mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-12 13:27:23 +00:00
Update threat-analytics.md
This commit is contained in:
parent
28ee5b857d
commit
2073e3798d
@ -28,7 +28,7 @@ Threat analytics is a set of reports published by Microsoft security researchers
|
||||
|
||||
## View the threat analytics dashboard
|
||||
|
||||
The threat analytics dashboard is a great jump off point for getting to the reports that are most relevant to your organization. It provides several overviews about the threats covered in the report:
|
||||
The threat analytics dashboard is a great jump off point for getting to the reports that are most relevant to your organization. It provides several overviews about the threats covered in the reports:
|
||||
|
||||
- **Latest threats**—lists the most recently published threat reports, along with the number of machines with resolved and unresolved alerts.
|
||||
- **High-impact threats**—lists the threats that have had the highest impact on the organization in terms of the number of machines that have had related alerts, along with the number of machines with resolved and unresolved alerts.
|
||||
@ -47,16 +47,16 @@ Each threat report generally provides an overview of the threat, an analysis of
|
||||
### Organizational impact
|
||||
Each report includes cards designed to provide information about the organizational impact of a threat:
|
||||
- **Machines with alerts**—shows the current number of distinct machines in your organization that have been impacted by the threat. A machine is categorized as **Active** if there is at least 1 alert associated with that threat and **Resolved** if *all* alerts associated with the threat on the machine have been resolved.
|
||||
- **Machines with alerts over time**—shows the number of distinct machines with **Active** and **Resolved** over time. The number of resolved alerts indicates how quickly your organization responds to alerts associated with a threat. Ideally, the chart should be showing alerts resolved within a few days.
|
||||
- **Machines with alerts over time**—shows the number of distinct machines with **Active** and **Resolved** alerts over time. The number of resolved alerts indicates how quickly your organization responds to alerts associated with a threat. Ideally, the chart should be showing alerts resolved within a few days.
|
||||
|
||||
### Organizational resilience
|
||||
Each report also includes cards that provide an overview of how resilient your organization can be against a given threat:
|
||||
- **Mitigation status**—shows the number of machines that have and have not applied mitigations for the threat. Machines are considered mitigated if they have all the measurable mitigations in place.
|
||||
- **Vulnerability patching status**—shows the number of machines that have applied security updates or patches that address vulnerabilities exploited by the threat.
|
||||
- **Mitigation recommendations**—lists specific actionable recommendations to improve your visibility into this threat and increase your organizational resilience. This card lists only measurable mitigations along with the number of machines that don't have these mitigations in place.
|
||||
- **Mitigation recommendations**—lists specific actionable recommendations to improve your visibility into the threat and increase your organizational resilience. This card lists only measurable mitigations along with the number of machines that don't have these mitigations in place.
|
||||
|
||||
>[!IMPORTANT]
|
||||
>- Charts only reflect mitigations that are measurable, meaning an evaluation can be made on whether a machine has applied the mitigation or not. Check the report overview for additional mitigations that are not reflected in the charts.
|
||||
>- Charts only reflect mitigations that are measurable, meaning an evaluation can be made on whether a machine has applied the mitigations or not. Check the report overview for additional mitigations that are not reflected in the charts.
|
||||
>- Even if all mitigations were measurable, they don't guarantee complete resilience. They reflect the best possible actions needed to improve resiliency.
|
||||
|
||||
>[!NOTE]
|
||||
|
Loading…
x
Reference in New Issue
Block a user