Skip to content

Commit 9ea39e5

Browse files
committed
Learn Editor: Update app-governance-anomaly-detection-alerts.md
1 parent e1902c3 commit 9ea39e5

File tree

1 file changed

+7
-1
lines changed

1 file changed

+7
-1
lines changed

CloudAppSecurityDocs/app-governance-anomaly-detection-alerts.md

Lines changed: 7 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,10 +44,16 @@ Following proper investigation, all app governance alerts can be classified as o
4444

4545
- **True positive (TP)**: An alert on a confirmed malicious activity.
4646
- **Benign true positive (B-TP)**: An alert on suspicious but not malicious activity, such as a penetration test or other authorized suspicious action.
47-
- **False positive (FP)**: An alert on a nonmalicious activity.
47+
- **False positive (FP)**: An alert on a non-malicious activity.
4848

4949
## General investigation steps
5050

51+
### Finding App Governance Related Alerts
52+
53+
To locate alerts specifically related to App Governance, navigate to the XDR portal alerts page. In the alerts list, use the "Service Source" field to filter alerts. Set the value of this field to "App Governance" to view all alerts generated by App Governance.
54+
55+
### General Guidelines
56+
5157
Use the following general guidelines when investigating any type of alert to gain a clearer understanding of the potential threat before applying the recommended action.
5258

5359
- Review the app severity level and compare with the rest of the apps in your tenant. This review helps you identify which Apps in your tenant pose the greater risk.

0 commit comments

Comments
 (0)