diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/2020-06-16_10-39-32.png b/windows/security/threat-protection/microsoft-defender-atp/images/2020-06-16_10-39-32.png new file mode 100644 index 0000000000..6aa1fdbaa6 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/2020-06-16_10-39-32.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-air-and-alert-description.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-air-and-alert-description.png index f6545e9184..53fb322428 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-air-and-alert-description.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-air-and-alert-description.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-details-resolved-true.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-details-resolved-true.png index 7cd8e4cdde..a53209c01a 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-details-resolved-true.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-details-resolved-true.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-device-details.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-device-details.png index 6791b18a41..53d9c179d4 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-device-details.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-device-details.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-false-suppression-rule.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-false-suppression-rule.png index 435f9b9a5f..c745e92b81 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-false-suppression-rule.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-false-suppression-rule.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-landing-view.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-landing-view.png index e925e50d7f..7fb81ae75c 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-landing-view.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-landing-view.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/alert-story-tree.png b/windows/security/threat-protection/microsoft-defender-atp/images/alert-story-tree.png index e7757be9b9..6893288201 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/alert-story-tree.png and b/windows/security/threat-protection/microsoft-defender-atp/images/alert-story-tree.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-devices-reporting.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-devices-reporting.png index baaea93154..bc0e7986ee 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-devices-reporting.png and b/windows/security/threat-protection/microsoft-defender-atp/images/atp-daily-devices-reporting.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png b/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png index d053776856..df7c9bfed9 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png and b/windows/security/threat-protection/microsoft-defender-atp/images/atp-preview-features.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/logged-on-users.png b/windows/security/threat-protection/microsoft-defender-atp/images/logged-on-users.png index bd5b8d1008..7e43a733e0 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/logged-on-users.png and b/windows/security/threat-protection/microsoft-defender-atp/images/logged-on-users.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/remediation_flyouteolsw.png b/windows/security/threat-protection/microsoft-defender-atp/images/remediation_flyouteolsw.png index cbbd6fe0c4..111080014e 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/remediation_flyouteolsw.png and b/windows/security/threat-protection/microsoft-defender-atp/images/remediation_flyouteolsw.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/risk-level-small.png b/windows/security/threat-protection/microsoft-defender-atp/images/risk-level-small.png index 0c18a9bb58..e3a9209e29 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/risk-level-small.png and b/windows/security/threat-protection/microsoft-defender-atp/images/risk-level-small.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/security-assessments.png b/windows/security/threat-protection/microsoft-defender-atp/images/security-assessments.png index 86aa56fc5b..59b4afdd53 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/security-assessments.png and b/windows/security/threat-protection/microsoft-defender-atp/images/security-assessments.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/specific-device.png b/windows/security/threat-protection/microsoft-defender-atp/images/specific-device.png index 35643da1b6..c468b24077 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/specific-device.png and b/windows/security/threat-protection/microsoft-defender-atp/images/specific-device.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm-exception-dashboard.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm-exception-dashboard.png index 59b200a955..0d1b944bfc 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm-exception-dashboard.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm-exception-dashboard.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm-software-inventory-flyout500.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm-software-inventory-flyout500.png index 2387885bc1..7d4da85108 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm-software-inventory-flyout500.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm-software-inventory-flyout500.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_exp_score.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_exp_score.png index 91c8b6f77f..30fbca437f 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_exp_score.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_exp_score.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/windows-server-drilldown.png b/windows/security/threat-protection/microsoft-defender-atp/images/windows-server-drilldown.png index a9742245e2..befd1e5acd 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/windows-server-drilldown.png and b/windows/security/threat-protection/microsoft-defender-atp/images/windows-server-drilldown.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/onboarding.md b/windows/security/threat-protection/microsoft-defender-atp/onboarding.md index ea40a6c333..c73e519c52 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/onboarding.md +++ b/windows/security/threat-protection/microsoft-defender-atp/onboarding.md @@ -313,8 +313,6 @@ endpoints. (This may take few minutes) 2. Select **Configuration management** from left side menu. - ![Image of Security Center left side menu](images/security-center-left-menu.png) - 3. Click **Go to attack surface management** in the Attack surface management panel. ![Image of attack surface management](images/security-center-attack-surface-mgnt-tile.png) diff --git a/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md b/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md index 4499b07fc0..4efc0b82c2 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md +++ b/windows/security/threat-protection/microsoft-defender-atp/review-alerts.md @@ -52,7 +52,7 @@ Other information available in the details pane when the alert opens includes MI Clicking on a device or a user card in the affected assets sections will switch to the details of the device or user in the details pane. -- **For devices** the details pane will display information about the device itself, like Domain, Operating System, and IP. Active alerts and the logged on users on that device are also available. You can take immediate action by isolating the device, restricting app execution, or running an antivirus scan. Alternatively, you could collect an investigation package, initiate an automated investigation, or go to the machine page to investigate from the device's point of view. +- **For devices** the details pane will display information about the device itself, like Domain, Operating System, and IP. Active alerts and the logged on users on that device are also available. You can take immediate action by isolating the device, restricting app execution, or running an antivirus scan. Alternatively, you could collect an investigation package, initiate an automated investigation, or go to the device page to investigate from the device's point of view. - **For users** the details pane will display detailed user information, such as the user's SAM name and SID, as well as logon types performed by this user and any alerts and incidents related to it. You can click *Open user page* to continue the investigation from that user's point of view. ![A snippet of the details pane when a device is selected](images/alert-device-details.png)