Skip to content

Commit 9c1bd2b

Browse files
authored
Merge pull request #49413 from KenMAG/Bugs
Updated module per triage feedback
2 parents 66b639a + f6ca94b commit 9c1bd2b

File tree

5 files changed

+4
-4
lines changed

5 files changed

+4
-4
lines changed

learn-pr/wwl-sci/hunt-threats-sentinel/4-bookmarks.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ uid: learn.azure.hunt-threats-sentinel.4-bookmarks
33
metadata:
44
title: Save key findings with bookmarks
55
description: Learn how to save key findings with bookmarks in Microsoft Sentinel.
6-
ms.date: 05/25/2023
6+
ms.date: 03/06/2025
77
author: wwlpublish
88
ms.author: kelawson
99
ms.topic: unit

learn-pr/wwl-sci/hunt-threats-sentinel/includes/4-bookmarks.md

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -11,15 +11,15 @@ You can revisit your bookmarked data at any time on the **Bookmarks** tab of the
1111
1212
## Create or add to incidents by using bookmarks
1313

14-
You can use bookmarks to create a new incident or add bookmarked query results to existing incidents. The **Incident actions** button on the toolbar enables you to perform either of these tasks when a bookmark is selected.
14+
You can use bookmarks to create a new incident or add bookmarked query results to existing incidents. The **Incident actions** button on the *Hunt* toolbar enables you to perform either of these tasks when a bookmark is selected.
1515

1616
:::image type="content" source="../media/4-incident-actions.png" alt-text="Screenshot of the drop-down menu for incident actions in Microsoft Sentinel." :::
1717

1818
Incidents that you create from bookmarks can be managed from the **Incidents** page alongside other incidents created in Microsoft Sentinel.
1919

2020
## Use the investigation graph to explore bookmarks
2121

22-
You can investigate bookmarks in the same way that you'd investigate incidents in Microsoft Sentinel. From the **Hunting** page, select **Investigate** to open the investigation graph for the incident. The investigation graph is a visual tool that helps to identify entities involved in the attack and the relationships between those entities. If the incident involves multiple alerts over time, you can also review the alert timeline and correlations between alerts.
22+
You can investigate bookmarks in the same way that you'd investigate incidents in Microsoft Sentinel. From the **Hunting** page, select your *Hunt* with a *Bookmark* from the **Hunts (Preview)** tab. In the *Hunt* details pane select **Bookmarks** (or select any *Related incidents*), select a specific *Bookmark* and then select the **Investigate** button to open the investigation graph for the incident. The investigation graph is a visual tool that helps to identify entities involved in the attack and the relationships between those entities. If the incident involves multiple alerts over time, you can also review the alert timeline and correlations between alerts.
2323

2424
:::image type="content" source="../media/4-investigation-graph.png" alt-text="Screenshot of the investigation graph page for a deleted virtual machine incident.":::
2525

learn-pr/wwl-sci/hunt-threats-sentinel/index.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3,7 +3,7 @@ uid: learn.azure.hunt-threats-sentinel
33
metadata:
44
title: Threat hunting with Microsoft Sentinel
55
description: Learn how to proactively identify threat behaviors by using Microsoft Sentinel queries.
6-
ms.date: 05/25/2023
6+
ms.date: 03/06/2025
77
author: wwlpublish
88
ms.author: kelawson
99
ms.topic: module
88.4 KB
Loading
43.8 KB
Loading

0 commit comments

Comments
 (0)