Skip to content

Commit f23d1d8

Browse files
Update custom-detection-rules.md
1 parent 2bc228f commit f23d1d8

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

defender-xdr/custom-detection-rules.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -58,7 +58,7 @@ To manage required permissions, a Global Administrator can:
5858
- Check RBAC settings for Microsoft Defender for Endpoint in [Microsoft Defender XDR](https://security.microsoft.com/) under **Settings** \> **Permissions** > **Roles**. Select the corresponding role to assign the **manage security settings** permission.
5959

6060
> [!NOTE]
61-
> A user also needs to have the appropriate permissions for the devices in the [device scope](#5-set-the-rule-scope) of a custom detection rule that they are creating or editing before they can proceed. A user can't edit a custom detection rule that is scoped to run on all devices, if the same user does not permissions for all devices.
61+
> A user also needs to have the appropriate permissions for the devices in the [device scope](#5-set-the-rule-scope) of a custom detection rule that they are creating or editing before they can proceed. A user can't edit a custom detection rule that is scoped to run on all devices, if the same user does not have permissions for all devices.
6262
6363
## Create a custom detection rule
6464

@@ -155,7 +155,7 @@ Selecting **Migrate now** gives you a list of all compatible rules according to
155155
:::image type="content" source="media/custom-detection-compatible-queries.png" alt-text="Screenshot of the continuous frequency compatible queries in advanced hunting." lightbox="media/custom-detection-compatible-queries.png":::
156156

157157

158-
Once you click **Save**, the selected rules' frequency gets updated to Continuous(NRT) frequency.
158+
Once you click **Save**, the selected rules' frequency gets updated to Continuous (NRT) frequency.
159159

160160

161161
###### Queries you can run continuously
@@ -263,7 +263,7 @@ Only data from devices in the scope will be queried. Also, actions are taken onl
263263
After reviewing the rule, select **Create** to save it. The custom detection rule immediately runs. It runs again based on configured frequency to check for matches, generate alerts, and take response actions.
264264

265265
> [!IMPORTANT]
266-
> Custom detections should be regularly reviewed for efficiency and effectiveness. To make sure you are creating detections that trigger true alerts, take time to review your existing custom detections by following the steps in [Manage existing custom detect ion rules](#manage-existing-custom-detection-rules).
266+
> Custom detections should be regularly reviewed for efficiency and effectiveness. To make sure you are creating detections that trigger true alerts, take time to review your existing custom detections by following the steps in [Manage existing custom detection rules](#manage-existing-custom-detection-rules).
267267
>
268268
> You maintain control over the broadness or specificity of your custom detections so any false alerts generated by custom detections might indicate a need to modify certain parameters of the rules.
269269

0 commit comments

Comments
 (0)