Skip to content

Commit 88beee4

Browse files
committed
Update manage-incidents.md
1 parent 8d8a327 commit 88beee4

File tree

1 file changed

+9
-7
lines changed

1 file changed

+9
-7
lines changed

defender-endpoint/manage-incidents.md

Lines changed: 9 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -38,40 +38,42 @@ Selecting an incident from the **Incidents queue** brings up the **Incident mana
3838
You can assign incidents to yourself, change the status and classification, rename, or comment on them to keep track of their progress.
3939

4040
> [!TIP]
41-
> For additional visibility at a glance, incident names are automatically generated based on alert attributes such as the number of endpoints affected, users affected, detection sources or categories. This allows you to quickly understand the scope of the incident.
41+
> For additional visibility at a glance, incident names are automatically generated based on alert attributes such as the number of endpoints affected, users affected, detection sources, or categories. This allows you to quickly understand the scope of the incident.
4242
>
4343
> For example: *Multi-stage incident on multiple endpoints reported by multiple sources.*
4444
>
45-
> Incidents that existed prior the rollout of automatic incident naming will retain their names.
45+
> Incidents that existed prior to the rollout of automatic incident naming retain their names.
4646
>
4747
4848
:::image type="content" source="media/atp-incident-details-updated.png" alt-text="The incident detail page" lightbox="media/atp-incident-details-updated.png":::
4949

5050
## Assign incidents
51-
If an incident has not been assigned yet, you can select **Assign to me** to assign the incident to yourself. Doing so assumes ownership of not just the incident, but also all the alerts associated with it.
51+
If an incident hasn't been assigned yet, you can select **Assign to me** to assign the incident to yourself. Doing so assumes ownership of not just the incident, but also all the alerts associated with it.
5252

5353
## Set status and classification
5454
### Incident status
5555
You can categorize incidents (as **Active**, or **Resolved**) by changing their status as your investigation progresses. This helps you organize and manage how your team can respond to incidents.
5656

57-
For example, your SOC analyst can review the urgent **Active** incidents for the day, and decide to assign them to himself for investigation.
57+
For example, your SOC analyst can review the urgent **Active** incidents for the day, and decide to assign them to their self for investigation.
5858

59-
Alternatively, your SOC analyst might set the incident as **Resolved** if the incident has been remediated.
59+
Alternatively, your SOC analyst might set the incident as **Resolved** if the incident was remediated.
6060

6161
### Classification
6262
You can choose not to set a classification, or decide to specify whether an incident is true or false. Doing so helps the team see patterns and learn from them.
6363

6464
### Add comments
6565
You can add comments and view historical events about an incident to see previous changes made to it.
6666

67-
Whenever a change or comment is made to an alert, it is recorded in the Comments and history section.
67+
Whenever a change or comment is made to an alert, it's recorded in the Comments and history section.
6868

6969
Added comments instantly appear on the pane.
7070

7171

7272

73-
## Related topics
73+
## Related articles
74+
7475
- [Incidents queue](view-incidents-queue.md)
7576
- [View and organize the Incidents queue](view-incidents-queue.md)
7677
- [Investigate incidents](investigate-incidents.md)
78+
7779
[!INCLUDE [Microsoft Defender for Endpoint Tech Community](../includes/defender-mde-techcommunity.md)]

0 commit comments

Comments
 (0)