Skip to content

Commit ef7c267

Browse files
committed
fix image path
1 parent 7b63437 commit ef7c267

File tree

1 file changed

+8
-11
lines changed

1 file changed

+8
-11
lines changed

ATPDocs/understanding-security-alerts.md

Lines changed: 8 additions & 11 deletions
Original file line numberDiff line numberDiff line change
@@ -27,12 +27,9 @@ Alerts from the last seven days are displayed with the following information:
2727
- First activity
2828
- Last activity
2929

30+
:::image type="content" source="/media/understanding-security-alerts/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
3031

3132

32-
:::image type="content" source="ATPDocs/media/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
33-
34-
:::image type="content" source="ATPDocs/media/understanding-security-alerts/filtered-alerts.png" alt-text="Screenshot showing the Alerts page in the Microsoft Defender portal, filtered for new alerts from Microsoft Defender for Identity. Two alerts are listed with the name Suspected brute-force. Each entry includes columns for severity, investigation state, status, category, detection source, impacted assets, and timestamps for first and last activity." lightbox="media/filtered-alerts.png":::
35-
3633

3734
## Customize the view of the alerts queue
3835

@@ -74,7 +71,7 @@ The alerts page provides context into the alert, by combining attack signals and
7471
7572
To view alerts from both Defender for Identity and Defender XDR, select **Filter**, then under **Service sources** choose **Microsoft Defender for Identity** and **Defender XDR**, and select **Apply**:
7673

77-
:::image type="content" source="media/filter-alerts-menu.png" alt-text="Screenshot showing the alerts filter menu per service.":::
74+
:::image type="content" source="media/understanding-security-alerts/filter-alerts-menu.png" alt-text="Screenshot showing the alerts filter menu per service.":::
7875

7976
### Microsoft Defender for Identity alerts
8077

@@ -90,7 +87,7 @@ At the top of the page, there are sections for the **Accounts**, **Destination H
9087
- Move alert to another incident
9188
- Classify an alert
9289

93-
:::image type="content" source="media/legacy-mdi-alert-structure.png" alt-text="Screenshot showing the Defender for Identity alert structure." lightbox="media/legacy-mdi-alert-structure.png":::
90+
:::image type="content" source="media/understanding-security-alerts/legacy-mdi-alert-structure.png" alt-text="Screenshot showing the Defender for Identity alert structure." lightbox="media/legacy-mdi-alert-structure.png":::
9491

9592
### Microsoft Defender XDR alerts
9693

@@ -103,7 +100,7 @@ At the top of the page, there are sections for the **Accounts**, **Destination H
103100
- Move alert to another incident
104101
- Classify an alert
105102

106-
:::image type="content" source="media/defender-xdr-alert-structure.png" alt-text="Screenshot showing the Defender for XDR alert structure" lightbox="media/defender-xdr-alert-structure.png":::
103+
:::image type="content" source="media/understanding-security-alerts/defender-xdr-alert-structure.png" alt-text="Screenshot showing the Defender for XDR alert structure" lightbox="media/defender-xdr-alert-structure.png":::
107104

108105
## Manage security alerts
109106

@@ -115,18 +112,18 @@ You can categorize alerts as New, In Progress, or Resolved by changing their sta
115112
### Move an alert to another incident
116113
You can create a new incident from the alert or link to an existing incident.
117114

118-
:::image type="content" source="media/move-alert-to-other-incident.png" alt-text="Screenshot showing the option to move an alert to another incident.":::
115+
:::image type="content" source="media/understanding-security-alerts/move-alert-to-other-incident.png" alt-text="Screenshot showing the option to move an alert to another incident.":::
119116

120117
### Assign alerts
121118
If an alert isn't yet assigned, you can select Assign to me to assign the alert to yourself.
122119

123-
:::image type="content" source="media/alert-state.png" alt-text="Screenshot showing the Alert state section in the Microsoft Defender portal. The Classification field is marked as “Not Set” with a link to “Set Classification.” The Assigned to field shows “Unassigned” with a link labeled “Assign to me.” This section allows users to manage alert ownership and classification." lightbox="media/alert-state.png":::
120+
:::image type="content" source="media/understanding-security-alerts/alert-state.png" alt-text="Screenshot showing the Alert state section in the Microsoft Defender portal. The Classification field is marked as “Not Set” with a link to “Set Classification.” The Assigned to field shows “Unassigned” with a link labeled “Assign to me.” This section allows users to manage alert ownership and classification." lightbox="media/alert-state.png":::
124121

125122
### Add comments to an alert
126123
You can add comments to an alert to provide additional context or information. This is useful for sharing insights with your team or documenting your investigation process.
127124
Whenever a change or comment is made to an alert, it's recorded in the Comments and history section.
128125

129-
:::image type="content" source="media/comments-history.png" alt-text="Screenshot showing the Comments & history section in the Microsoft Defender portal. A text box is provided for entering comments." lightbox="media/comments-history.png":::
126+
:::image type="content" source="media/understanding-security-alerts/comments-history.png" alt-text="Screenshot showing the Comments & history section in the Microsoft Defender portal. A text box is provided for entering comments." lightbox="media/comments-history.png":::
130127

131128
### Classify security alerts
132129

@@ -145,7 +142,7 @@ Following proper investigation, all Defender for Identity security alerts can be
145142

146143
- **False positive (FP)**: A false alarm, meaning the activity didn't happen.
147144

148-
:::image type="content" source="media/classify-alert.png" alt-text="Screenshot showing a Microsoft Defender alert titled “Suspected brute-force attack (LDAP).” The alert is labeled with severity Medium, status New, and classification Unknown. Below, a classification banner includes a message to classify the alert, with buttons labeled “True alert” and “False alert” for user response." lightbox="media/classify-alert.png":::
145+
:::image type="content" source="media/understanding-security-alerts/classify-alert.png" alt-text="Screenshot showing a Microsoft Defender alert titled “Suspected brute-force attack (LDAP).” The alert is labeled with severity Medium, status New, and classification Unknown. Below, a classification banner includes a message to classify the alert, with buttons labeled “True alert” and “False alert” for user response." lightbox="media/classify-alert.png":::
149146

150147
> [!NOTE]
151148
> An increase of alerts of the exact same type typically reduces the suspicious/importance level of the alert. For repeated alerts, verify configurations, and use security alert details and definitions to understand exactly what is happening that trigger the repeats.

0 commit comments

Comments
 (0)