANT]
3737
> Some information relates to prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, express or implied, with respect to the information provided here.
3838
39+
> [!IMPORTANT]
40+
> Behaviors feature is now in preview. Have feedback to share? Fill out our [feedback form](https://forms.office.com/r/x0mX5hBkGu).
41+
3942
Behaviors are a type of data in Microsoft Defender XDR based on one or more raw events. Behaviors provide contextual insight into events and can, but not necessarily, indicate malicious activity. [Read more about behaviors](/defender-cloud-apps/behaviors)
4043

4144
For information on other tables in the advanced hunting schema, [see the advanced hunting reference](advanced-hunting-schema-tables.md).

defender-xdr/advanced-hunting-schema-tables.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -57,8 +57,8 @@ The following reference lists all the tables in the schema. Each table name link
5757
| **[AADSpnSignInEventsBeta](advanced-hunting-aadspnsignineventsbeta-table.md)** | Microsoft Entra service principal and managed identity sign-ins |
5858
| **[AlertEvidence](advanced-hunting-alertevidence-table.md)** | Files, IP addresses, URLs, users, or devices associated with alerts |
5959
| **[AlertInfo](advanced-hunting-alertinfo-table.md)** | Alerts from Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud Apps, and Microsoft Defender for Identity, including severity information and threat categorization |
60-
| **[BehaviorEntities](advanced-hunting-behaviorentities-table.md)** | Behavior data types in Microsoft Defender for Cloud Apps |
61-
| **[BehaviorInfo](advanced-hunting-behaviorinfo-table.md)** | Alerts from Microsoft Defender for Cloud Apps |
60+
| **[BehaviorEntities](advanced-hunting-behaviorentities-table.md)** (Preview) | Behavior data types in Microsoft Defender for Cloud Apps |
61+
| **[BehaviorInfo](advanced-hunting-behaviorinfo-table.md)** (Preview) | Alerts from Microsoft Defender for Cloud Apps |
6262
| **[CloudAppEvents](advanced-hunting-cloudappevents-table.md)** | Events involving accounts and objects in Office 365 and other cloud apps and services |
6363
| **[DeviceEvents](advanced-hunting-deviceevents-table.md)** | Multiple event types, including events triggered by security controls such as Microsoft Defender Antivirus and exploit protection |
6464
| **[DeviceFileCertificateInfo](advanced-hunting-DeviceFileCertificateInfo-table.md)** | Certificate information of signed files obtained from certificate verification events on endpoints |

defender-xdr/auditing.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,9 @@ ms.collection:
1414
- tier1
1515
- essentials-manage
1616
ms.topic: conceptual
17+
ms.custom: cx-dex
1718
search.appverid: met150
18-
ms.date: 05/29/2023
19+
ms.date: 10/30/2024
1920
---
2021

2122
# Auditing

defender-xdr/before-you-begin-defender-experts.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -15,6 +15,7 @@ ms.collection:
1515
- tier1
1616
- essentials-compliance
1717
ms.topic: conceptual
18+
ms.custom: cx-ean
1819
search.appverid: met150
1920
ms.date: 08/14/2024
2021
---

defender-xdr/before-you-begin-xdr.md

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -14,8 +14,9 @@ ms.collection:
1414
- tier1
1515
- essentials-compliance
1616
ms.topic: conceptual
17+
ms.custom: cx-dex
1718
search.appverid: met150
18-
ms.date: 06/19/2023
19+
ms.date: 10/31/2024
1920
---
2021

2122
# Before you begin

0 commit comments

Comments
 (0)