Skip to content

Commit 91df472

Browse files
authored
Merge pull request #5441 from sbreingold-ms/wi-502580-batch-2a-defender-xdr-image-reorg
wi 502580 batch 2a defender xdr image reorg
2 parents e927183 + b89273e commit 91df472

29 files changed

+23
-23
lines changed

defender-xdr/advanced-hunting-defender-use-custom-rules.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ adx('<Cluster URI>/<Database Name>').<Table Name>
5656

5757
For example, to get the first 10 rows of data from the `StormEvents` table stored in a certain URI:
5858

59-
:::image type="content" source="/defender-xdr/media/adx-sample.png" alt-text="Screenshot of adx operator in advanced hunting." lightbox="/defender-xdr/media/adx-sample.png":::
59+
:::image type="content" source="./media/advanced-hunting-defender-use-custom-rules/adx-sample.png" alt-text="Screenshot of adx operator in advanced hunting." lightbox="./media/advanced-hunting-defender-use-custom-rules/adx-sample.png":::
6060

6161
> [!NOTE]
6262
> The `adx()` operator isn't supported for custom detections.
@@ -76,7 +76,7 @@ In the query editor, enter *arg("").* followed by the Azure Resource Graph table
7676

7777
For example:
7878

79-
:::image type="content" source="/defender-xdr/media/arg-operator2.png" alt-text="Screenshot of arg operator in advanced hunting." lightbox="/defender-xdr/media/arg-operator2.png":::
79+
:::image type="content" source="./media/advanced-hunting-defender-use-custom-rules/arg-operator2.png" alt-text="Screenshot of arg operator in advanced hunting." lightbox="./media/advanced-hunting-defender-use-custom-rules/arg-operator2.png":::
8080

8181
You can also, for instance, filter a query that searches over Microsoft Sentinel data based on the results of an Azure Resource Graph query:
8282

@@ -97,7 +97,7 @@ To use a saved query from Microsoft Sentinel, go to the **Queries** tab and scro
9797
- **Open in query editor** – Loads the query in the query editor.
9898
- **View details** – Opens the query details side pane where you can inspect the query, run the query, or open the query in the editor.
9999

100-
:::image type="content" source="/defender/media/advanced-hunting-unified-view-details.png" alt-text="Screenshot of the options available in saved queries in the Microsoft Defender portal." lightbox="/defender/media/advanced-hunting-unified-view-details.png":::
100+
:::image type="content" source="./media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-view-details.png" alt-text="Screenshot of the options available in saved queries in the Microsoft Defender portal." lightbox="./media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-view-details.png":::
101101

102102

103103
For editable queries, more options are available:
@@ -120,7 +120,7 @@ To help discover threats and anomalous behaviors in your environment, you can cr
120120

121121
For analytics rules that apply to data ingested through the connected Microsoft Sentinel workspace, select **Manage rules > Create analytics rule**.
122122

123-
:::image type="content" source="/defender/media/advanced-hunting-unified-rules.png" alt-text="Screenshot of the options to create custom analytics or detections in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-unified-rules.png":::
123+
:::image type="content" source="./media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-rules.png" alt-text="Screenshot of the options to create custom analytics or detections in the Microsoft Defender portal" lightbox="./media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-rules.png":::
124124

125125
The **Analytics rule wizard** appears. Fill up the required details as described in [Analytics rule wizard—General tab](/azure/sentinel/detect-threats-custom#analytics-rule-wizardgeneral-tab).
126126

defender-xdr/advanced-hunting-limits.md

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -61,11 +61,11 @@ The report can be accessed in two ways:
6161

6262
- In the advanced hunting page, select **Query resources report**:
6363

64-
:::image type="content" source="/defender/media/ah-query-resources/view-query-resources report.png" alt-text="view the query resources report button in the AH portal" lightbox="/defender/media/ah-query-resources/view-query-resources report.png":::
64+
:::image type="content" source="./media/advanced-hunting-limits/view-query-resources report.png" alt-text="view the query resources report button in the AH portal" lightbox="./media/advanced-hunting-limits/view-query-resources report.png":::
6565

6666
- Within the **Reports** page, find the new report entry in the **General** section
6767

68-
:::image type="content" source="/defender/media/ah-query-resources/reports-general-query-resources.png" alt-text="view the query resources report in the Reports section" lightbox="/defender/media/ah-query-resources/reports-general-query-resources.png":::
68+
:::image type="content" source="./media/advanced-hunting-limits/reports-general-query-resources.png" alt-text="view the query resources report in the Reports section" lightbox="./media/advanced-hunting-limits/reports-general-query-resources.png":::
6969

7070
All users can access the reports; however, only the Microsoft Entra Global Administrator, Microsoft Entra Security Administrator, and Microsoft Entra Security Reader roles can see queries done by all users in all interfaces. Any other user can only see:
7171

@@ -93,7 +93,7 @@ The query resources report contains all queries that ran, including detailed res
9393
> [!TIP]
9494
> If the query state is **Failed**, you can hover the field to view the reason for the query failure.
9595
96-
:::image type="content" source="/defender/media/ah-query-resources/excessive-usage-sample.png" alt-text="view inefficient queries" lightbox="/defender/media/ah-query-resources/excessive-usage-sample.png":::
96+
:::image type="content" source="./media/advanced-hunting-limits/excessive-usage-sample.png" alt-text="view inefficient queries" lightbox="./media/advanced-hunting-limits/excessive-usage-sample.png":::
9797

9898
### Find resource-heavy queries
9999

@@ -112,7 +112,7 @@ The graph supports two views:
112112
- Average use per day – the average use of resources per day
113113
- Highest use per day – the highest actual use of resources per day
114114

115-
![Two view modes for query resources report](/defender/media/ah-query-resources/resource-usage-over-time.png)
115+
![Two view modes for query resources report](./media/advanced-hunting-limits/resource-usage-over-time.png)
116116

117117
This means that, for instance, if on a specific day you ran two queries, one used 50% of your resources and one used 100%, the average daily use value would show 75%, while the top daily use would show 100%.
118118

defender-xdr/advanced-hunting-microsoft-defender.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ You can use advanced hunting KQL (Kusto Query Language) queries to hunt through
6666
When you open the advanced hunting page for the first time after connecting a workspace, you can find many of that workspace's tables organized by solution after the Microsoft Defender XDR tables under the **Schema** tab.
6767

6868

69-
:::image type="content" source="/defender/media/advanced-hunting-unified-sentinel-data.png" alt-text="Screenshot of advanced hunting schema tab in the Microsoft Defender portal highlighting location of Sentinel tables" lightbox="/defender/media/advanced-hunting-unified-sentinel-data.png":::
69+
:::image type="content" source="./media/advanced-hunting-microsoft-defender/advanced-hunting-unified-sentinel-data.png" alt-text="Screenshot of advanced hunting schema tab in the Microsoft Defender portal highlighting location of Sentinel tables" lightbox="./media/advanced-hunting-microsoft-defender/advanced-hunting-unified-sentinel-data.png":::
7070

7171

7272
Likewise, you can find the functions from Microsoft Sentinel in the **Functions** tab, and your shared and sample queries from Microsoft Sentinel can be found in the **Queries** tab inside folders marked **Sentinel**.
@@ -81,7 +81,7 @@ In the unified portal, in addition to viewing the schema column names and descri
8181
- **Data retention period** – how long the data is set to be kept
8282
- **Tags** – available for Sentinel data tables
8383

84-
:::image type="content" source="/defender/media/advanced-hunting-unified-view-schema.png" alt-text="Screenshot of the schema information pane in the Microsoft Defender portal" lightbox="/defender/media/advanced-hunting-unified-view-schema.png":::
84+
:::image type="content" source="./media/advanced-hunting-microsoft-defender/advanced-hunting-unified-view-schema.png" alt-text="Screenshot of the schema information pane in the Microsoft Defender portal" lightbox="./media/advanced-hunting-microsoft-defender/advanced-hunting-unified-view-schema.png":::
8585

8686
## Known issues
8787

defender-xdr/advanced-hunting-modes.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -32,7 +32,7 @@ ms.date: 03/28/2025
3232

3333

3434

35-
You can find the **advanced hunting** page by going to the left navigation bar in the Microsoft Defender portal and selecting **Hunting** > **Advanced hunting**. If the navigation bar is collapsed, select the hunting icon ![hunting icon](/defender/media/guided-hunting/hunting-icon.png).
35+
You can find the **advanced hunting** page by going to the left navigation bar in the Microsoft Defender portal and selecting **Hunting** > **Advanced hunting**. If the navigation bar is collapsed, select the hunting icon ![hunting icon](./media/advanced-hunting-modes/hunting-icon.png).
3636

3737
In the **advanced hunting** page, two modes are supported:
3838

@@ -54,13 +54,13 @@ When you open the advanced hunting page for the first time after guided hunting
5454

5555
To take the tour, select **Take tour** when this banner appears:
5656

57-
[![banner inviting user to take the tour](/defender/media/guided-hunting/1-guided-hunting-banner-tb.png)](/defender/media/guided-hunting/1-guided-hunting-banner.png#lightbox)
57+
[![banner inviting user to take the tour](./media/advanced-hunting-modes/1-guided-hunting-banner-tb.png)](./media/advanced-hunting-modes/1-guided-hunting-banner.png#lightbox)
5858

5959
Follow the blue teaching bubbles that appear throughout the page and select **Next** to move from one step to the next.
6060

6161
You can take the tour again at any time by going to **Help resources** > **Learn more** and selecting **Take the tour**.
6262

63-
![Screenshot of help resources](/defender/media/guided-hunting/help-resources.png)
63+
![Screenshot of help resources](./media/advanced-hunting-modes/help-resources.png)
6464

6565
You can then start building your query to hunt for threats. The following articles can help you get the most out of hunting in guided mode:
6666

defender-xdr/advanced-hunting-security-copilot.md

Lines changed: 10 additions & 10 deletions
Original file line numberDiff line numberDiff line change
@@ -47,38 +47,38 @@ Users with access to Security Copilot have access to this capability in advanced
4747

4848
1. Open the **Advanced hunting** page from the navigation bar in Microsoft Defender portal. The Security Copilot side pane for advanced hunting appears at the right hand side.
4949

50-
:::image type="content" source="/defender/media/advanced-hunting-security-copilot-pane-big.png" alt-text="Screenshot of the Copilot pane in advanced hunting." lightbox="/defender/media/advanced-hunting-security-copilot-pane-big.png":::
50+
:::image type="content" source="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-pane-big.png" alt-text="Screenshot of the Copilot pane in advanced hunting." lightbox="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-pane-big.png":::
5151

5252
You can also reopen Copilot by selecting **Copilot** at the top of the query editor.
53-
1. In the Copilot prompt bar, ask any threat hunting query that you want to run and press :::image type="icon" source="media/Send.png" border="false"::: or **Enter**.
53+
1. In the Copilot prompt bar, ask any threat hunting query that you want to run and press :::image type="icon" source="./media/advanced-hunting-security-copilot/Send.png" border="false"::: or **Enter**.
5454

5555

5656

57-
:::image type="content" source="/defender/media/advanced-hunting-security-copilot-query-big.png" alt-text="Screenshot that shows prompt bar in the Security Copilot for advanced hunting." lightbox="/defender/media/advanced-hunting-security-copilot-query-big.png":::
57+
:::image type="content" source="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-query-big.png" alt-text="Screenshot that shows prompt bar in the Security Copilot for advanced hunting." lightbox="./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-query-big.png":::
5858

5959
1. Copilot generates a KQL query from your text instruction or question. While Copilot is generating, you can cancel the query generation by selecting **Stop generating**.
6060

61-
![Screenshot of Security Copilot in advanced hunting generating a response.](/defender/media/advanced-hunting-security-copilot-generate.png)
61+
![Screenshot of Security Copilot in advanced hunting generating a response.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-generate.png)
6262

6363

6464
1. Review the generated query. To check how Copilot came up with the query, you can select **See the logic behind the query** below the query text to expand the explanation behind the query. Select it again to minimize.
6565

66-
![Screenshot of Copilot button showing See the logic behind the query.](/defender/media/advanced-hunting-security-copilot-see-logic.png)
66+
![Screenshot of Copilot button showing See the logic behind the query.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-see-logic.png)
6767

6868
You can then choose to run the query by selecting **Run query**.
6969

70-
![Screenshot of Copilot button showing Run query option.](/defender/media/advanced-hunting-security-copilot-run-query.png)
70+
![Screenshot of Copilot button showing Run query option.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-run-query.png)
7171

7272
The generated query then appears as the last query in the query editor and runs automatically.
7373

7474
If you need to make further tweaks, select **Add to editor**.
7575

76-
![Screenshot of Security Copilot in advanced hunting showing the Add to editor option.](/defender/media/advanced-hunting-security-copilot-add-editor.png)
76+
![Screenshot of Security Copilot in advanced hunting showing the Add to editor option.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-add-editor.png)
7777

7878
The generated query appears in the query editor as the last query, where you can edit it before running using the regular **Run query** above the query editor.
7979

8080

81-
1. You can provide feedback about the generated response by selecting the feedback icon ![Screenshot of feedback icon.](/defender/media/advanced-hunting-security-copilot-feedback-icon.png) and choosing **Looks right**, **Needs improvement**, or **Inappropriate**.
81+
1. You can provide feedback about the generated response by selecting the feedback icon ![Screenshot of feedback icon.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-feedback-icon.png) and choosing **Looks right**, **Needs improvement**, or **Inappropriate**.
8282

8383

8484
> [!TIP]
@@ -94,7 +94,7 @@ You can start your first session anytime by asking a question in the Copilot sid
9494

9595
Select the chat bubble icon (**New chat**) to discard the current session.
9696

97-
![Screenshot of Security Copilot in advanced hunting showing the new chat icon.](/defender/media/advanced-hunting-security-copilot-clear-session.png)
97+
![Screenshot of Security Copilot in advanced hunting showing the new chat icon.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-clear-session.png)
9898

9999
## Query explanations
100100

@@ -104,6 +104,6 @@ Select the chat bubble icon (**New chat**) to discard the current session.
104104

105105
Select the ellipses in the Copilot side pane to choose whether or not to automatically add and run the generated query in advanced hunting.
106106

107-
![Screenshot of Security Copilot in advanced hunting showing the settings ellipses icon.](/defender/media/advanced-hunting-security-copilot-settings.png)
107+
![Screenshot of Security Copilot in advanced hunting showing the settings ellipses icon.](./media/advanced-hunting-security-copilot/advanced-hunting-security-copilot-settings.png)
108108

109109
Deselecting the **Run generated query automatically** setting gives you the option of running the generated query automatically (**Add and run**) or adding the generated query to the query editor for further modification (**Add to editor**).

defender/media/advanced-hunting-unified-rules.png renamed to defender-xdr/media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-rules.png

File renamed without changes.

defender/media/advanced-hunting-unified-view-details.png renamed to defender-xdr/media/advanced-hunting-defender-use-custom-rules/advanced-hunting-unified-view-details.png

File renamed without changes.

defender-xdr/media/adx-sample.png renamed to defender-xdr/media/advanced-hunting-defender-use-custom-rules/adx-sample.png

File renamed without changes.

defender-xdr/media/arg-operator2.png renamed to defender-xdr/media/advanced-hunting-defender-use-custom-rules/arg-operator2.png

File renamed without changes.

defender/media/ah-query-resources/excessive-usage-sample.png renamed to defender-xdr/media/advanced-hunting-limits/excessive-usage-sample.png

File renamed without changes.

0 commit comments

Comments
 (0)