Skip to content

Commit dafb889

Browse files
committed
Added XDR topics from xls part 2
1 parent 5115567 commit dafb889

File tree

1 file changed

+77
-15
lines changed
  • defender-xdr/unified-soc-platform

1 file changed

+77
-15
lines changed

defender-xdr/unified-soc-platform/TOC.yml

Lines changed: 77 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@
1111
- name: Service integration in the portal
1212
items:
1313
- name: Microsoft Defender XDR
14-
href: /defender-xdr/microsoft-365-defender-portal
14+
href: /defender-xdr/microsoft-365-defender-portal ## Placeholder article
1515
- name: Microsoft Security Exposure Management
1616
href: /security-exposure-management/get-started-exposure-management
1717
- name: Microsoft Sentinel
@@ -20,6 +20,8 @@
2020
href: /azure/sentinel/microsoft-365-defender-sentinel-integration?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json&tabs=defender-portal
2121
- name: Experience in the Defender portal
2222
href: /azure/sentinel/microsoft-sentinel-defender-portal?toc=/unified-soc-platform/toc.json&bc=/unified-soc-platform/breadcrumb/toc.json
23+
- name: Connect Microsoft Sentinel to Microsoft Defender
24+
href: /defender-xdr/microsoft-sentinel-onboard
2325
- name: Microsoft Defender for Cloud
2426
href: /defender-xdr/microsoft-365-security-center-defender-cloud
2527
- name: Microsoft Defender for IoT
@@ -62,42 +64,82 @@
6264
href: /defender-xdr/secure-score-data-storage-privacy.md
6365
- name: Detect threats ## Have each writer provide article and then we summarize in one article. Our outline and scope should align to datasheet: "Get visiblity into, and disrupt attacks in real time across identities, endpoints, email, cloud apps, data in hybrid and multicloud environments"
6466
href: /azure/sentinel/threat-detection ## PLACEHOLDER LINK
67+
- name: Hunt for threats with advanced hunting
68+
items:
69+
- name: Overview
70+
href: /defender-xdr/advanced-hunting-overview
71+
- name: Advanced hunting in the Microsoft Defender portal
72+
href: /defender-xdr/advanced-hunting-microsoft-defender
73+
- name: Guided and advanced modes
74+
href: /defender-xdr/advanced-hunting-modes
75+
- name: Generate KQL queries with Security Copilot
76+
href: /defender-xdr/advanced-hunting-security-copilot
77+
- name: Build hunting queries using guided mode
78+
href: /defender-xdr/advanced-hunting-query-builder
79+
- name: Work with query results
80+
href: /defender-xdr/advanced-hunting-query-results
81+
- name: Take action on query results
82+
href: /defender-xdr/advanced-hunting-take-action
83+
- name: Hunt for ransomware
84+
href: /defender-xdr/advanced-hunting-find-ransomware
85+
- name: Learn the query language
86+
href: /defender-xdr/advanced-hunting-query-language
87+
- name: Get expert training
88+
href: /defender-xdr/advanced-hunting-expert-training
6589
- name: Investigate incidents ## could be incidents, threats, posture findings. Need an overview article for USX. Current overviews (XDR/Sentinel) don't appear to be updated for USX.
6690
items:
6791
- name: Overview
6892
href: /defender-xdr/investigate-incidents ## Would need update to apply to USX. Per Dianne, this isn't XDR specific.
6993
- name: Alerts, incidents, and correlation
7094
href: /defender-xdr/alerts-incidents-correlation
95+
- name: Manage incidents
96+
href: /defender-xdr/manage-incidents
7197
- name: Investigate alerts
7298
href: /defender-xdr/investigate-alerts
73-
- name: Hunt for threats
74-
items:
75-
- name: Advanced hunting
76-
href: /defender-xdr/advanced-hunting-microsoft-defender
77-
- name: Microsoft Copilot for Security in advanced hunting
78-
href: /defender-xdr/advanced-hunting-security-copilot
79-
- name: Learn the query language
80-
href: /defender-xdr/advanced-hunting-query-language
8199
- name: Investigate incidents in Copilot for Security ## This article is specific to Sentinel in the context of using outside of USX and with XDR in USX. We don't think it applies to Sentinel only but need to confirm with PM. Austin thought title w/o mentioning Sentinel is misleading. We might need to leave this out of TOC or as part of plan/deploy to integrate Sentinel w/ Copilot features.
82100
href: /azure/sentinel/sentinel-security-copilot
101+
- name: Investigate with Microsoft Copilot in Microsoft Defender ## Copied entire section from XDR TOC
102+
items:
103+
- name: Overview
104+
href: /defender-xdr/security-copilot-in-microsoft-365-defender.md
105+
- name: Summarize incidents
106+
href: /defender-xdr/security-copilot-m365d-incident-summary.md
107+
- name: Run script analysis
108+
href: /defender-xdr/security-copilot-m365d-script-analysis.md
109+
- name: Analyze files
110+
href: /defender-xdr/copilot-in-defender-file-analysis.md
111+
- name: Generate device summaries
112+
href: /defender-xdr/copilot-in-defender-device-summary.md
113+
- name: Use guided responses
114+
href: /defender-xdr/security-copilot-m365d-guided-response.md
115+
- name: Generate KQL queries
116+
href: /defender-xdr/advanced-hunting-security-copilot.md
117+
- name: Create incident reports
118+
href: /defender-xdr/security-copilot-m365d-create-incident-report.md
83119
- name: Investigate entities
84120
items:
85121
- name: Overview
86122
href: /azure/sentinel/entity-pages?tabs=azure-portal
87123
- name: User entity pages
88-
href: investigate-users.md
124+
href: /defender-xdr/investigate-users.md
89125
- name: Device entity pages
90-
href: entity-page-device.md
126+
href: /defender-xdr/entity-page-device.md
91127
- name: IP entity pages
92-
href: entity-page-ip.md
128+
href: /defender-xdr/entity-page-ip.md
93129
- name: Respond to threats
94130
items:
95131
- name: Overview
96132
href: /defender-xdr/incidents-overview
97133
- name: Prioritize incidents
98134
href: /defender-xdr/incident-queue
99135
- name: Automatic attack disruption
100-
href: /defender-xdr/automatic-attack-disruption
136+
items:
137+
- name: Overview
138+
href: /defender-xdr/automatic-attack-disruption
139+
- name: Configure capabilities
140+
href: /defender-xdr/configure-attack-disruption
141+
- name: Review remediations in the action center
142+
href: /defender-xdr/m365d-action-center
101143
- name: Optimize your security operations
102144
items:
103145
- name: Overview
@@ -108,12 +150,26 @@
108150
href: /azure/sentinel/soc-optimization/soc-optimization-reference
109151
- name: Manage your unified SOC ## Need article w/ overview about settings? What else needs to go here? Several other things like permissions and costs would get referenced by planning guide.
110152
items:
111-
- name: Manage multiple tenants ## Work will start soon to integrate Sentinel into one or more of these articles.
153+
- name: Manage multiple tenants ## Work will start soon to integrate Sentinel into one or more of these articles. Copied in entire section from XDR library
112154
items:
113155
- name: Overview
114156
href: /defender-xdr/mto-overview
115157
- name: Set up multi-tenant management
116158
href: /defender-xdr/mto-requirements
159+
- name: Manage incidents and alerts
160+
href: /defender-xdr/mto-incidents-alerts
161+
- name: Advanced hunting
162+
href: /defender-xdr/mto-advanced-hunting.md
163+
- name: Multitenant devices
164+
href: /defender-xdr/mto-tenant-devices.md
165+
- name: Vulnerability management
166+
href: /defender-xdr/mto-dashboard.md
167+
- name: Manage tenants
168+
href: /defender-xdr/mto-tenants.md
169+
- name: Manage endpoint security policies
170+
href: /defender-xdr/mto-endpoint-security-policy.md
171+
- name: Manage content distribution with tenant groups
172+
href: /defender-xdr/mto-tenantgroups.md
117173
- name: Configure notifications
118174
items:
119175
- name: Get incident notifications
@@ -124,5 +180,11 @@
124180
items:
125181
- name: Threat actor naming
126182
href: /defender-xdr/microsoft-threat-actor-naming
183+
- name: Identification of malware and unwanted apps
184+
href: /defender-xdr/criteria
185+
- name: Submit files for analysis
186+
href: /defender-xdr/submission-guide
127187
- name: Microsoft virus initiative
128-
href: /defender-xdr/virus-initiative-criteria
188+
href: /defender-xdr/virus-initiative-criteria
189+
- name: Microsoft security portals
190+
href: /defender-xdr/portals

0 commit comments

Comments
 (0)