From 9b01bc6b182d1e47f808e67d97d7367fe80e2c8d Mon Sep 17 00:00:00 2001 From: Liza Mash Date: Thu, 29 Mar 2018 07:19:46 +0000 Subject: [PATCH 1/3] Added advanced-hunting-save-query.PNG --- .../images/advanced-hunting-save-query.PNG | Bin 0 -> 43225 bytes 1 file changed, 0 insertions(+), 0 deletions(-) create mode 100644 windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-save-query.PNG diff --git a/windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-save-query.PNG b/windows/security/threat-protection/windows-defender-atp/images/advanced-hunting-save-query.PNG new file mode 100644 index 0000000000000000000000000000000000000000..503af3860f82bdc03f46f14ea384324d9d98271e GIT binary patch literal 43225 zcmeFZcT`j9*FQ>8VL$;LDM|_ULK6#}1aTA<1$9(9C{a*>1f+zT;0Q8`5S2kdN(LE3 zMQS7g0z`ul5g{N_LI^Pi2rUUAq!E(*;*5UZdGA`kKkmDJ_pbZL&4QJ4PR>)#e)jX( zpS_>`oV#Z{+}3Gq)=*MXT6g03FXxn$*61iHsQ}g2D6Rw`Tuv*#l%vnNxhhrn8qFw9 zR)roueOO7U4yn0vd9~vFr^w?z(Mn32hQ9qP8}xr*DJeaNocQJN`S?JVl#1RyoPrWV zkh}ich~ihr9^eb!~XMe(N-Y{%xQY*~26BzIE7)nnO9?i+s6p#Z5J> zTL`x^YMznn15@TB?Uv|C?b*lFRnh{!&T8sdjw8%lBstnPNR5`LJ^qPhV$k=p{^j$R zQWug%V-l_OLSTxb1CTmg+yH-VAp1u2v@@ zEL%8zID&C#s2st&6*<39y3j^)4kA&0TBVLlQ~Dw8zEGk{8XDGOW|TN=yk$ylOUovc z<#)04J_%4i&fN8HX{`F*9T$|bhEDGt$MM+RExTT@@#4N+gjkmDPn8Q(-E=dQt;x^|(uX8-IO(8fVHW}F*0L!O7!7Nb-nPxa5&@#DZa_j(qxd#97E})gAxn>`g&8pT?%Nm zHUh?MUlF)**1}MU$(UBMjg`}8woC-g*p{J{;m39w)?PoVL?4T$k0Zx)vK4o>7w~#PQB8iIk zNnMy~S|F2c6ipM`nFCQRQYpI5z<~Hor+Rt|kz;27?LQ*}pJSz>yxA1TnD%hgqo@QP zj-G3Wm>LGAMBBy8QTdBmHOa94?yJg#@(hqM#Qr8YUd}>kSD4fc;}@o>gH4Ik3l?Y| z*z^|zI};wbsf+tv>Z!&dYAR`TitYv43VvpQ9>Z&VKdIJEgxGC_h~BrBu1vDr>2y!p z21v`~Yh5!6|eaKH)1aeEn+Mf*q#OkF6AoFB=eKPDAf1YVDvk(HtAI40SjevbGZ z@s#57v%W!W%621mN;|&X(lkhTH{(P4c(*VeX#_L^-lQ!q$|jRQMv2Ogt~Z8G9zlQ}{D>ZsPqGmYW{#bsye&Zh2* zywLueLdmoM8g3j<{brSab$Oj?+9YkE=3YYvqjjp9U)Pzob4;JGlDJZ>b95l?k$_|72r2R&r`FaeGqLzG>k z3-kNU)L%l!^YUJ_y}-}gZtxui?CY)U(nn@!Z^Zv3|7L|QiiU)Sc`pI`+T?7*1Nk-4WZSdV=J;i0VG_&c|} z@mQsvK4XvDU}|ps+%+|FN4DDc89KkuaJBj%R_=Io{<6E*o>#u=)duF{!(NA%AUWqP zK*@!Lw!J8IEMlRU{{9uzZ5;k<<4h}FAA(~c2}}+ir~PP?~(Sz zZV?aRg4SBKHQvk916^qezSVXt^#PipOvtq}`QB`8d$^A2XW9aujRBc$MB@TQD;b1R zf^98qr_1l4*oB9RY3}Bl`0xl{qRf$uy~<0m1c|tj47wp9gDpB2zlfVO{IoH%qi~J7 zI~0*~PXAFR$fI?wvTOQ(j4XyEP)&Q84-a^c2yHyh2X{&VfNF$6LI+{?h3B2QJNJZ8 z;6`9nfC9}2=mWOvsJ<`6hbf*YlRZ;GT0(eysA}45Mz&WYRQ_8u{eUfU#bwE0P@7xb zM>-y>`P|IN^gKS4d#l#m@I`01#{cEn99^Eb(eaB&m0|3r*?{$DbSJzdQRJ7?j_1;x z`CW5UcuA z#$x0>K0(?+GfJ1s0lIAl*@#PVYoFSUk7F5?l(qbO z9Dc+DEre)1@^}Dpc zSxPTU5kA4vNZzNwU!<|$xt1EuC4gv*OO6}Yy%RRTNMCW+MmUTu`k}N?K;PYZ(2b^P zk>a<=LCJCfIuqd38_&p!=`Hv9)i&)&2J|ObiQ#i6y!fW*LorGtsIkupk|2v0y$NrD z=Ch92!y7l6EKlItvj7rr(SokF&ZwDp_MKpx#ZK}>0Y`x8 z$M|J5{V~<)U+TNf+-FhC7u}0&rf>UYS-f2ixS`Mj(Aj zGf&xdY?#TGN)>9~PH*-DngHcr%IL2ABLn(`GHp0;O!gLbXPelD=A;jljBlg&(GA-r zP+2%|Db}}liW73^5_cjiMzi;5=p`Y{xaNI)aE6>xfpQl_+JaVnZFqYOmZZ5Rj6QJ8J# z0KC#zTP>Xs|3p#mLK5c{Hc8YB%K!^G@Kl`{W8@7K!fK`e?o#}#gjnq#u&P3lt-q>- zbK$EFn5CWnfqLEQI;qlk-{42fc%4vtW#XH!`0eArXO;RJ;Mb)JsPBy6)IZmhYAN4t zCzO9P#x(-N|0v(L%VuwFNhHLdxcB85?G;daBdylC0s3o-{&)K_qW1SaszgF*`*6A+ zFfp`I@|i*J&<}dm@?WI#eQBhKidu`{)-Qc;@{PGzW=$O`Ttk` zL!kf7{r;be1*xDXZV;)2&XG&2vA|Csiw;`dVL+)w$@2TER>tBG!^-A>ZTYycIP8aB z*8&slrKqsM*6I;+AZN|opI_rIEJ-B@c@>=| z#gQ3T$VbmM)wZU2pb7G9^CM#IE1;OBJuQP}co-s_r( zElIQ?I8R!sF?r%_($dK1j)jBa&)aj@@vnJ2hUon^mfW4V$5D@L-w(k#RihKImVy^I zDyhUk$DWnfLB+i5#}4hhE^n4Nw*;jFdohT);EHC3S40Iqc|7QQ-$tPG$5YSf=i_M4 zdo^nxHu^ihI0!1gfwsd3<+DFoEa+i>-CG+f**IL8`KFwud+)vE?z3yffSkwu;9t!l zLe*T4QfEWllUquqwbX>Vlwv|+bNJ=fWWQq8$M*oQ?aa3ea0`&2I6}X->Kx+xSYE={ zm0|at)U2p;q3j8^jng23FN|#B**L5oId>T3F$bxLXl^Wi_1w=Qrz&XEuo;`9tgbU9 z@j{*+9ac2EH$D_xqEFLj%aOWhsn^=ql?EVPy*hdWy38 zBx8@u_eYIX8tFvt*48HtJZ04fM+SZ|F7w6ws^h6SAZ9@1_b6SN&0OxKpyl+1MBjw9 zg4N~HZVkq5;!Z!z)4lQ9YUAM-Ma764{iGV0UTl~H9^dDPMHT~-1&2gx8v z&cirRdL_o|O}{s3rxd=;CI76hi)8hP2mQ5gNTaF0+_|)L8vVHb_hm!zYzp#oT1dfACc857ugR-PnFiH05#2ZeQK& z8BqLk+C27NV-Dn&oo4UNY z&<;U>;aJKK2jo?jlCt}INEe#%nN>lP{kS~utg`A#40QN)A(mV~+xb2s`McaN(f&7K z$p1MG{`VMXzJVuxxon}MqK%|F0UH;ci2h+5FUd_^@(u9Z0(}BPdTUogYBHOThh+b- z%kzL$>OV8u5rP|{Ao;{m6VrfOKl%*X>hk?i>HiRR|Mx!sf2VRkkm#+piuSWzo+aiU zyG}gX{_XGPudCJ7yp>gcoMJbc8eLkg{`YT>ws%p_rADUenm+h`4s%x~C|^u<`KRoo zF^m6q3&)|A=rhI3pPDCRaaBt6Iug(rGcLX&!pq-A|CW~WWlEVaK%XXiwfAcmYr4r^y*~97 z6`<}1NVIf{6EsEk_$m|h+xw3w+~+2@cKyt5uBoAF+E@FSncRhkw3Ktdf0v_)%doc2 zI1IQli@%F)BX^mWS_Z@LP4j;2?lGY*QlL66!6`gpN!p&xbJqT}=wlu45QTzb$ zaD852OIzQ&@i7AuzjG{#R~osL$!E-Zzp|DEIVJ8MOC}b4Z85t#$Seyo@7?zIC{NTX zjCS4cE4MirUcJc&T0)7xrNP(Zns=ORsEVtgzMO-_xF11{GpSmz&{*&SSyQdv|geaG>M*p|k1Lrc4a*l}V9W3V-T7TI1Q zTk>!8&-YqdY+9&5Ei)o#gD;O;`f2E#WS%dQ@$gN{gX)8Izls7*C=+T`R{gDuU96_d zseR4YAJm$=c$@5dN0>N-N~!a$mOkUfpLNpf%ee}|jSEJvj`Fdxg${B3pq-Q+-Lq2B z&RM~U;;j*FAMbd1&tFMh2$IXvBir$YTp`LACrmE*Cr6-qEhvu=U-- zmv-AbG%*Oj*)n&EQ$M##-L0*0)*@?>cj>+P@3Skt$C8}p5R|J^OzIi$Ln1$8YJ_oX znbyPEtD5P8omW0c2C8X}wuPy4ec^bdaW|<)CiX6DD9HAateAz@gxfqGTqMI|J6|~; zn@OaChk(0YGK0~lWXV;6ur@dlM8ntV)cDk(X+10D5|4i*Hl_$P`(h2ZPppcdChlCOts**O`?kxA(vTwH- z(P~f+yfxgf_S8@oFX`yuwaesJ2BSZ%O5~vl*RO`7XWVP- z#!y3=8;4?ZbuJ^@Z%;cY6P#iS6Qn3%UV-0cT1hP3!I%Mg*lGdX#XLL+ku)N**8ALabj8nWp->`g4QBUAf))qcW@ah`Xob{-df zvTY0Uu5PgSg5B96ydsM{jJG^xsj=LTaTy1CghPor9%idn-KLo7_Ja$1F02`}yXs{W zvyAQ8n#}H9rCy$}4f0u7sxnXTxLmvET&D^+aNnun7pFBJWDVAfmmt{6Z5b=vIs7`~q|>$l1^>Mz{$_GCjtD)OnDiLDkzFeEI@H=I+V zI@4TG9ud3jJ#x_j{~A=+6GD+jTWhX-d{<@;nk(*#?Q zBZW*>Dn0*&gTY=&vNk{7cGMX=6J00W{`z+wE`?g+sBh}86(s+pNskt;6Xm*R@@>|F z^g3GM^jberCJ%hMUWyHX6hBRV(YUF?0z- znc!`Wuk$zPMP6=laRv>4V%XjMc#kq$q?#Tv86hM*FF0{#C=9e`2)68BD_@!62>a{} zEp*4j(3r<-)MNcviyd)HhEwEyN6K@`^nD*kk5=g>;P??@?mqzD&c2pf3yRkCY#+kJ`Q_{N;P)4DAHO$iGxezOIROe!~Kc)EWauEeD z8>;ocjz{Th%_Uqft=pS#;yj9TK6~Mm{|f_e{htS}R=R#|(LMk!-M`0WidRV_3z%AZ z;JFlBf_d^t_UYdvmo!Oty7N%$g6x_>gxk~XRqEiQtjelzwP=T%zx8MSS(yZGJDrqlS zF-enxJ6JD}N%OrwjZ6=EnIu1Vf;zHeQgw)oPnk6t%)k>6+uX4yFK!kqmF{I9q8UI= zX{KM;5((s7vwNa1d%{oZ=y*1rkD-|Tp=F-LGY*>9HLv{o^&Zd6?OtAS?6G?t6wFWS zA#DlrG_`)Gwcb07yss9B?f=k4kjA23@A1vMUC}XOO9VOV6+cDnXH6L_-#0>!i$_ZQ zGBM5Rv&nF2{ItLE-Y>)%>-)YJm5>zn>i|}$?-+mvkCI=Mu1ot1O65XPpssi?iqBG| z%<+KE@>sehw_62kdbj+;RV-m;N|$+G{)|2Q#-qZEQm9`Ee(R{mE%VGM zLkwA5snIq4rBLVc^VX}Bx!#%x3239~((TNiF(;S!y(@EW!QQn7@^L%J2Ge}!i- zSXQ#N)uoCQ9~(TzSwBN14SpH%CV}=yTIrhBff=IUkpN=lNJ%>$QqjpCG*5LCin8Z4|5U(PxY`wFD2np6+XFr;M1p zh~RcoK#3N9!OAL4zVNPNL57I6Tp_{mChSI*zX&Rqc0|$%a}6-i&lpIOB2Ms)1ev)Q zVE4ugGN1fvb4U4l{^K<_j#QhNhJSrY#O+BF{+7N&Yhx|!vsqnM1gDOIA| zqSoT~l`DihteVE9m_!hJRMM{fy!A>tZBj$$1BPblb%shd)3J$aU{G86eVf^dQFykz zI-sY%?uY%}gNsYu*QBUIUo~y{;wfg_JXYJ+R$J#imHTFuI*S$MfOYn54^YffES)@z z9bf;QlX{R9x}1mSE-(FdTlJOFEy4iC3{LWc({{0%FQ&ecmMh)*M_k*R6jVa% z2XQ#@Xacgw#qN!U&hhW07FVuBS2Fv~aJHXdKUPWmR`LHsh5sQ^iprg_|H^onb3*wOMO$M@?wkvMLqx;h@(*lyJYM=+imn30^}Zq$=&NPmc%V`1p=v}*W2GHJJ9!Zk*#n;?>0*G-Bn;?Tb^&9!mxN7; z?R`+`EsZEB#^Gekz6)>XDw#dHDOFjN7DCMl$JxO9WXu2RPh4swcdRRNabhNteltOq z->MCDzxU|EJlby)9;)Riu+j1$CrHJbOUtw9(`L)gjZB*tstq{?9xo@-fx1b zk26#zxYNhFa_D2}n)D^D)#}{#iG_?lk#cg+Z|^Pj5OMfMJf&kvI{jLhAWLY51T2XqNWlFg103(xK9~lf@c3k2gADcw3Tuwv;^q;7^R@ zr#xVdYy2gl;}t7W9kHkeW|o!C*dOc|77D!K0kWwupf zo8Smxd}kceDPIs~jYs#q^WY|SaW|u*&3XJ_Tom9_8!2y(aYnLlvuFQeyfBl?Pb?ew z1iT6k5`r;RG5(8J9f;sd1;2@#Kv?5ELDK~z^f|-1;@kZ#+B_}%pLY}l(tHH2;bfxRp!PV z@Hi-`{Yv|gMKqUF9%cKCLFCZSPiZrWRWpm-*~C70Rb)xee2IJ#{;d1+T=kG(e+CM~ z=b9_l+khb#5Dcz+cIdLuiVAT^fy9|iNe+r^!7r#$W(|gt907C?;|MOWqv7rJ(AME7 z+v0?B8^!Y!uW4&_;1FUE4WHQ6EKa`aHZc<+|PKChkpB%u1{%4#k z4@T{P?RLr6*L!qbQy;Lio2T~b-a4_`*P-Rx+^0RuQOqML%@BV4S@jpd&ljatlE*^l zUfNIwx#f&4mgO!xY)_MYRYkNy#fyxK#4UTymjkA>CwWDGlh9@Q)VA50LJ~~Et zWg9c=5-R4z^UAxW<&ZGVtv z1W^GWPxQ{{n)91(cI8hJ+wdqxwxEG3NKQ(Zp27@*fY)*2{DuJyqUj+=wHtX(ws~3P z4a8pbtb8y(CV-zn6I89N>_vG+Q1}>z_ve91U@vJn+;_mkzakI;Bbq}FP%GF50wnKg zP|xcdNt3)<%0-@?Bd3#y$4i^gERz#M79|6$M!l(;7%go(*~;~7X7Z_7Vlgk|%Ewt| z?0ye2?e5Ux$W_V*Qu;$yHAEcyj0K}q$l|TgW00%7mV9KC%}&O*vEkmp7CY01$QKW_ zm8TetV0E+I8d|@$9Ym--vi6jGGL*0QkG%Pmbm1EkU143k{`DmLc=Tj%F>l&qwex#t3R(ZotQ7zIqx5`p>;BN2B?nM#pHb#`!Xy5+LK>NLBQUV>cg82HkR<_r zzn@L^iR*wQur3Q)fzDd--y?_}yNL?5+=Oln6xux|{uS;YH|><~6M=I?^pi%A;f}3s zaV!o)BgLYjX}+oH%Ex0>Lp_quoKP-jRHM_{AQ7TVIn_(-5bcl_kgQI-50QJU%?g%E z55ilcOR>_JWfAvz=Rp8ATguXY!Y><+t3idmrbdx@p|`CIeTv=9me9i?2TgGEMl5r$ z2-xlDvif8=KhXA=pl<$s0>yq;*-XB#$a; z>AyE!mt(NV4#v2n=OX+sBtxDPp--w?v^H=+@^~*B<>idP5sy$qALWWsVW1&Hi=UAE zaaPV`zWqRabtCBt`D;G5I$kT3hm&{%;l}PMyN%0Yn)Cp=~%BdL~_=t_W)6T z@fq{@CzN>Q)9Wk6R3r2Uf_NV-5V4ZTOo|%Ic*bPKqST~7Ar@b|WaJwTT}ZHpy<%Bw zG6uKqQvcYw9R8;o6s~Li*l>gXVzw*0gO{&U-c;{O(}04@zU; zBx3kt)Pfz!NbXlqU3lM*S=3vxV{U#b|4?^a3FidhB(cd>tDND4YFmkqVNOa-fTUoM z1Gt0_o{t}_j?~f*z>I$rrAUaqbX|Ti0NY@D$IJ(aPo$WTiS^r<5zM0d&%iBI#)tz( zw#Ynp=uTJIadD9!%ihPqq@5U(ZbOO6BnGn>PT~IzkZsrLJWkdL!d~l(dd0dCxU75# z-WTXpjVY`y)NOvL-F_OM*e#gHv_3g9_jy1cFfpe+nn?t&zCBreF6M5xQ9>l9IJxP@ z{X1CW;kk{biRn4)#%y0>JYR^82l9J!T)A5<56p$Fly#C(%Sc(oaEz23 z{|A#~e*eOZcLil+x@o|>;j9DT@qO|l^IhYh!DEaeD*`vS7@K2V*-Kt&oFKjUtpjMD z08v0gl$RrE4RUxtu>^MkKL8(+kb!|k(OqIYP>}n;Vr(4jqh7=?#rM7^3^W^U6VQhL zNEpl}63#g$$o1kVH!!*P+k;n{=PZmMNdlo@Cfjn@Amx zE;Yd>8@9srQF2Bc@_H}_ngqK~L=yK)h-M8yrkVgenPQIgfpFu`BVZ>f-sL@0M)*UB z(~v4sdu&j~$sfc}p`_rzwn&E}r-c2{t)^Sx-iB7YUkTpE^ga9X0DilgcX@vyO5c1| zdziHX@88aX@#8W6)M3HxIRanPzWr!^prn{7}Z+e~vV3(nWrG0Ceo$)g7oTd0B7y9Ywj$?O zkcxFl=*tR&H~JD0mdzVmX`;+Yf&(1_Govl-0ZbC>)9W3~8INqAP*jN2u0+~%f=R+q zSi>%cJSJ&`I}H*hvW}_sqQ{pQ)TrHp1F+{T-FYXsr#$c@BhnS}1>!3Q&;Wx{2MX!; zppb$5QT9hexnY0ZFeHMR07?w34u;96B)Lvjdfj}Y9cy^OU`jywz{>Lbls6t1+AC@O zkRLmhORPj^i7{SDCBqa02Q5~74Xo(jLxE#`(#E!G4{i5q@LIZ2k>K%gJJCFS``~M? z%h!{>iCL7-|1pau3JMSFo-Hgc{(6#^HDheq_+b04kXYRlwk`(pPPuMe9^w9vo2!&= z6%|qaLe6VwAAe*vf=}-Us%t;;+f^0qSAF4s>jV6~9?@Q{M9`mvjOVh2B70l` zjw~oy{=!#exyH^#&`(`2Fbhrz9S>bsnXO|(V^}Kh;*tlWU>}keA#?u4DngHp#tCBUZ zLnWQC56XmR5)2CT=TM5_N^Qf0(dar`%SGf;LcOxEY z{g$7+4nh*!%oQ#whP9JPK5X8}iABMpCGM1Q5{GnbtR0LQMpO`KL{>-AgV8$SX2k_5 zN&iSh=S(q|{DM*EDZ}IfCEk7Q4DO>l2aLF*HtTOB)X z$&{o4-_{fC*7drkMyK+UM>bn*XJ;Ggi`|x6q9_uovpf~64;U9#U)tv*{E`3&@Xa5s zVdoG|4)4K3SYY8~Q|-G}HV*=ko0=dmjI~Qg=kNoPLoNo<@gHs0>S!?Eh(ht}#&(g) zzbnGLg2XulI$>oO)Ty>U?&E(z7LG+8bcwGOKXX3_1wqioUekVq>@O=LvS3*=G`rGv zl*b<+c(2s1$L3;ay)~fU&4>K#x_kVocG)id{?->*lS5nSAGKf_hV7j)kWQ{cfx^p!w#m<2? zENJ|T6-s*hwQXHddol0ImoY=9yk=tkQp=nPQkEY(G-I4s$|T*;LTN^se`UOuUZHu} zWiY#QJIw>2f0DqA{qZGN2beo4-f>QgHj7M;Uyv!OtYH=~E% zM%$IBqN6V_9BQJ}1mX_hi2G+?gB9VR#p^!!lPv8fHm#^vyblD+xmq86$XR<4lUEXY zgwa|Yy(NX+!OsKQ66KH>fmxyLjj^e4u^@Jr15J1XU(dBVZ5X|a_zE4=V=ueXdk5p!SNwP1Kg>7sz5ekIDQC8+fhycQ6JH*}!VYAT zP&*LXI8qP0C8pperT@ySsexIpH?Zo8e|2Pa1@U?Gsd}K5G5VRbj^uH~hD1pw$0Q#^ zy3NDvo2Rj0;}YtpC?ciyb@Y@_amh9sI$b*0+Jw*>%@zSc0r8 zlBrs_6YUtk(^_u&sHNW|ew)9a5XPOd4NEE@V_w!3Kr5yD1_Tzgi!on%B4cEoxa%Mq zDW+*$W4E z@i?)+N$m|7CYh2q?+ufX;dZ`DVA~=CS*)Q4+<#wbO zQ;>aFkh}?iUTo@flpRH@06%7h4o`^>1;M{~Yda(A6~4eL+C|t}v{=mb z2|jeJYnd9sM5vvl+?&Hvx~Gsvm7l*RVCJExV>iJtGU&>QdmZ-7+opqCE?Ci zf{V>*`n2FcVyG}8Qmt7%-wlZV=fl`Xs4aedjgZ8)5 z55zy=Vulq7;-Y5YgMjUc&}Hm(uIjtE-rSWVM-TcytjD_= za|MVu3b!3I7x$9eMd_kg@|)_01)HU_*uw09lvmA+5o1ats}ydz-0(Gj9gE>0IdDyw z3@}EI3mzAF8h1-ZDS^S_1bkL>d`PU*MUmkrj%RCY3v%XW8F=U;ZN=_ToSr~|Sn;u&N#U)ps{(Ok*##a^04wO=D%{Wt9I{**NR>rL z$G0p~_L$7wVtV>x9IGgSuv1{eF3i{XE7HACTsV}x6yG5a1yg6-8^W=iVnHzNqJg}w zZnFum;0V+85S(oP*s`!VM;!G+P&WcOXehr{)4Dz>r5a1!gch$r@Q-m_`FvIhEb0`F z_`(q}wKqaPZxcecley8@L4$l}ll&MS4~@>d&ma4AvvS^xw-Z<5CA+l$TB%eP zWtDvVI4k8%zRzghl_op*U|dMIvG_bMtG==KB(X9EZrOMf#=CSGg3vo#14aVST02V{VyVAa5DB|?G-&0swGw-9H*JD8kDq|O!F2gtc zis7(4fMvb;JOH`)`kOKwVe~DTLBn2@bAQ((MosYl`m&I3;g}(z?8*97oNQSPp237Z zljzA&^N2&^t+8H!;Xu$pbfp7I53a*2C46C0=yx?OgOCM)qStG*Qu zL%PSBtOeSB0+weZ+s9l{I0>rAom>~#6Orxn`XGcCHH~686GtHymIF}Sft^vsS7ajY z9`7m|wI+e$-kUC7E|=~-?K$cFDE_r zL{faXP1XklxY6mv0}7NtFAg8V{G%4}leX`2`G&({o0HJ< zUYLcQ@m(u2L+L|nzXoXe2$pZ_d(d2A#ssTkZBW^0U#&z@k66x#@lyg$14Hv9#RlAV+^_R0^IiWs%fYuEm)PHgBd>FONznXax{Vjc|{%th}Jm@X_h~$%|6I*pIUq$B5V; zKycP5qm)}eUFge%uFrrmHP=l}6+U85ix z4Mrq)cPpr^d&#f4nOB2B194vV*-@+l%J$(_Y-Lab1@?~(k`>H{I^%wU+&#SzY1%+HzK<_WU%#IQK_#{hm&A^DYJ zNxx%-9$k9#8vZ4>XZg`7zwljT{9jde_yGvLC16raC8LH)fnItgnX29TloCIK%FYBl z80WrBtMh@+B#jch8?=z*N4)UQjqLCwwCsY!QG%6OypTmd{Wi*&iK0w7NqDGOPmceP ze@M`aTmQr9PCK`)h6ws3<&_{VC7J0ID;9W?Bg6^?GfQGSo8S-#T@ zRk#JtV!|DL{+^({&K_x~kcVig6#f!NYg~;r;#Eey2e>n3ufW31gJFufc)y zNzr4E+G0EZBty9V-l2%i?$VEVAA7qHa>B(L+-#l6_;82!_J~8oHaRxbk-6}(v1iGC z|0SqAR3LkHKElGpi}9cs-A=qJO12EVIQ+ac$cZgI4WQx^*CtU66v=^vDbaQc+XNq#mrd^DR-P(RM0UT9taCyn zGUMMio(ib_@VK%Q%#U`!Qb@^b(a{bta#NvwjME2ju8#vdtVq*1N!pv;{m8mX0A7H8 z+`wZ-&m@e@4<8cO1r9fKhLgiwBq@&pNu?ww+~&aAvQM|zH9KSMy2tM1Gt(MTw%Fq;ny`gM0Lak8xI z@{0ST?FkR4drupom-{Djn&zZhgq71HeQKZkZHFo;3BTII(!XiMv?!!Dmiw&s#(`p6 z(XpF!2gzCeBaiq@mXP?D-5pjTvs1hnh0*{-`X)(qS>~YnpjNIg=ZI%01s!2>8tJB> zV=PP(<3d5(UD9%Kw%0%$uBy3eP%>_a-a&jCo!t=E38`a!wYR^y;&72-EUVRJ30ftk z6Jq%#vKReI8s5?waQWjg5}jQ?6CFn8 z?HY9iB&I-@y*AhEV2}<2;5Mgc*Rh zNq3N1b4iR9qrKTd1HxF8p<%WUu$8y@j2+Qkt3lySTw_9en@Olojk&DwBur1Q1YK|) zHTR$z1Zijb#F^|OhSzC#$;xXy$?!?ep-*vBELf*`!FWE~3sLYFt2e=Jj>7#bsC(4% zn^$!~T7qqQdYZz*%ti$j8B!U2&As_qMWJOj;Qb2PFZl#X%C&Zv6v%r{45KXc^Emed zhTzNC%Pi|To^4yt%7-5}J>l`uwconIYoDnQRjJ<>Kk2`So!pC# z$-cPyYpkkX;8|&ez32zc6z*0m8V9y&=)^Bvn4lmo(hLNv|L9!igbR(T@D{8VD)FM1 zUA)wB`bPmppr*@A5eiWYQYOfvqAJ%TY#nT{*G@p&zZOv|dZAedZ>HO5-~Y~Pe7-Me zJ6@XMSt*vS4}Z_YoY3GYYNX*s(*EuDnt5}MZQcSzr1i>GxfY@=^0Hc~4hF#$iBc%*Hc z0eS@*W|x>*;55gRQbrQHzr|w4Z7hrxp`X8Nn|KRrH&eW5;9I<8K;Ke-Y8^#Sh#aHn zJ)I*gA0qaWGzXGqtJkP|?c4YMzj9B#V%nAHq4cj!iao!I)g?tr%2zAJ&P;ENpc-3F z`&v_61JImgEd{@I!fm+Jc4|iB*7Vb9#MDRwe{e&W%_!?4ubvfKk+oW#kHJX_JS&OU z$7_~eX4wTsInK0UdFVR-k##4U!OgyXXC2zU%dqP<=gvRNyx%;BPc4^|lwE)Q61edL znvie^wC9@F(M61ix^d7Q>#|wYnPUD2GLUs9q9%E@tFHPxl_UyeG_M8Kdg+R}%QX#A z!tMu4WsaaQ+@|&fd}2z0{XP?SW|sHA8^frib?bX@7NDjZHK;zO5A>uw*QA+3dG0o4 z!nL~O>!}ZV=kBOn2T53;-@XsVmvya#iyNyTq6hpvRQxz*)|&0#ugHKj_{sK;`M<^O zr|fz|cV|(X&NpF`Eg-}4pp74LpyE(WcTA>8%2#A7eVmIOjdMIIn66hUjcGU%R^J0r z(lN%Xl!7d~>Mx+08E2b*RVIAwZA7xb!84-oL%ChMO<`uk62z`{DT{X_>kdNS1V-VO z1(K(t)^iWr&i`U%VS8?0O}GZH*j2Jqk?Oboy-I3tON{Suf}~FSI?ZkQdchW9yC@BAmOWm_Rf+lHg;zCzqk}gyZD?Ec-@z^s8s4RWifmw zEV0`{u~YENmueqFD$8omY|RGK^WElTI2c~|e9OP*#NTFsCs8w$t#Per3<$XJU?WzM z_!Curc)t~1Wy_OQt1obqBH_kbfAQ8p5eI`p>R5_=Lb}plc-AM5)@P|zKtx}fy24ZL zyLuvZpJEX;S=zDKYV9|3GJTQzcgn=KI9u|tmQEbu+?K>x_jGQeueJJ!W>Uw>jPJk4 zT3Hbf!|HEd>68aHk_h($F#mpfRmGME^D)9TPWx>KyXVVj0#xl($ESZapdFI>CI$TO zaZp(Wx$@u77gK!_6@lV^=A4HjN~@h;&fNHYLbG41torXa;FyZk4k$&#jm`4dW*Q`rUCE>vz2)PuOngXO*A$=41*yIQ9S-&2K8J7M=SC<4nlR4=1|&hw3`uj ziIzUk>XwSO{?k-fahw7lZZ<|PU$IMAjA@K)I*1r~ZIBqdT74Jcp?50B+j0Zvo-h!A z8Ncagm*WY&ed}t<&!%g=0mHosM#Sa=kF$<|y);Z;+ANp;^6y?@6r0@jJu-5bCF;yo z>R|?&J>L*Rk=D9_!5x7rzlGy_25*4%YIct((p3!YtkkM6*+tKf22%bl1&ZQ@BSGpF zm0!M;n*mJ6qEpoIa6i#m8>t&M$dDkJa}6^#Em8-G`DC{A+|uYm4ti#B7s0b~rlGi& zJ|963#mA(GqMA=(T1VhG$P26X?A7Y&&^qC>;+lJX9Z)n;C1$PKC&m6Ko?6YmY5i9j z_vnL5A+3=0PJ-(gPvR3+?@&bEY2l6lgwOB&=o$GXZp!Bh0!qGUb;na0%&Uja{=XNZd4$8|0wzOJ7hHtKyr6x`_Y=Gm(sh@ za?at@eO3#w3Z}BFIa|I|k{HNuEYQ~+xAyi#Ig>vf>u-`Lxsc0HXnvAe`ua7 zmXDl1(T~^q87Qe!yf{Iajze(u+o?Tu&hk2h4v?Q|n_km9TXTtHb|C&y?5XGAW)+DVrHNPhU!R35<#Q`uEs3#sU(^{i|F8Qp+?T;R* z`!=e_KvP~v7AsvAX{15=K{Am1PU2>#gNiKs(v44ku~pXznX5_eJzwgQX!x`sBDL@1 zod2zT_^+mG)WsH=3VdUe6o7p2nIdCc9A)NQ@jXlJX2mxkI~bS}xp;*fZIwH`CtuG^ zv5R1|_RBA#>uXoDo8SUDJ6G9VHEmuaEnD%mBHTC><&*kg<2d-Ry@dd&n_nhza511U z2g85+{b3uws%ESASp9CCN@+omEbI0sU3KYoDfj)W&cE<-MdQ^!65^WltMyHn#xl)x zo+!};l#r4dO&RxO+F#S4&8FwKxY&SVyDaVoQ_7UzJvZAp0Nx_Dz^3D}0}8X;1D*rS z|5O0;+KuR6VL+E_qyLM&_YP`u>)wWgiXf;&r5z~&j+H7$6r=?~>;e{wlte`lqy(h5 z1Ox;@!Ez9lCa9pah(JP3lq%8`ga9ERHBv$ggoLzj$KyGV=lOl}ely=6@60>%&Nvx? zJA3bYm$k0F*0t7h-0FDOAy(u?%xd<<55$`7SsS30mraMJME;}?nS4Y?AJUqoZoYTD zY%uKfGw-WPCLf!se-SDSll7wAC~3~Q(48jS7a!fuVhl~<7%20v+%4k^4qL62O)Gi! z@N9YUhBxD=+?0f7>NHgOA_ifH*lF_QqEr!edIf)0Gbm-1;$_g+ZW6H%rR#)w`8}g5 z-S=gg>Z+}+%n_6r#yCXSv^12Qt$O51$22eE=D6LSZCIx4MvqSC-%{>4JL*sPgy8RW z`o{k}eu4eK7eqOzao_8l{4U*MKVj2J)u?Na%~H~f{bJ01kzT;{W?R_ZEewDR@4;9x zd3$mp_H*w7y}a^P7RK82zn(0PagZ%kP}E^~DVM!jkUlm}h9&=Ue%~J zVh^|pi;fAE{4!erEH1{|tvdV+Il0LPF&x3>>RgSV1jGsqKw8x*k9pERV|@mQpiyrU z8CUxtw5sd4MMvk*nxCz+Nhj8ef<14;?4wZ==)2}>NU?>5h2Cw&`F{Msuk6~jn3cKP zp>W<+Ca({^aiyKde=l>gg$8J%xxC?_O_`a?x|Lnw#`N}!Rs4C0x)NHzU@+3BV&K;< z0NQMkshxbZyRP{w*x)G&`!rM$_dqm^Gs&y!Bdp2Yuf|Cf+RtNz3Gn4*)?~T5$#?0g z7v1mD4<0S(=d=yV+6b?jp5^r=@n0k-ESLH7*Zm#Vgdb(Bi3XAS0MSXENr<;a{)Kx1 zjj=|c+0I5Fw=2!$0p(PfKl%8)n~?GC4g5W6`c+Th7rrC=A|boxdrc}at8vGCWkU^U{Uxm}^IVp`giOW|g zv$*Ne`#9|Zycc;{pJMgGz%!Uk2_LMAxT-LnzpXKWzWfI_e_Lgj3{J>Ai-zdEUv_rm zAD@Iw=T6>6klT`lUwC3slPIB|>Y6(ZoN}*26_i@VIh4s@5E8 zU?s9u`{Qd^Q-JdV!3i5;D6!kV#a3y|lce0Nvg0FpRuj1rSZq1&Idd#u4a%FfinEd# zrhmR?Wit+?OI|N*FdtWXkl>N{}^x0kV%k=qq>If75fW!8^)L88;YL~ ztrKnT7G1U$@!z7)#as*NHr*)tE`NRJeAXuDL}YENd8l^S$08S5QJqgN4P0iZaPV2U zM!n1cB4S_IxQRg_$*Tw7pEZI`BZzLy;~uY#MUd(F`=0TylbcDfl1;lSap7;+$9eLzr;pWUF0uk~wcFJ_^Ko@raeRN+kdh39q3zz%(4S zO^%CGlPR^K)*F%M^yZ{SLo;Ba&_(ik|CH&nDw~M=MKChWE1wh)5@Sk#(P3n}5z0tv z(}?Le4c)H(vS_=~OIxWwAFGuTe-|=c=6h8o|8&ovSj_VUY)6fJwXH>0BR=021~|ug zk9Ws%2|p0K(QdoaRa+%L$L&gE#N4-)-MZ7_4U4#P!YAE1JWT1XC0WPhi59XvTM$cd z_@s|Pz8rZrX;P|sjq-t-8<&z%w50W5DTIqZBQ=?UQIQH&Yc8M2JXpMhkNAmDdH&#n z_Y)@0zN)Rh+?727ARZZ&8cfh+HmPlSn9X;Mu!@27alY=v?}+zIS`YpGaXderENvaL zys+?H9a$==q!YuqT2q~l80y&seMUpjAG;?2gRqkpUi9SDLAuYOI2&Ppu&WjF@ID?{ z$c*Up*-m&Xf6qW_EX4W&k^5mhpyI&V=z>fZ?V-L<-R6tGNX*KB2&8I42`kk3Hzh<^@GSX+!a^*}s1p#qY>7jrQXvqmLYt{zNB>ww*>% z_hSqho-De*5Fvd?dW62by{ov;G@4btWOEWQ>~yk@^mvt4QJ&W1tFPLM6@*$i`lRMV z8d3BvX{rpP_Evjg+(WD9C1`$pgld5+Db;i30?qG}KH&brCk+GQ1EB$5Wts~y2YZD);oQ-(z`imgQheW169ng3C zt|tbS)%ZnMQ0S1zvF^+NesoOg*Tu93QKDnk9+Un8!ugI9e+Xg*7gcdf`e%M3Ot z`(P=Dkn~+Y#LnG+X`6>*$;JOXnGVA8MpsZVnH0bcK`jbw3jG2CdezAlIQ_dr?cn+g zKg2PS9q7&7On1AoVtASx|77wasaO=EL9{3wC_F>>;M$JN` zmgM8+!X8$eca9FqI`Bs8h!0J^gF+YRjHuwd66M|H*buKGkFX;C3-2ipw?VH|PP$u$ z2#t`8$o)%Pz955~i5UjJS!8$svxv`A<*w{TYbm9)Dh%Mb8(480}G0vdQr?wm9Zs z;$-`J(HP%9Qt^6;eZ>W}A7^@Zb)DqW60wlTfejc&NhYA-gnLXbr|zhD3X+xxj4>pM zP3OoXN0&ef#)q}R)-%L|@hCX zOj8)CAby24bi04b&?3>v--8?uP+1&i_q%18(I>|E%8n16(>lRr_Nqt5cuTo(bg zgO_`}wLjU1wK^5)8dyb9Q|xq`H1i4EoaW3mEx97aq4duLVnwysFna=j11zoN< zu(uZ<(>vktv72M@;gGbM%|^ltUuI8)*HjJG&hj>`+qkx2yw|0Q_x;HM zXP$@keb2`&jC|G4IC^$EZPUFz6T5TwK4i`#(g+(e z(3&7jlT}wYjnd!ano>wkn#O0D1)|H+cj$b_)zqt-ycS<&Np0xk1aE<>rRn0$rjjVE z;9}x_BMB|B&B#bA{8Q^v1DRxeGCbjQ3-i{oO=31y5D54q<% z>cLc@Hs)m0;deI?7d+!1q^tPVq?@OnDfUBrRbP2gc7EOih9{qhuTU`H%A?@+GACus zdp`9BbXlYgG2n@HC!Ko~b8%Yf+E1TK-k>H?xr%Znk=!@^mQ8TCD%Xniu8a3=d#vS~bU%P6P-po4AVbFU`Aa8v^XBRfc~=+f)veyA5BV0ZZ(6 z5L9#XfN6O5VW(&dKJqD|47&E#OkSi;nCsf;;OF~%zaTck-sS(ce$Bn?Ghc|@obcT5 z#wBp+NnHlLHW(2!XEAqg^3u1r-U16}LJT*U--Vu_=}b3rHOds&$@k3MxWPmNvXd8D z{KZuKEqqM-A8*pfQz4frUsj*eh$j@6%ZLXr3?a0&0}+mCWpoM5e#7~8CjX{T zg`Luj6moxlwzEE%)eA3YB+E;(U7F4nmwul6!b@H$aUZb2@v4)~@Slx%$Y*vpsZ-`k zVKK&SNoVPN;Q3uro(!x+m(9Ej&v;tYWhZs7#7!Y|+OMg|p4heGhu;5qvbcT4z(At2 zI9;X`oFQ#RJ?Z3S9F_i#`yEE|XXGO=egmpi(-&;m_s>kLlaRU9Nin`RTqtuFhqfC` zH)wzCD7o5yrP>)bIp>y=NYCPFclX)%D0w7##~vk>bS=&qN${h~-`d zjog8!0-XNVKjL%E$a5Xffl}{cU`X9F!e??xv6=068`ySZmRLR6jnEN(zS_n=41i=- z`dqX8rPhB<^aOb+9W{BZLraXNP&G7`Dbo`=jqhoZYSO8(KAR;<1U6&?iv_)&%SRn? zL?lVx;H=m0wDUJQlS+}(8CorCqB+v$Uo6-wyXY>S~wP2Jx)cyVMNZKwJjwd4TgzReJ{f* zTb4<`^*5b^b-7LQZ0Y&FJIDclXdrcGyLy>9j}f`edsAgLWxGWxYnZ$=k0ho<%~;m+`Cp$(#Q_EHL{vL0uZdVVs=s z4>wqaG2DEK>=yDJ8_#=aI@}+S-PP8H*h+q#wh7mWQOtKdyAOsBdR52td~y@yOx`7b zoc%~EGlb+(lWZDoclB-zF?iviwAys`6{lX!f=Am)YLf6%4ezf+zO@@WJtLJ|68yXQ zr}lUBV7CPwtw!k_Yp&e(*oExnfkER&TB~Bm>iI$g_R8Q?;P0#Ci=M5WXvtN{l`4h0 zPUg$55&re25@SXQx}66TuQrRJ^b)g1A4%U)%ctES`LKqHlPF zZ99eS8oSU2M7-`6a<-|%RoAsq=ZZ(Lys3MMsOkl?hdU}nCa}#c_W-$FFNI7?!?_(p zGJg&l+~0u*7`w(nc4w09J`G0?1Cw$t?kUyGdOpckWrsQc3nZ%|{`vm@*rJ{Q%a_d8 z{53qQNJC`cXQ_DZ{(R5z81~eSh|YsHZY79`XL!d{4bo{;UE<)uDTn>Zb@yWy4DWbq zIcNqZL$YY6LJ!n_M%&PBE5(Kht76f(a$T)`jkhk@K-Bvr)9910OaT$-qKuu0`0JYN zn>Uk!^w(w#F5!2N&@uydn0#ElppiOD zeW;zEcwK#>aeTBoXlJdrP_>>*;acvDCVbkGOe&|b7Tex6_a@2oS2=$!`7QPf_c+Kj z5#CI|jp`ZPX8q9}@_Wat1@5Q9BqRnz59EdNbex}*QjC!7X~_kn?WEc50+HI)N<2dKg?qf8UZH>!8(fje8e|?7k;7v{inS z5l_#}yG6axP@OeG&F<~Rk;}*d4(eWK;-9?`GSzX1(@r@UTDFQ~tq=Pf6RpMy`@hRD zWCHMTJ(qN@YtK`-*9wusd#Ek9r&Wug;e^3CIuiEZZfPo@*!YLhRnV1QZmnC{!jl}k zK$2xr(^_O4w-x84N4i1R-qULUJK8^c&qrrEv?nFN<0RDtHSlm$n}Fo{W_6*ZD*dQ| z*u{^l0|pY6)Bt|aP8a9Sxj+huwaN^ZjbN=8e2$t&51-ofEGC?CIMXTY+t=n zgT7OfW%R3>>=|6+CgM15bBx_6C59ak!gl&-N{<9vDQuE0x-aPLWR7s8>t4e+;TTu- zeJ^ddmqs2|zYs<>7}`9!1t_(9w$5EWQ2UXi$zS{1Qe@%bsJN@M8b^boXw@v1z57jS% z%Uu%XAPbAN@GYkKttHiH8$d(|_~Dno`4ByK48CcIo1fWQ!)Z*a3q&(rm<$P? zel?E^iy>+9_k~T9ha_Z>Rq_PZ;;Z?A2HUzA8N_C4W~jE|@{DfXHY#yTyRpA=823(Y z-S0{1;u4v`Dq+h@ee>PNVB)!oybwKBS=VqD*4Unvf(*Von__9yYBc}g*zt$wm%bc> zJq=x5dNDkWge$bCu|k4oiuVuC^fjqEKZn*u%P!#$n^vnR4-W2Gzrii;GjEqE`^6`k zwJ0!mssD&s8QXDYZ8TtrQHMVS4vAvXRFUEFQ$w4y(9`7f`ESkQ9kETB=!0p80tsT9 z35?~YI$Om<=Y`j6D=`xuA;l$(m%8U)#S+f3-Xk;eICQPd0!|4rC@%C{^P?Tjdqbwa zHh;o~jb9kIC9WpVmtn&X7;@%G6GCPirLH`OV(pGcMF$-)-MD2WS#%-bC=I1DhX3Qn z+Grg^sM7tbz&!x$CXaL^pd;NPSPcKzaOVmyFLe2XT1u@hV%0{E&pFkdETSz)FD#NN zt5UDFWu$P!Xp&kJ%tojeGvtv7+y`C{Dxt8@V~PcCzJa zYKcVk%Ie!?+_v%HQ`OU+mjgJT=mB-IiW}DhE3JrD_2McRi*JXajAH2G(QtV6^BHeyL6>FJ^uc}5?xvK9%Gn_4@sAU<40z7+FrHiod z=<3q*ql6scvY>XS57}srK_%tZ;2-&;hVTqhY!&$CohqHiZo2@Uh5P_@L4VdWV*Ub? zj^s6XuNb`w7U#CPc_6wvxdn|bDZKSdg)8m`qt&TGrrd!uY3XW6Q1XG%^vF2^ieUrS zo>t9j`aGuvYi$cFg+B{hUC7OYodjh#L^2t=U>)y{Sc@)*B#)w$OYzz#F(S%{n9u7) zP1ikiEC<5=u}r4uZcF1WnvW+oJ;8iS4Y}-s?3FxJB^*1Ay`&x9N>TgV-Oy1W%fzW! z_fl%O{hlenQ^vX=>Ri-FFZeCNeej_q3F{s4)`4v!GuHX}+Y!B+4e@`T8fbtFKf|{s zQaSR*n+cduFqW*g1kRWZGDQhwN-X3pFh3qAgXN=L@TqU;20Y zTw}ry{#Ca{Hzp|$*`_bJb*?#Ufb}JmdcJCDT`A$&Onql{&z^F|izZ85&GS@md}SQi z<>MfE-liXW&6sy*z7Hul1U;qYc)!6j!}+w)0=+<C1`!rpvw&#yBUS9 ztE<+583(8hU-I~8LYr}?JhgCg9bZByA***>!YX4bEcjgk=jonaH@c}ig=@>(a7b&u zEd?8-SkEVc=eP|O_u-^|dXE0CK0D3RDKNPbbBBa$l^v8-Ll5#P9HsP&QKmH6DP;4p z5*`(k*-5X`!F*(f5!lXcLorC+5#|lLqeayFSvngQ4aZbh@kW9X{I>6!zR2=Wf|v58 zYHALvx|6dscV=dY)wxt3#$7Gn(LuVp${b2tl23h_ChkM|y=2r{A*pYvYJ%!slfD|1 zF(*IAG5o%?H+XZ-^h?I$%#LYeQXXAt*7jX%7{$flm@_|>*P4Rr8Ja;^Fakp^g@uwG zKj@o?mN4oHX#D|I*Il~sE?r&3%dgzbCYoO8uTKZr>4pn2qo`=2HXY9H;FWl{6(;$k z`QJD&{!u0?lh2w*a%A}COb5&~Du&3#^BFTnYCy7mPc!Da`b(K|G@=D+*kA4iNbyAT zygM?dREpmRBrnJ2=&MTU6NoeI#+Av}3&zGlUXN$Cup@Mduzcy`6B#ucoPzV^bCtm8 zl(2e6+t?x#pJJI$e$(TYuv~%*xm;U)pSWipPo8T>6{fVTjV=Nv$C7Y$PxmsiQn&D* z#Xd!FSFP2HMqXmd{)g41W!g#RF?vQC^W*04Kz4!qr&gazUYv6CuNvoF3-9PhNZLLl zyrky`CyXFEstczU-rZ`=uDNmd;W%Aeeh9nspwMBKT!p_fN*jwd)G9B8D!ml0oboyM zIiWEdfi=<7ReW@HK)o2)$5F?@}B5k<7cYt}bW!_R+Dx@@98h3}yC4aHPFqWbZwk?Tay1byDHY1%D; zxZxG?FvUd0Kgfah2ZeYxJhq+YVHn!eba^2#>yT!1aZzShAFDsjV0qzm54L^0VZp5< zxsv9Brlz&Fr+?-2UiZY4Gw>k9TuwI%GyO(qDs1|`~ z8Z@4ql24W`BSw8jM1JONz6Er5Rl9K>*h3=$MaFRxFy?JIN1|79C01-6P%-jEGbI;F zAXx?)PPuMc2i&SWOG-Shqo)@k%Co?>3AfsVce;7v!A`BK7aIMi+!AV!I30i8e?na3 zRQxVEsf#1;=%z@aZE*3_n&=PNU#vqic81@bzR(pywm8Es?&bTXH{eF!^*z~?$p6UmteXnj zIBP~}8m4xrvXhq&fY2mk&5MN5ciQ>nsim5)P30B`Je$jRO&9rXPD;Pt{mzV>2XZ11 z<=SvE9eppKWb&Lowq>j=52aa3)<(JX6{OD&Jy5Tok>&HQ4%a>;o;3=knoU0>9`dQC zFF(XdJ0p#eGEF5;@QXzy=>71E_>6;Lv-LQGX_poo^6Xz78Wj$azLwG!2?0$iawUW4 zvVbOMsZjjBPo`1r92W$?JmntyzOn8I4@bm!vu0qe867b3q*C~E4n?>2jRSTQpXI>U zsh%$+)s^r`!}GrI6}e$XZsw+>jPO6g#+iI+9*j6Y)HYbM1`-j~UMGRkFl6*TogaHd zoghX5{k9bQr*p)8-u-uft?aYp>*{5dtCwnEmR@b}`AujhY`=5|*@1P{e2KCNdPSMo z=Y?XoL`C-RY-!+4M4E4V=7%HqF`g`#@jmLwB% z#pT+n2hkcc%kD1r(UVeF-}&@kB{sGZY2-2)$Pw(-h<$oRwv)k+8QMJftQjus4Yv|@ zLP+!C^L`a5tzK`p~y}OuMz&7F;e6F#!l2+2`3XS1_6dW~;gF_Dj5UVRM zH_L=f7XhvV^=Q+o-A09$kwXvVlV<4!7=mWv^(u5=XbrgbhSpK-9d(UF?8(>IWQ)`I z{cOyP86j-aF`ukCHywt|TbL}eeVXJv&h&kAm9Gn}Er2&$i>zoC9gnl!T|f`rK%veS zbd)SS5fMc)k@*fXWsMH9+&01K#Gsj$b-Kt3Nli{eY#pCYMQd_OERnB);I~9mpUsPt zIPE{>eAse6a>L}D(w}RhiL3d#fc9}{WX9PcxbctCZjs#}JUb2F%2_+44>LYxgJ+x& zo2-&i`bsxw;I>;sfFD+}NGEO=ck(o{dDV<}NjqCrR!2Cdw$%J`wpXq`;=~r0i(htd zt&kN*A6zSq+e#}-?v*sX-Hye*-=|ZEr}<^3UeoQzR+~Ip@-K)$R<6m~?+E~thrBeR zje5~Q(MPU?d+4z`j6|CW>`&U+Q0<2Zpy{#tkPir| zOgc|Bj3)7mB;E6CzLO_KWG$VY$vXGO3$r_n&mP(aK>pV2u&z)0k5ax(MY-}KQLpcpzhCGaww)P zjC}cs)+o79@9s&MtlER?9-2>w7l9Psg3MhsLFa$)43sz4w3c&b+m;?eq=Kjv&ba z#r(cM-i$gwMpaE`CoT9mGWz=#JW{ZN>^y9Wm;2-)M=mCaTtOio9xakoYRz1sb&JM8 zE;IOmpnK5NDeP+uV|ip6 z47nz?Budez4pvdUJznf%IEQ;QdKJ>Ke@urOPn@YLOrUnW<9;I3RthyjdgvBAoNW-h z=E(C;c2aHMg}ECuC?nIY?ZzDp?TY@ZlZWIL4s}$rx3x8f)`K(5(;b~n^3Ple79xho zr=$`yx|M4=C{ukczJs+WAS_G(5{MU@HB>qkfSA4QZ zL+jD9#&lpvwG8zf+2RTzosssbeId9Cgfd^`aqcEEeBP_>>piI+v#!m0gIUKHWjfW% zKoeE78&LW-53z=8hP{E670FK;+R#Dd*q6_nh6|g9FMk*k!+-)dw0R`g7QI#o60z4C z*f&&7f;bB$!yHy_9lZlCgFv&c2<~@vfdslIuo4x0oB7>7xY6qw=9|Ncnaax3hU^Wy zJ*}Tylr+Z1wU=z^NRn3mFqAyQQ)H-6` zg&7bk{$fHbIt5XgjYkPSm zuT-_jsd;qPP)>)Zpdq6_Z5qy5zrb5HP&4_qikKuGS`)22O+`)SMW^rMF+S+SGYlv4 zglb{j{*IVTemA_x>+(`}*Y!Hkeh{Z?wgMHM zAcNcrgw}R3XnBQLm2F{-!_k?X_L6rCseK||j(~WRVY`S*gj{~l#0SYV?p!Ytg+I`r z1Je9ttk7F57Mda@dGP z14ob^rw?hU6WRf4p>Edy`O?6ByE|8qKGJaMGx9b7s&=3SIS`q&^7IvT)>y9l`CG#u61R()6~VnRT#(=Whp3 zy~(Y8b3XUkv3zC07XW=|xCrkV^ZQCb?gQJBp9AA=RWc0c^?A?W$aNZXT*~|hOt{Vf zv)!R~H;TW~<_Lj6L1ch(t!m4kz(O`Q0kU}BKQ^@WZnyQN$wRAS+~$eSco1T!??DGbsqrl*C!wGW!T5?rC&b!8H8%tDJKhDj)K zxM~~Oza#bqs!zZh9H#E(yUZI1+tas0fi5=YVb1-Fp z2QVP)PggPPXUuxG4PSZJ`UeJ-tCa)iXW5wxBD~$(j zwC>K`h_G6I6{h#Pdre~#P!y59i1l%CBFxMF9AtTk3SqZAaO3@^Wemu!I3@N zvG&Z7J6Z>P%?@aVr!9u!2YV`N0k^Qm>72*zBKDMf%Cm~mdVjKU{lP0_9}2Vll~c}< zv<#$Y@kz``wVsBT7LVT!XLa4^%R(o$t%b;YbiTjTHLs*1SWzbfflV=u;2o?@Ta58u zJ-J@=I+#!PtBd$h1PpD6oDBnP9EmoAE$HpATv~zrku(r0(kU61e=F36qj5T)K;hxG zb@Myqs}8bnhk9VWlWQXcG@73A!o~mxV83Jpxm1R^+4o7Ueu-A5qo#D(7qH~@s>@3Z zIWEnoFv+LpUIntkrWrqXG+Wsu&YW*&h_snWG+!>AS4>GVUu4)E^FgQ=QA=CO>S^P` ztFo6iN^#Ej6LRpjAxlerHzMd-*Ct?6%sMIH7Y7}t|oBw=L89y z#ATHu&ucutjC&6+HP1?IP}9>YZ!bt_p}46Xx+z?nGz2FXuHc1dClUAX43F!Tfon&aG#BZC~p-XF5Z_Z-D9h)^*n{(4@+3^sd#J`*O79k z{#NM5wT-f3`d2;}YcR3flnVMYnRT5$279$X#)W^nGhJlx7)Xv7AURf21Wv>7y=m@f z{&U|0wedL(op#X_;Ha&9_w7ei&64c)(ymTEiT9o1ZV*{_62#GTR~J@3Nt3)ozUAu_ z=M_&%&!(3Hr|-3_!`IPix}nu4s{j+B`aa^&T%dx|1@ak&zp-=)e?^RzUdsYC96_FN zO*v}dYKB76FeJ-r-g3pCQ7(ALw^xb!qi^3Xr2$^qbOmxv^l=BjB-p68Gm5A3{?%$Mz=lRlW}XuNBBuB0(QO&Wby zOw%j8s%ZSOUQMCXbG&}p!DbV*XVP-=WYlrTU7M7zz)#^1tbv@4I(O-e~`*;0@& z8T_HDkC-!*;F-%V^NO(2g6kahhc9MhYAgcnD>+u8R(tvbTa!qwea7-`kCUczKAb2k z9P>EKS;CPMgnI%D#A4>PrQGNLO$zUO43wL57X8L~(K|q5x6*3bJ`Qad?MmA;X7t zG#)o*-$0l+bx(bYoDzBPV$w6=88j=MRB=ujI9RHmPDhJaf6p5$=O5cCF60Q z9VgKQy1j$%uVRXSn63jg6$~&fZq4 zIiN^V@}~Sha9$hL7uR4oUq;h{t{vfMLd#Dn83948GzG#ft6`7B7C1!7ukdRc)$_QscpKUDAx$xR!bqkiyq-H{*A$d1`pV zbp5q{?-$p)d3S|HAM`f9y9R;m`GH%clumzI#Y+^;1ZmnvyagG+egG;iRH@!!uD&*q z(}?EiqJM`=4|UxNd8tv_bS)bs^f)PGnwG-TGy#l1oD~1wWwSJ#m}mKyBC;3U*y0X1 z>9ScrRp8pS0(y3l;XCrAL3<74k`u66R8)ZC@^&I34*N-5T9jHAhnoHuQoBs;&4(x> z{Gs@Cej>nf`9B_^Jc109hj<48kgRYg@K&dXJ71j|E+Zktv4qtd;C@e#LIjT|doPSM z%-4!*0aJRYrenFcvLS2i(Qxb2{lgEADQ=K3TCxiI7AaC2zCzIr?TCL|BMKdvGprv< zoCnpVBF->JWQcY(xF!-48%}fYcIQ?2Qfv2j7;Ymh+(TWM+W;;S<5S_LIs{Z);|lZ( z6P>+e9JK?x>qmC-w6uSaC#4I-#w7`yniufl>E%SRrj{^i;olT-q(QE&U zxKhtYfS-TNDp^dx*gnL*)E%^HTJC7)avD7La7W;IA<)E+i7Zl3awK?HZrgt0a&1LQ zNXxywg7CL7FI5xJ#t#_-9FQrs6(BmPBB8nTN1&2rbVB-g<6nMpT`48-prG^FgCNof z#ExI<`k#O52Nq1!#S45zfx#FsoR9s}zt`xoKc|638J->H#fV)=bC3mLyf6;?75>Nk{b<#~;-AsZx&Z+W`nioI@1ZEaw+nv~1_LWiN!A=@4SUF4^{K zy6v-qvX zf38(Ors@AS@PEQ222L9cvD#;n1OX<86o_0JDwc%A7&%t@?X70?yAOBUA~y}K_TXz< zw21PEu!V+s4!tAxdS>`R!{x8%hl`sO#gmLzT|vzHRc2=jL2|Zgj?gCul!5nW)?e}q zzVz8_csLfe`FeZW2EmRl_Z~I{)&OeW$~tWI;>l%WAT*KgJLoxwT>d}86 zo*%hV4;{*dDpk*g&xsQm?nLSKO!(00i_lyQs|D$$NYl{b(2*N3{)`6`TObg&$Pc+< zL)QgnRLGN!aCTouttDo)YyMFtX9tJb1mBDzuw0m5lF*Wa;ATJ1ox{K#31Jng(0UW) z+Z#Fz>8F9!rU}q(49^K~U`NU-RgWsnz2>#`NeI>E^Cyrt!yj7aDm269GWfC?tZ{zM z)3uQIJf-y_3uWAyzLMd|+{_}=s00};8>D8Oc`-BN8z5|AYmxkAr0ty42>Z5cn8cQQ zbGsqmZXAmMV~l9lPKFFK7e=k^p!_qS7t`vg=bJWPxepE`T2OR0^>-8S*!!_3CnM(H zScczFRCx*bQ`P5`K_CntUw>_66nD>+gGn1SZpV5brWQ91vdz z|L*7&MET~@_b;Cwm%fGZ&tR>Nlicef0w@QMA2*9)mOH_DgQkN4VTMQK82wMkV*zu2oq;Tk-Wu}{A@mpPEFlw zd%LE00_tNJpn4>@$zbs8y~%((&Rd(-LvjS`@}Eg~D+*OHxM+fu5;6rP#v<~C!5f}l z``2{FLN0^iU)YnbZQ>)7)#V5dekV%JiShl*iyEBs2cxaj20}xV&#DNh)p*1Hp9I$SEj8&qjNf;9 zRncruIv(^i*d+QG0N~P&2LYK~yjSdWY^ImNoU?~+xI7h4j^{VhUXnFwx{%XbetEy9 zZbhZ~HU94QqDf;73&+*pHmL-?k_E& zhP8mp!=0p2PPLU{?zoUCqSO*^`z&)SwJiJ$9#4TNhs!sw>{rPB6PUsh54%^`2gD7`urf6kuB`Nghf}<9UJV`sU zxRAiN1Zf`hJk=-xZid35kRoZYv-fTKDH+y)To3xjUJ3o4O8YJpB+)ysgsR`q6`m`V z&6I8jIei>=gX;k;Wlc2hTgJ+vo$aSc_mb$IW#Ko(muS4Bi_4?$e4hGk>{L>6!YN=M zmpkekv(P!@#FlY(Hv{F$5xS)M>#VF39nbc6kVT1qFLcu;XgtAB2ru;pIGBLK3n^z3 zMtmH6?8ywPh|jo8>0#e~9=;LRX`IX6mfOSv@iw#P$xUG!I|&W`UBPZcoy&_&U;M~E z2(-G2C;L?}WS`Wp?`7*7@wTgeB-p-S$St5M9GrG=(0@7YGx7_mi?7r~0^*q(9Et}F z@)l&c`1SCUch@L%cmY-{r57ENuMBzb_wTI=M6AQF9SURwL;9BuCa5JFQDYtffpnRG z51?EG66+EQh_ipruRzrFIxtWX^W*b#gDlIsD&yt1;CnXz^^KWh84`iv-;eA0)y>7S zwGKXlT-xxLP)YJ(_$Ld?# z-0f3C;U&TMZ)y)cjmUEH`<2Pe(2XavSW99V7-MV5> zMZJJM@;6jxQWOdMIfGSL@mPtr90k@;-GX@cSh$ma!>gX>?d5oU36enG+!2C_ZW7;{pqW+{3mIGgNzR3V&y=6P55ud z!J`_(?Y?W1mlZZZ1@+Siy9c~yc=I3fd#guqjQ-xCQ1hm?JpX-x22gry1(@RR zS6UUSbsmPJzmw|Vls1TR+U88cq*V|};d*M5aNhk(nDwGCyMW1c5&1th7G#&;j6?j^ zM(?iW@);BJ9sCC3W@1$;F>>GNjKZ8)Y>~nCS>o5z$Ad>bn5`Q4=oiOU$QpO2@>Po1 zV{az3Azy!)pl_CmFo~4`dhW2Lakx5X_6%_guWy+sHyaX`f;n<%aiYSTsu5e4B{wMN z#pk@4XC`RfmO)lS6>Hdxd7d0re2zO);qCSMKJmJcsb~j`Z=x5*d_0dLE-?#;TDO~s zeki^1TkF2%{Y0QY@Dm>#(b0J|;vzf-8BQjO64|IZF=Xg2UfiM-00$^znOPz?YIp(< z+YmcKi{GrU0fm`6R!1c)-VE|R82a`;F&1=|Qd<|uLj+MD^bXYxR|dkwSHz(a`HH_T z1m*|}*kStJu`zQXbOY27gLofMF#!|**DeGmh<`w%0Gt8)$1j+4o#4`7x^R;k(^1SVJn46*yytcf>(x|iT!uK&TYr;SWp z%_1H%`K9GB{?KiRr=B;D!`W%^xxnn!xfwSfuqxuL6Uy z1OxyX3DxXZ;GUp&{9mn0K(CyI@77q-5{Gu?Zyq7OqLqTbLqw#0Ss!PRkYxu#8N|Qx zEzM#|zr*UH%EL~jDZ=nVrtEU=y=Va-|Mpzv-|rk(pN($*r zWAs0t{jo7qf1NVH5dK%t|Hm=>^*uy@<8xKU5+rW;MsfewRDd5K@>jvXr>F;_e0!bQ&_Gg`bGhI$DH$K8La&AT~W< z6ml_D9y>HsXU|JQ-tI5hs#5Uo*Sq5A4GC}-HjI?wn3=KbCabHDXKp2*6z4qfUmM+v z_9DA*FqO1}I>-5$sfZ5%xmv7+cw`nwTuK%=RR04x%lp?xA6L(5a&tRt1k#_?V)jCg z?-dsHVF91)!Pk4XB=CWY(E4K&xQ2$GJp3VV`0$ZmW=L7U#J_lg`4t za*ORp#ys)nyn|Qc_&Id)cx)W~HgFLRV0)XkPV(w$kd>%aWAM?Ow=#?S7 zS4hEBpt@^4`VmOAd>4y!mZQRh4+NA8 zPFW5g08&gz7{Ty67uUT_<8A!jrZpT8^Ss+-4Av2%f6ajJi%NpBDpNK4yEapo#;d2? zA|(7lv#^sI3xLmsiern2ERlpikmSJbZkwAzO%diq>KFi0-madmhh5EGj9_BQ8T)oU z64fn-5houD0ACqcK-8RuJV3*Xi}GBC-5A*mO<$;TYnRZ<=)7ySAT0m`t!b4uGz1-T=zvQ4x|5~4h|0v2+{OztNx zF))1n;GzW{#60WeNjFo#u4Zub#&bxR{yzgJNNW6FVH~d_ZEvaq*V3b;q>=}}2y)vM zkO~~ojiZ!yoK}uINmTQQBwHz3bWZh@tlkZ3m}=zQ^M1$3)UUC$%^7uEw>}z&D7hLC zgy}u3veSaGo*ry7AKAzTu;7~a2vSSBB{a3dUu6Q<)&uo^POrFOlgyD)skC5e!n4E| zXE!!oJj+_ldiEd(`1Gq%wPr|5)23YtSaDe`-e9j zrPNe1^LEY6Oe_|-Go#FfK{#I#a~HorOI9u@H^QJwwx!K}W#3qs2y417VueDK-EyZ( z<($6GFx$SYsm40nYzb4COY;4~Zw|r#ded*4gYlfyk;xh~>2mXvatPvM!nGSwD4+{x zJ2E2jZi8d~>*EA_r=Pf@WCu}sEvMyJs4Lk-Q!jPyXrcP=^>BK`VoLjNTI2svXV;GS zr}&jShIw=Z`g2WDRo{GgyWR%JL`YslxB69eREN{7`TB<5SFs{p{z~Jw2hiEm9-;~iFzK#Y<&MSs zbR>yK6=eU_1UkpLbFAZlXk6HzP~Wj=-ln5r2~EtB;@Xdd-@a1*P-{-gR-XRYy1hKF zvN-S_cLA#EU%KOsIR%Myni|P}-Y>sTNN`cLR(D|6kXSJ8p|cnvhWu~fOav|;C~ID^ zW0E2XmG`V^Cn5tN;y-Eps%wp5@jAxUe*?7{BteKC-!yg*zmYWwZ1x< zACt#g9sBxcb$+K*@%V4aYF$3BBA`lVzej<#HXQb7*;iM(WOBlkdO z8vf7~k_!}~L53pb0y0>jeFy?H#x2?w#y+P9hm3_DP;l+8Pa-tN7-wv#eTJP9!v`aWCo69DjBkx56b6TX;Dylr1=?EHQa=+(jHf&C zBtcJEJr8OnRi#z5yzTWS4#(X5}pt%8^i7eaW&g}dYwS>qB zKPZm7058AU3b+=br!uVY9Cw;h*kcCVJQ6?9OnK4(!hkw8%Dj@*WBgyC8wGNxv>`wg zMD|024FtM6x91V?ri+me89*krBq#VuYkJCjZdBS%W23g`vtM^HR6W-`tYLVldeIf^ z))o`wvx#Kd$OT@rJn6^_s0g^Q6nypE!sjH`q2zPR&bB#hz~0+qttV477}RWsG(G5$PJ|Md0Iya%6r{pl6xhFrw z>h=?bphaM5#i=l>rSy49uIZePHxagH!@3Xtz4D0rU334avsOf6UG+l4o4VJ@^|TAY z#Ja-xrV$(8z1yy%9^BXQ)ihEgikpIC9kPy0XMo9g&;@Qzx)B2ycc~?i5;eae zXUzRp9R8?6U`rIkimG;-nJLhiBV@GVl}qzSAl1QKN)~0`_)T_(K`ncGugJ8orbhdr zlSZnBI#zaE(KiPs`sNJR_#d#*fjKQlnw2kPkg%U5r%1wjp`pW1hawUOpV!~ev7*@? zLzIY%{vj$d5EU7UijV_v^4vVh`dA5x%<(UN;-6h-~eqQHXhQR4TOiv7!@gqXC^7G7?mvMU<@ZrVMzSu`>q+ zAnoM77UF`HZDc%KHGGd(u%?Z&j2mXdp)8*^N~!m|e1kjtDVMKO^c`0$PgfjBcj-=! zqUn2Cokg@E%)?@V}6Tm)^qlo}z*KJa-UXq!dlc5OM3Q7oBHltte zlHbweL7#TJ>eIU+X^+@NsI&@%utw$&_`nJb{1R&tNym`)L4B-OW8PyZ7x8F@gETTW zo&lms7_-8Wi3?M;_-^(p;3e9>Ah$&i_2#Xo>_0Nbh|sIK>7G+ix4p|yO11+l zGlHlA1;LhW;0S3BI9VWE-0Eb(nV2V?4g@n^hWL~@dIST(p!ujJ!;9YIldGQ<5<=HM z5fTkn8Wbl>N)S4tK4TJWjub&JGVTj*sQ>Hc)LQtXYZcmF=!j8eQSw7Q2u;! z{df3?3MgL3E>Q;eJW~!fFuK|T6^o%^ek;jr@?{1ZE9^}q5reNt<49C#9^)?BL-kc3 zM1#<#ZCw7Jit|fSM@pK8@$73{=nBI^i{faiVFE>2IzEAh1tEBe%%92I^=c2B?g>L_ z!D=qXuG!embf(*g+{Ijgx9j%Zq_K>0*a^k1QM+nNO&5hmnP=EfG^9d*09(z#Lrwhh z=Fu{zMZzwlD7!l5eY+@m-4nBN@>HmG9-|pVFW19QiQ^7a^A2TXB=bC}rUi^X`3AS} z2uq?^JY?I-SB-K{b%I3`Cg8p|O9|k@U+iOM`qj+GlulOWMn+sVHIJ;ZgYGP<$F0uW z=^ic6i~-7OMqPK(dlGZAazObJ2c1hMu1s_BWGzDkda*C#qgLi_ec9oBGB@jw&$s+o zRmOj+&?>BKh&fTw7-ErFk_ZwHz*>?1Ib?<_ogtS$-P%vaab)?bPZ7qk^t zWZ~{uutNW>6=JZ0UB-VNO%2Fr+?Q{-(=7c@X#mwPS0bPnFmH^nU~QQ1)X0 literal 0 HcmV?d00001 From bf60d18ca4b98071037d1a66a1c573f546486dc8 Mon Sep 17 00:00:00 2001 From: Liza Mash Date: Thu, 29 Mar 2018 07:26:18 +0000 Subject: [PATCH 2/3] Updated advanced-hunting-windows-defender-advanced-threat-protection.md --- ...nced-hunting-windows-defender-advanced-threat-protection.md | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md index d45acacab9..66684eb442 100644 --- a/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/advanced-hunting-windows-defender-advanced-threat-protection.md @@ -79,6 +79,7 @@ For more information on the query language and supported operators, see [Query L The following tables are exposed as part of advanced hunting: - **AlertEvents** - Stores alerts related information +- **MachineInfo** - Stores machines proprties - **ProcessCreationEvents** - Stores process creation events - **NetworkCommunicationEvents** - Stores network communication events o - **FileCreationEvents** - Stores file creation, modification, and rename events @@ -103,7 +104,7 @@ You can create or modify a query and save it as your own query or share it with 3. Enter a name for the query. - ![Image of saving a query](images/atp-save-query.png) + ![Image of saving a query](images/advanced-hunting-save-query.png) 4. Select the folder where you'd like to save the query. - Shared queries - Allows other users in the tenant to access the query From 81d91a0ce5572e49dea9d3eb9ed0307dea0e7828 Mon Sep 17 00:00:00 2001 From: Benny Lakunishok Date: Thu, 29 Mar 2018 08:43:04 +0000 Subject: [PATCH 3/3] Updated automated-investigations-windows-defender-advanced-threat-protection.md --- ...ows-defender-advanced-threat-protection.md | 40 ++++++++++--------- 1 file changed, 22 insertions(+), 18 deletions(-) diff --git a/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md index 14306b90be..2154cbc061 100644 --- a/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/automated-investigations-windows-defender-advanced-threat-protection.md @@ -35,12 +35,12 @@ To address this challenge, Windows Defender ATP uses Automated investigations to The Automated investigations list shows all the investigations that have been initiated automatically and shows other details such as its status, detection source, and the date for when the investigation was initiated. ## Understand the Automated investigation flow -### How the automated investigation starts -Alerts are the starting point for automated investigations. Typically, they are generated from machines and any alert that contains an entity (that Windows Defender ATP supports an investigation for) can undergo automated investigation. +### How the Automated investigation starts +Entities are the starting point for Automated investigations. When an alert contains a supported entity for Automated investigation (file as an example) an Automated investigation starts. -When an alert that contains a supported entity is seen, the automated investigation then proceeds and analyzes each entity within the alert. It determines whether an entity can be incriminated or exonerated. The outcome and details from the analysis is seen in the Automated investigation view. +The alerts start by analyzing the supported Entities from the alert and also executes a generic machine playbook to see if there is anything else suspicous on that machine. The outcome and details from the investigation is seen in the Automated investigation view. -### Details of an automated investigation +### Details of an Automated investigation As the investigation proceeds, you'll be able to view the details of the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Threats**, **Entities**, and **Log** tabs. In the **Alerts** tab, you'll see the alert that started the investigation. @@ -49,27 +49,31 @@ The **Machines** tab shows where the alert was seen. The **Threats** tab shows the entities that were found to be malicious during the investigation. -During an automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean. +During an Automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean. -The **Log** tab reflects th e chronological detailed view of all the investigation actions taken on the alert. +The **Log** tab reflects the chronological detailed view of all the investigation actions taken on the alert. If there are pending actions on the investigation, the **Pending actions** tab will be displayed where you can approve or reject actions. -### How alerts are remediated -Depending on how you set up the machine groups and the level of automation to apply on the group, the automated investigation can remediate the alert. For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). +### How an Automated investigation expands its scope -The default machine group is configured for semi-automatic remediation. This means that any malicious entity that needs to be remediated requires an approval and the investigation is added to the **Pending actions** section. You also have the option to configure the automation for full remediation. +While an investigation is running, any other alert generated from the machine will be added to an ongoing Automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation. -When a pending action is approved, the entity is then remediated and is reflected in the **Entities** tab of the investigation. +If the an increminiated entity is seen in another machine, the Automated investigation will expand the investigation to include that machine and a generic machine playbook will start on that machine, if 10 or more machines are found during this expansion process from the same entity then that expansion action will require an approval and will be seen in the **Pending actions** view. -While an investigation is running, any other alert generated from the machine will be added to an ongoing automated investigation until that investigation is completed. In addition, if the same threat is seen on other machines, those machines are added to the investigation.You'll be able to see up to nine machines in the **Machines** tab. If the threat is seen on more than nine machines, you have the option to expand the view from the **Pending actions** view. +### How threats are remediated +Depending on how you set up the machine groups and their level of automation, the Automated investigation will either automaticlly remediate threats or require user approval (this is the default). For more information, see [Create and manage machine groups](machine-groups-windows-defender-advanced-threat-protection.md). -### How an automated investigation is completed -When the automated investigation completes its analysis, and all pending actions are resolved, an investigation is considered complete. It's important to understand that an investigation is only considered complete if there are no pending actions on it. +The default machine group is configured for semi-automatic remediation. This means that any malicious entity that needs to be remediated requires an approval and the investigation is added to the **Pending actions** section, this can be changed to fully automatic so that no user approval is needed. + +When a pending action is approved, the entity is then remediated and this new state is reflected in the **Entities** tab of the investigation. + +### How an Automated investigation is completed +When the Automated investigation completes its analysis, and all pending actions are resolved, an investigation is considered complete. It's important to understand that an investigation is only considered complete if there are no pending actions on it. ## Manage Automated investigations -By default, the automated investigations list displays investigations initiated in the last week. You can also choose to select other time ranges from the drop-down menu or specify a custom range. +By default, the Automated investigations list displays investigations initiated in the last week. You can also choose to select other time ranges from the drop-down menu or specify a custom range. >[!NOTE] >If your organization has implemented role-based access to manage portal access, only authorized users or user groups who have permission to view the machine or machine group will be able to view the entire investigation. @@ -106,7 +110,7 @@ Status | Description | Not applicable | Automated investigations do not apply to this alert type. | | Partially investigated | Entities directly related to the alert have been investigated. However, a problem stopped the investigation of collateral entities. | | Automated investigation not applicable to alert type | Automated investigation does not apply to this alert type. | -| Automated investigation does not support OS | Machine is running an OS that is not supported by automated investigation. | +| Automated investigation does not support OS | Machine is running an OS that is not supported by Automated investigation. | | Automated investigation unavailable for preexisting alert | Automated investigation does not apply to alerts that were generated before it was deployed. | | Automated investigation unavailable for suppressed alert | Automated investigation does not apply to suppressed alerts. | @@ -165,9 +169,9 @@ The investigation graph provides a graphical representation of an Automated inve ### Alerts Shows details such as a short description of the alert that initiated the Automated investigation, severity, category, the machine associated with the alert, user, time in queue, status, investigation state, and who the investigation is assigned to. -Additional alerts seen on a machine can be added to an automated investigation as long as the investigation is ongoing. +Additional alerts seen on a machine can be added to an Automated investigation as long as the investigation is ongoing. -Selecting an alert using the check box brings up the alerts details pane where you have the option of opening the alert page, manage the alert by changing its status, see alert details, automated investigation details, related machine, logged-on users, and comments and history. +Selecting an alert using the check box brings up the alerts details pane where you have the option of opening the alert page, manage the alert by changing its status, see alert details, Automated investigation details, related machine, logged-on users, and comments and history. Clicking on an alert title brings you the alert page. @@ -200,7 +204,7 @@ This tab is only displayed when an investigation is complete and shows all pendi ## Pending actions -If there are pending actions on an automated investigation, you'll see a pop up similar to the following image. +If there are pending actions on an Automated investigation, you'll see a pop up similar to the following image. ![Image of pending actions](images\atp-pending-actions-notification.png)