You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: unified-secops-platform/cases-overview.md
+24-12Lines changed: 24 additions & 12 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -19,25 +19,37 @@ ms.topic: conceptual
19
19
20
20
# Manage security operations cases natively in the Microsoft Defender portal
21
21
22
-
Case management is the first installment of new unified security operations (SecOps) capabilities for managing security work in the Microsoft Defender portal.
22
+
Microsoft Defender case management is a collection of features and capabilities delivering a unified, security-focused case management experience. This experience is designed for managing unified security operations (SecOps) work natively in the Microsoft Defender portal, without the need for third-party tools. SecOps teams maintain security context, work more efficiently, and respond faster to attacks when they manage case work without leaving the Defender portal.
23
23
24
-
This initial step toward delivering a unified, security-focused case management experience centralizes rich collaboration, customization, evidence collection, and reporting across SecOps workloads. SecOps teams maintain security context, work more efficiently, and respond faster to attacks when they manage case work without leaving the Defender portal.
24
+
The current, introductory phase of the case management rollout centralizes rich collaboration, customization, evidence collection, and reporting across SecOps workloads.
25
25
26
26
<aname="what-is-case-management-preview"></a>
27
27
28
28
## What is case management?
29
29
30
-
Case management enables you to manage SecOps cases natively in the Defender portal. Here's the initial set of scenarios and features supported.
30
+
Case management enables you to manage SecOps cases natively in the Defender portal. Even in its initial stages, SecOps teams are demonstrating the following use cases for case management:
31
31
32
-
- Define your own case workflow with custom status values
33
-
- Assign tasks to collaborators and configure due dates
34
-
- Handle escalations and complex cases by linking multiple incidents to a case
35
-
- Manage access to your cases using RBAC
36
-
-[Manage cases from multiple tenants using the multitenant portal (Preview)](mto-manage-cases.md)
32
+
- Responding to security events that span multiple incidents.
33
+
34
+
- Managing threat hunting.
35
+
36
+
- Tracking IoCs and threat actors.
37
+
38
+
- Tracking detection logic that needs tuning.
39
+
40
+
The following specific capabilities and features support these use cases and scenarios:
41
+
42
+
- Create and track your SecOps related cases in one place with the new **Cases** page.
43
+
-[Define your own case workflow by configuring custom status values](#customize-status).
44
+
-[Improve collaboration, quality, and accountability by assigning tasks and due dates](#tasks).
45
+
-[Handle escalations and complex cases by linking multiple incidents to a case](#link-incidents).
46
+
-[Manage access to your cases using RBAC](#requirements).
47
+
-[Add rich-text comments to provide links, tables, and formatting to the activity log (in Preview)](#activity-log).
48
+
-[Upload attachments to store files like documents, CSVs, and encrypted zip files containing malware samples (in Preview)](#attachments).
49
+
-[Manage cases in multiple tenants via the multitenant management portal (in Preview)](mto-manage-cases.md).
37
50
38
51
As we build on this foundation of case management, we're prioritizing these additional robust capabilities as we evolve this solution:
39
52
40
-
- Multi-tenant support *(now added, in Preview)*
41
53
- Automation
42
54
- More evidence to add
43
55
- Workflow customization
@@ -71,7 +83,7 @@ The maximum allowed per tenant is 100,000 cases.
71
83
72
84
Each case has a page which allows analysts to manage the case and displays important details.
73
85
74
-
In the following example, a threat hunter is investigating a hypothetical "Burrowing" attack that consists of multiple MITRE ATT&CK techniques and IoCs.
86
+
In the following example, a threat hunter is investigating a hypothetical "Burrowing" attack that consists of multiple MITRE ATT&CK™ techniques and indicators of compromise (IoCs).
75
87
76
88
:::image type="content" source="media/cases-overview/case-details.png" alt-text="Screenshot of the case details page in the Defender portal." lightbox="media/cases-overview/case-details-large.png":::
77
89
@@ -131,11 +143,11 @@ Share reports, emails, screenshots, log files, and more, all centralized in the
131
143
132
144
:::image type="content" source="media/cases-overview/case-attachments.png" alt-text="Screenshot of the details of the Attachments tab of a case.":::
133
145
134
-
To add attachments to your case, go to the **Case details** page, click the **Attachments** tab, select **Upload**, select your file, and wait for the upload to complete. The file is scanned in the background for malware. When the scan is complete, anyone with access to the case can download the file. If you need to upload malware samples, you can wrap them in password-protected ZIP files.
146
+
To add attachments to your case, go to the **Case details** page, select the **Attachments** tab, select **Upload**, select your file, and wait for the upload to complete. Once uploaded, the file is scanned in the background for malware. When the scan is complete, anyone with access to the case can download the file. If the file you want to upload is actually a malware sample, you can wrap it in a password-protected ZIP file.
135
147
136
148
## Related content
137
149
138
150
-[Microsoft Sentinel blog - Improve SecOps collaboration with case management](https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/improve-secops-collaboration-with-case-management/4369044)
139
-
-[Microsoft Defender Experts for Hunting](/defender-xdr/defender-experts-for-hunting)
140
151
-[Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
152
+
-[View and manage cases across multiple tenants in the Microsoft Defender multitenant portal](mto-manage-cases.md)
-[Microsoft Sentinel blog - Improve SecOps collaboration with case management](https://techcommunity.microsoft.com/blog/MicrosoftSentinelBlog/improve-secops-collaboration-with-case-management/4369044)
71
-
-[Microsoft Defender Experts for Hunting](/defender-xdr/defender-experts-for-hunting)
72
71
-[Microsoft Sentinel in the Defender portal](/azure/sentinel/microsoft-sentinel-defender-portal)
|**[Cases](cases-overview.md)**| Manage cases originating from multiple tenants, or a single case with links to items from multiple tenants. |
75
+
|**[Cases](cases-overview.md)**| Manage cases originating from multiple tenants. |
76
76
|**Hunting** > **[Advanced hunting](mto-advanced-hunting.md)**| Proactively hunt for intrusion attempts and breach activity across multiple tenants at the same time. |
77
77
|**Hunting** > **[Custom detection rules](/defender-xdr/custom-detections-overview)**| View and manage custom detection rules across multiple tenants. |
78
78
|**Assets** > **Devices** > **[Tenants](mto-tenant-devices.md)**| For all tenants and at a tenant-specific level, explore the device counts across different values such as device type, device value, onboarding status, and risk status. |
0 commit comments