From 517a6da6fbf9bb6488d67b9e7fa48cbf9ce3ce58 Mon Sep 17 00:00:00 2001 From: Beth Levin Date: Tue, 30 Apr 2019 15:02:55 -0700 Subject: [PATCH] updated text --- .../images/response-actions.png | Bin 0 -> 16289 bytes .../images/specify-collect-package.png | Bin 0 -> 16850 bytes ...ows-defender-advanced-threat-protection.md | 44 ++++++++++-------- 3 files changed, 25 insertions(+), 19 deletions(-) create mode 100644 windows/security/threat-protection/windows-defender-atp/images/response-actions.png create mode 100644 windows/security/threat-protection/windows-defender-atp/images/specify-collect-package.png diff --git a/windows/security/threat-protection/windows-defender-atp/images/response-actions.png b/windows/security/threat-protection/windows-defender-atp/images/response-actions.png new file mode 100644 index 0000000000000000000000000000000000000000..87108d3e727d39810a3180129e794fe3356542bb GIT binary patch literal 16289 zcma)jby!u~_Vxy(OS)T9O6djx>5%Re>Fx&U2Bo{Z6xc|Ew19MX_olnP#rYl2x%Z#@ zeCt`nnz3e%G2VB~vBDJPB~XzFkw732s+6Rd5(oq<1N`ra00;b*GaiKn{vg^(YC3{I zXkE`gPzkTmh=4?RCn-5``1Kd0I1I>lxNqkFN)p#_5^;7ivvmNKR1Qi4NhnT0l9-93 zv4gptlew)82n&&d3P?wKP8YScb9XQ|HFE-$qYv@|sc3(tI+z$f7bSNxw>ANBT%jWZ zIf&0W%C?`JTn!yeK)QBM&&84ddbzoyv6UfE)B#lAUK;}>BRnUo8#>sS+n9pdiMB$3 zH2D9k@9bb~0=jq#*#A>Z)YjVC#KsA9Ihfc6q`^HGQ!#h4G65As#%Mtxa*&jmh>BbK z;i9KTyvd``F<0jYY@V>dFMbVM;a^fHc!QH48M^x>!$+jcma7uk(LHfiu5#-*D{X&y zc#prFUC6TDqHjxkh!mS|P2?5FOxe%XXz0n2#9Vs?A2L386vJ~oI4D5-DfsKrw6lG} z)fxYlqfpUZ%FUp+opRZv#Y>Do*W$*<2VD^5pDWkjuS4n210^M^hP2q9>&1WNfczx1 zwY7bd{Nenjrlua5p)q(2u8&tAbYJ{co6xVcwDh(K0XHZl9Jhi22X^pbV9Uv@=zlcTp4WyfEGk@& ziPvi0^*c-8c(7S`5W()~=>Oh~=(IX_Gca>%jup*bY$r$4`A~mryf_w?Of*>a9%$jk zk2)~8G~;Um5)N%!M@yE=N^1XGA+JQ7fRx{}7!AUfmX<8wz4t?|&XVd*>kv0zen%O2 zm+ku1eO7&|1};z@0UPxmTW1J*y<b2ku*{}dB zu6>Tr@s$xgKP4gWf31X>Wa&GXPtWNiKKN+)@*O0CJwau?I&d=Z z?026F7}#|!e?C5aSX(v@F*I&wXSKi=_V)Qwg)A*2)^mWKXrV{!O91pvnPz?AVVK&#BuCJ z@<~@*6z=ZMihWYW60C%@@1hxuJMfIrTzRLM$Ck82Zq8etTj z^Vtm(^Ek*5&&e&1C2F2?8N}pO5QID}bL9J!{QO*y<7TV}df()l*HS?uXH8P!Ug8ka*$ZH-jC zm|EitaD|SxU+pzJ_Qa(_16#rdrC^EQi~mXsiT=9{Lo7uEC^HnpGnneN3`t|qOEtBnZF~F6s%1DSJDcv3mJGQzAq~9&!FX$xM9uHPhuZsFJ;Y~6) zj!&8~FLL$<-1aJH7`>Q@+v@GH-~$R0wc>*f4_`afKGH**E3T4}Wp<8HO)BzM*K6A2 zxYY||dlYw$x}x*OItqnp1`M~+b#3couXRS%_-)$mKDF=`wjtAw1$Q3RXYWGDiLZ58 zX>OtAOzI>TolzBV*o~f^Ce~e_>Iti`>$4XZ@z}N&KEueg*x#68{cgNQo2}9i+f6ZTNTePF^US> zBH5H~Us!i=jK^Nl3jDJ03Ha3uK3dNt#L(o>C+W1$A$tt0o}P%U7IyEtCe$dx`qVyB zy%9T8_?jI#>JVXp9J>|Hf_fR>A#YD0k*!Dv+;*>EX1Uj)k#tUrw?TG91~;nq(r|D{9=5{sUbun+3;RU|STXE_mmTOm_Ck$wAz^8j$ z+-BzZnu+^Zk}lJC2bcJ6Sw!Q0-?^N{X1pA-AEr3$!)QZRcDMJ6^~s)JkgSh)!q-rN zvdQgw{c+QEec^(sPOT7NZ8#&-HhhPJT#-!9Xn~t z0!U*@A5!eQUS(rsG!mlNzr2Wx6)Ts8Vkn#W6gh~H>6bAaMAvkT4C;eE*?A{KOke&^`N#!nP&>$}IXd8d+nC<{8ab)w zTUZRZ5@+t)+*-?~TI473joSB_15P&@Gd@ML9WaAzd%0PkMslZE zpB69=Pj<9kOi9KJsOsKopFEo5WXcl;g|&W}m)wdXK#%N7x2;+iOUt_(ah{)YN{Wt( z5-%4SkdTt;JDbO7;zkadi7_=YuG8&^YVx*xBqr#UDK`s@=NmD?77-<8j&>Q-|+XQ`XOO}vEJ>dhkNVPu|QllVmKxw+BZ?Uj3% z0Fxlx;h53cxAaZ<<+-c)C}WY)q8@tBS`BQPa&z_?A6M9efB($BV<(j$6L}Gw>XkW* zjNJ;Z-X=^T4k)lRKh!%yetX?3+u<)HW;E8;+Sy{O-*d$j4SqWb)}yBvPOTo$P}ol# zYj$It)prQ!0Ix8x{eNgufU^hKb z=zXVGH+D8VuBtKpwjR)3H*fJ>aX2(=4m}8*4-+$y1H71=CQ&2AbVkk7zrDofq-*Pc zpxj%tpjq7T(A;~h;#qE>9&?5>Oj@5~O zSobuxG%(gYsIR`x&X+}Ec!M&K$MW@+LMQIKo<(Elt3(=s3v$I;cd6kUhuxNvvKq#6 zTc-y(tpoxlJfG-^$~?_akZbYYqB3LIm{A_*Z4kAYz3E8WJ5Pmpt>GWEQpK#g84Yup^PLyzjr0ogJYK9DxN# zMj>yX(wRQ4{&wRSRm*x^zEkz)UM< zD-nOoS_xhIF5S3m!4zqof|`9lr6DWw%FxNTkff~sG;;oynYA?rc6wx?X%t6A?pn>B za9NK_cjA1}JpEDr79Cy*dL^r6|49M&U<3o`Fai96Vq8B@sLwP%7%?P`Vb&@?V^cfUz~+PfACStui9ea@TAw*h)MnIuN}>yy-AfET;psKa1d z3t84IFKJ=*y>p*_+e^**!>Pmu{O%^oxVjlSgN7>tFP9j|z1e4f&Ay4sHt3+L!+p)= zlxM-~5=54BkBIo-#g0U)Uqh>7q2VH@S;G$X)BMV)J83KjWiR&Ww@xHsEWi8B zb-F|}REpWDL`(DW7KjDayKiruX_hi4KBGQepf271{&rI6PiZv^|B((`kuI8C0P<1^ zmdq+o8Hf7|27JC*BN}p3TVgu&`Qq?ttWK@?*}CSS1sz%u6%i`^_b7zA+h&vl%I(g^v(4c&H&SJ@j zb_^IesX7h#0?5ZxrStcj+KHIp4Ng1&z*E;;l(rk!OGSP2&JluxMCT%AFpxFmgp493 zb{UNjz_P1!(K}YXF|m;8{ZVD_Nl#r?Pcb{85 zjpJ_C@rz4eD`Mk?vC8bvIFV`0P2JZq53wCQ`o5wX8$2@)2q@vEo<5`{5KrT>Y-PW^ z3v*a=>IiMqQQ?pcGNop@1R zHG^TuIw)bDb52N;XLi<+$#UH@eQn1}8C8?CAX;Y3Na8zuaxt+;(B8^Kx5v};yQ(ZI zFxYL?%Q+xJniA>Qeyb^fp>(zIqX2_R2dq;q!;xk+2Pxb`V$Lm)Zv*G-& zsN|L5@m-mjC#$WStolCz4rC?RLj=PDOC z%h99Rz>T3-y|1m~Edi9>fV?qeHS=!#*3}vi`_u=UurDY%#wxD+(fZdmPX2|qr}hW? zHQX+@%kO0#qsC!P?ZGSTvWe+}!8Q71qK{lHHlz|8#Avm2le?~cW&m|Sny z_FvC83*WgK%gaKOzUB>LsS}BhIBG+)lJ)P$Kgh!~cFu)h$+LbMP77j77~5H7%r9b^ z@)1VpS)*0<`;Ih(+&u=SE;`m*c%Q$cPu!uA4#uc)dMf9E5&wXc8E@5g-H+XT735tZ zQ^em^xSec-d5q7X_<`ydS@P+veP88 zX?>zd`FC3b4tLQXlw5|s;pE;kfMmN{6tLGe)ScnB*Otr$o}OwqxWA}XuyRl1+}`;z z6wYzelw7PMz8^#W;`qif^YAJ+YI@B4s*$aP_`#eTZI@-YH4>KMWS{r{Gg0a%OOZ4HxAfQf$@~-kBv(PWQcEC=CcZ&{R>Un=^Hj8f>7Nrh+Wxp z3!J^ANxw&dU-K3av=-JLzg&C!_7&L(YLcZ!gWea2kI0)*gt6_{H1+*kNi6$5a|797B)4nH^+BP3-+jqgDV9_{Fx;Yj zbbI8W#yD};J1lv!PbRJ$^GoRD7w_NFpfKv$6^dd=25-OsJ>-z*RZb^)rIjAww_xh|(K)Uf!6j;a1I zc;A_Ok{6|Zeq5r_3^{Q}D-ef9IH%fi2YJ`qpn|Ba?kY#XonS<#E%Qu2Tp50y^~#1# zL_fgNlBn#WF0sGHq9pp;Eeh{Rjiha0;L0GGso}OUmR+wTI*9Z*ixtYeq{a>cdq?BJ zTl;>xR1r&MqUEfjErMF~p-W7=m5WJt8bIREoxHC-;ttnsQmcH~zqsO0F}*Ih5HL7# zjHa;6qOWxxYK6w$D9Ba1(yLXXHTU6>LNf6Be1rFs1&2EzfSaw?>}Saj$qD1|Lm2L9V(~d8^N2}J$>~ipyfBm+ zA~@rdDX*38R|{vn>|fst*bX~oav~k~q=P@j*TP)65wTcxPCvPHPVl9-X-nw#jXEVw zd9InWS?Y=3B(*=X7=K$P*NrYFG$@rC=s>=fSP zbeQ_UhtLPQNDfAvPZBw3%5k-a+|_!XB$+czHsTh!Xq#Z-;hV!yZ?(o{99Gv$6pfZd z@W(L;txCh;rPnj-B%hmwWC14$aXS1+No`x>6}!~C^oC#6jnDvE&b<~5-nEY_mT;Q%m|&59(JF}g@uQjG`IV6`z%tp%u4NoB+Gy|)8(F5*PNfG0q4SwU?mwAn zt!Y`5;Ng~_N>AkF5{JgZr!Y^$>6T}HO`cRd7;(xPe_{MR4nMcQekU8ukJVvH0g ztfeCg7cc0G(*L|*2dmbrl9!9Xt%8l-NfjgdktsI0R9H`spS?+;7sEQD*o+M@)2a!= z@h44uC~=J}1fnK`DrM8-ad+*%>VgYZ%Wj5ge~-^^k5rmUR1xBc+lPAfpK2Ajp9ELP zDXYynF?u`N!cn|MDjs>Lc{U~a6@2ULS#K&xEiu65^zTm5f~3mm9D7*=1;Z?+Cnn)& z0#_T*t5*6H*1w&qX)l>GsCaz{(T8M$ngoCC?UTt_&gnF~re&&G_ckkfCXvLxNChRM zq0Br%qV%tG?375%WxOlQgJ|8<%9y6#w0Og16oPTr*`j=?Q4mFD9kwAf?jc*Pr9z3p z)V|E^-&5 zgHyH3@wHSS*FwfwDfyaY4`nj<2`-r)?w(bSD zq{Q&Px3sX*{(7)7P{P4|?yfnY&weEh!shBEm&CR`U+!psjxG~?##CSZ##3a+o(p}% zq#ra4>t76rlN%Q$S(a}OqR#|gb7%;I^}zBT*aRooe^{Tv4zB$x$WG?fr*3Ppo~iB@ z->?ZlrpA!?Z^S9Sb5Os7q`P_~;;F7MywW$bU{FMq?6E@aS*r-rC>KcdbZMkC;3Y;M zHt#-)nW8e1df6jIgHv{M%ZnCC65ZJ#bQO&x0Q;H1+*YAM2C&lGqNx7o=z>n(r37%F(Z5itG`Bq zn*SLx6_sdA`dv|j3SJO)>mkHN$T*igDWzrtxU1;z4es6qlSE8f^1P%`QOYUVz*LHv8>h-4FO$REd&`8W& zkN+}RTYwSM-hQ{w?vgQ&qJ|YO&A!kD*A6N9PAPW%EUQi`uO9rPh$lc*bjt z#y9nhFT4S087Qf7-)>zo5B{Ku6Fxb|!e`#TY9;m_sz2uHG9sx^d?K^dgPaB>&fZ?q zS875)uF0hoI$Y&2sf!)|g{=54ugEG!dkK=rF*RBoCz+Qol7v=bbz5mptY$J%J#3M* zTADe>ZlCwdk2hM=a~N)}Dpgsce3>LLJ^nIs2Jfyq%Gg;*Jt?Dwb4Cv89yJIPXRcFf zY$0;i?wccmO*k4Qie^H_iIiM=>R+{x$9gEddv((Fuwrzis=N12l88w3onga4f> zrj9M+n%I^;=?4_E5Ch3Tn}wMLJviB+X-&>*ji*pmb=(d!Bg{M;r!2=v%_mv^Ip_m= zh4*j4D+W@zTV5I^Uv+SsYmf6x#N32lNQc1%F?=+gGOn~iQKE$dq($L4f0o^0NtZ6! z1!mxkc}-t>2d02%K4kqHB55jAnJS4{qXPj^y-$d88$nFn*Jfg7c2-!&B(ko=Y5(&O zaglajm3SzOTR$a|R(|*Q)tRB2)&UUt_HxSISIPiAt=upj9Ibg7GySch-G3znd{Nx$ zY|vkl`9{hZK#3^5`YqS3wXl2Q8`3oKgjhLbM?hZ?pGWb+ry_$R!Y zThyzKs?0BaPe)oazZpPzzvS4b`cT4b(6r$d6;|u40XmF*fg4=}DMDHS(>-uh-tFZd zVrlU_Xz^;QV?ElhSPnj_1Ua)TL`}o%WMhxiyN$u4OWW^d2Th88GGqoD)QrQoqW>&^ zv2uO~Z%_C|bCG00-^qgX%Z2eT&0l4J&)I%TR!fI?!I+z3DpmBB*=*Ed{aZ!tdIt62 z_g!R#hi?m+)}oXb%euLn{oJ)ZJ^gQ`9in!#o@XB;yxx6p zgc+;z(M^6o#<~Z0mxK6aX>5k(=PJdZ1KFWh(HBZ9jxc;Ts;Zfh%?FZ4fg=n7eHeR-yHOG$bm zLo?9U^>Y?^_SQ1;Qd+v^O$IVm_SR5H`NLKkfYL9@bC4U}kWY*j+JQ8Lvf(Qzk5B3k zn>g1|WFScS zHwN2x)p*b2S4oaghOZOVnW3ZOhmJ+bQ1Z2^>8LSM_O^y-a%lH*U!yc?g_5mlrJb;J zyy5|koQtwCP~IC1hoTdvQZQv#3^Pp)!yPTLip^;~gdyyej~R1DAL&|`JdU!KTf!PY zX%BEx%o{%$xiY|8%_B?ZYbB=tSksrJ;m7SAdEy42s@;6ez<}M$Xk=h6G;Y;o1cbml4Ty7P;F1T}# z`?|77V{w5YTV`w;nUn-yosiUgt1--FJWqYCwzb_3+WF=-4MXWYB#KU9C{T zYd9D6E+a!LwPA}~n?;TrH_s~KvuGq}*>OmBI7?PX>zR}WmoPBX8yp=QYGh-WBg)s}I%K5|5V%r}&3&RYR)>)g+7$&8ED%lf!M&wi68!-X9+8P2~UJzO%&oc&Nz1iL#}ZkK;S69K?gI!u%p zoH@%1?WOrU@}9A}M5l~|rK|{YFF_KMCr7i@**ElAhF^d0Oi)QGXpcE&6>LzjY{r7A zvuK1#+TKr3vZ3|U2gil(0EZ+dGB4XS`MiQwmGBnQ>?LEkgRZYt772FTnT?cU(RRPR zqSE|s0-VYa`=1l`Qan@}hH+rkshUOeP@^Ns^s?xxCoQ85C6~md;7=G8&^fn>f46)y*R|4E5t1o!6y@4C7T5Qx;^ITk>? zkyp=?bZsmy2_qy|ug<6TRIt|6^RVR;B@I-+CHvPmvlq2{9@1t_ti2{1<~=GeKrd!B z^wWIRx}9ZT=2q|rJiJEfKV`UwnBhS5ZJd_r%Z{h$ai*TK^f;-|rNrL%m@{f7Mo0z) z-OlbTzJ9PWXz;D|MWW!b@p-QVXZweOUhQ}FGSkN=|n zQxTjrRC`5To$8?*Cxc4*J?-~5qaWY)joc28~kC%`2Wt% z0W6@l#zGZr==kd+KjG>%p6H%_s!ho249rkU^$~u@s#IM_$nf{icDyyDjy0d{=055Q zc@^$|5_>2wBC6f*$vw~#O6>nyn=M#C^!S9#RU!vt>u znnaC$Z_1{vd9TkdG6dgyo~{{lGJ3$2DE78qjj>7S<-liNyK5ErxrdgV_#0!*@{9CP zxbn04lR-V6x8h8}AuqVD6-Xo4V%}3uxC^yo#A&9gIepw6uSFdJ74d zewn+=Nt9%t?<>ePaL;;m!WZXyiplxWHwymCPkRYX98Mhq=2E?9aoFwq;+Ip$lh;H1MsiJdCSV1}PAi1^XlQ=*Wsab|7s;`p{3GT(?n4bCOU z9CWoJ6;G`0L`cEa=r>yRcv^m3O2+p@Mq8K+9u_L=&9!i~k|m6Sfr3ocQxlrWerlX{ zDXKU5TqR=8nCWw7c7KQS+a@A9D}*9|s=k>yKON`cTBROrOddB4%p-~JPA!!EY-Ime=IZo`&*4+4Q4 zQI3$WZEbxzEmAAXAY?W9C)~vhAr|hvDg%xR15RUO<9P)aywON)US3{Xgm6G0GdIK6 z{`05Fhc=rAwtquu*!!fk<4aW-oLpV=%F2*QNJwtmOQZ`3?K;N5VDMkv8CxlCYU2C& zmVlq1-B3=qeL|B-_CNX$9SKvAk&$6$Yb&9yj@Q`KbOAN)pWo2X@Z78)v*OPs{^7}T}V{0SIJlj@~E+}nHS>B(n9m!P=x!{4tx`;nP6Zk&U2qSJJS z73J*2zrLP}pP&C6N?9VH&`R@93={i{bEi)A9Bm?YSijiVSRZDBxU-3=soa(plFZD^ z9f-@LM)TXE&3{(@q31`Cxv8nCFJ4$5H7_6E=;UMpdi=kuBt|n~!J%T2;FC+6n23owDVNck@3iMiCp1Nr|1A(qZd(6?ijYpn-Ind2wFe@L z{w)z2`oDsp{3Lww{Qg8f!3FEjHy&>fTiWfsqpGZTg#o?yXrgkr0O>WFvcJE18!skG zbY%BugQlfxp%S-FgyO~McMqJsJ2`BW!rv;{ja^u%{JC^?k^JrKEtr`&z~n2;%GT5{ zER6$(ODFB$l^gq8Tyvn>o~n^-Sx7=mAxKm3fUY0b4&FA6{>e40(4`-~f4md~mv%PP z-!J0h(<*AB%#hGGIM~(TxJ~@aG`re`KPoCpqt0S7mS?FW_@9Wg+_agiHt;%2w{xF2 zD=|w}anEeleBeIporl4+X#Ey(-V{bWdSPZeh?|l;?6A44)@%JhcJ$ZSw%Y#`MklTtsd~8YzA{iMOJ0~Y_ z5_9px?SvA*&GGazU~3|1XlU6}Rz3A31!rfDsY>05y*&$TTwKD9tgNgUp@&@swX@&D z!xAPY)F6Z5Oo3Zx9HbzhJE6yu7)fbq=!YS4L6ESw zw}4uOR!{^U3ne2Xif!u+O>S=PxjVCNBldWa0vG*Pdjh9T@aA>TfiWk zOhJm}V-kx1B_(0`0=ak0#bpG=a+H`Dd+qUqB)bYee8jmgCx49GFPq}Y_MKG$3Q9|; z@zG9!Y&A=89j%53WPwMg$puy4>jc)z%gb(ej2a}+Fq#B6wbzB|+8%ED)Pnb5H@r3atO!}%g~i>-|fgDc45&vg#wabSm5n~&4T zX7J*C`0&AnY*{foIK^{m)u1GeTcdP9<5s^Dk6hmen38I#wqx_hWx1y(Kv6?j0{>&f z=9*)=R^xy1G`K)fNPq+p4Ilij=7Q?CpjBN~-_|(rI);TwPtg#Z3ae zBqNJa5PHC#oSZ~JMrP|1bs;gO>Vr=OY z&5!JN1<K{6UjFS%~wIZ)9@4XjRx8NpfT{@O~7Y$Mx{LJMn@fH>g zzPEA!8?<+>&hnc<2XuhVwyLTs0xBv80_N@Yb^GwJ0@=&>w~$*jv&Mo5x&&!pc2;Li zvp6Ktk&(yY`I!(=P`dJ^z6L_clI)H^`_WXFs4&NE-ow!HJzDVYa@#=3Cx915MINT(efM-Luv$r?)q{;SECK$0}Nl~SC zg{xzUWA8uZz z_iXUjFX(JUwbXTBDWtyA7>*ap-Qs5cj{o{KAT$&qUBDApcsRL8P*CuBu=8t^nmXQI zFbU_RM+XOiX=y}&iU0UE<)K4~i|dC77M*H|3ah6&&_AjNm=&^@W;UvS_ngupE_>wz z=MyX(EEPE`!XuPF{;sWd+0O)5xYb2p&g^o%g*6>QRsp9RjHAaIsMkj*-|x8P)4Bam zPaQz1xM_`QG3&iC5~`{=f;Ssj4~_gf- zuWY=pTun#oNKw(zr=OaB{LpCAVNP1F@_i_KOeP{C`k`mC*x;CCoY@Mbv=d$USX*KLg!H0X)yJIn92p0k9E1q1DmuLQ>@CMf zIgGy_F^wCzI(o$rTjK_VkeSROO{QjNlk=bUQQi6;&DF^)6FSU;tu@+wT72HS?#f<{ zksAO~v^AVnHEaqf+*^Z!69-*VDJiMq^75{99>??j3Y~_rRm508T~#~nDtY5w1N%L| z=IVJ1mQ}S{I1K*YDqU~VY;dl9eetj#6_CHUxVUq$_p|r|1;{TN?Suv8dGm`b$MhF= zyqOIRH6vet-t1?mr{96iK41=jByDY?)U>qGiHSh_^&W~>ue$aGCoEQu3*I-o-7}0q z2%=~UVLOJk$0=^!7a_q*6CTg?Th27vp(M(o39|$Ty>bYjo71|#UXMAxx(dn4BJ=Y0 zUOhZSb#=X3a_;0ZIyo#*D#->LvKsu^0))*A3w|MaFtIN=pnV^k;glU)J1<=1Y}ezK zAd;Dcel>uNrV}Ys&dupMAgKhD6+X`7NzI7dYjRfJ~J{*0qEI2vv_;qT(x?`I$P^{>+n); z6HGA40MY6}y8vT6TK{5JTU(1TE)j`8+DlDAN$HRQkv}=;Cs|yJ!RhpZyXZxwq-@kI zQT@3w#d+dscWtMyo)}!LPr_*4o*GkXrFHdD6PeV#3OY+bprgBh(g79x545MGNFa3E zT`zO7cKlurtKC*?{~;_?C*mJ~Ly76Jts~&mxLZQSbM%fsAG8);K6hWC}$R@KaO)iCG0p{@3+!AwUMO}?d zb8AT254}@jn#{$zGTnuW_gglQ3!~*CYIJmaK?o$E>GR$7xI)lwO_4bAcv~yE4|+5j zA+zk!&P)BPTg!`|=PUN>LA#kYYl$G$WgjM4^px~hvRAv0QpuHj*vmo*>cFa9(K5d* zeA1v06lzmbMIMI{4G7v*ui`)&_xA3(N^5Ac`<3B}JnqeZL&PyEoTKE7Jf0wJ-;%$F zTO~B8u7m#CcHw2AClIAO-Za!gI=S}X;TC>opM(nW*cxeF{COUx+QOjrP{932}UXu$ik$=emg1d&1TfVcZs-4Cr2yNj&R=*RF|SW25rD-sL4WO{ZyK z8*58liAb`b)yHhsmI84vp?c1+dF`~oT@#`3vm*$$5FQ4`+R@@V z?Gm#rIx)SEPk($BOqL<>Y+`ZS5B7h6t60D^Nj*yEw}I)P0o;4J1v6P%kJ^~m;bI#~ zC?{Bd>&dv0Fa2w3zd(wOE|~KC)HWRVc21yR&o>8R0q93se7lGS1-O2Ld{~u_1)F4y&l%t9Egvb0gw+qXC74|QXr_NY$mlCy)qCr8 zJMp57NwzooyvtvLs@kK_4Vo>tqrHGhMy8boukfyTE^rq|D8keq9Sxse*4DxTx6oIg zYN_hixI*&M9DU})NQ+GR(=77ZETU+0cMY?Tr#QdNdaaak&@L1d6);Q75x(CVti#=0 zB&!UqxMiJc0POrQbx{5zb4^p)#3F&4jLTktzH)JJn6UgUTUk|8h#TQ_r48GrJr@`H z%}O@pL7i^0V zfz8$uv@142Ht6+u^>W(S=F?JupBtek7u(TtCG&~Z)}n>IASq}VZ}pKU%3{$P0=z*HQ^ z=}CqX`m2rykh7_qV4`A17XGosi}{VJ7879Sj=>{VnjT=)_kMh^OM;?kCABkkiVw#B zm#W$*wbeSU=6G)=bN?dBgn(fM`I;tw+*|SqdhsI}ON4845xr(%dB$}odu3Hd0N!t5 zwgoUeXaxZCJIp|+VFdB&^BG# zpYMEFa9#GMV`Qx5(RfDma%r4~0J{ne4~J&u4#?l!+&UrFHy-#{!EWTFG(mntm{o!&*Na}Sg0sv~*&CRujPoZ$o{|>KDIPW`A+q^y` z-p^c9li;1GC6+d!}7qzF_j7bYTIV>!OO`|2#M- z3qaM4?d|=hHJDW4gHqKp6tK0`ge-fZ3PW5$4;M zjb8_ML-FR{{`wdz&CUJp2m6y@YpY8|l~R~QR1)gxtmk2!-KtU1hVn_LiJ?btVA#*| zGC*j%Z8jMX&ROy1=xpT41eW1b>&#`T)H()UtE42|t->E!a%Mf$O|wevtL z>qsIhnXh}fX0YHY=?Bl+?NbriBcLSliKu0-&MFFX2S?_1`xy#$B}itiIeC zc5^(@7$oIto_5E<#eK(|1OwV|;1RrDfq7odC z06WX|+eiVX*v)s;39s4zo`!~&+nF3n!@$oS;GZWU(NbbCW5*8H=IL0S+TY)khnItsbmiXQM4^SDE zJD3LB+&>sm1-qN^lJ_o*v877_Jg&9k!`kEW^)pmIUXBqr3QR(Awq8^_0~~+PEVfd& z>3ng(KXY~!;0PG__{Fxn=CU0g?dZ;j8ns0zAuJrZdmgk~%UdCB z`c`6oF?^&cm>_+H0YhqCS4UkuuM7b0U*Fv1l$XmsJ$YV1CRtb*87CCRKK5Uqtbb5d z4N?%i5zD&lr_IVPDCmZ$6>OdI*{{8ThJhI!8#9W9gaY-8w*Grc80?bymNeLLJrkqG zpN8=HP=*c{XY3A4o53r%#M03dES|=r8j;AyKWkj!sqB)Qx|?H21;PPUk{l_t_kTp) z3s40hKR|5&?i4v8wtIlmuL3!KexSiDA+i|$(@-BZj}qV!VC<-5UdR4E^FToR>V_Qn z<>u8PU7)$GQu1KRm&4h%wxZ%%0M2%_#CV z)IcEbO-*Ted3o(*W|AKnsW33&M72_@kjGn^n*(<(>a>!VtUrN`^p}^0Q2>|fg#NY9 zD?;997bxI;ZfY7`T8ajPIoY|m@=8h&*L$KwB_%_3Z**;sdcvP7yUy4o3|G72m>D=e z905+(wO%scz_vD_`}_Nq{e5IxTiYK^O`-Kx##)x4_DYlJ&QFo9jo{;xm?p0 z@or*!1~u!C%k!LnaS@-cAPx6FKl%J0?)roDm6Dp8an((70QD0%)?CfWn0x~31KcLm zjP)-c#qs&Zb&i;KccH=VWSKe?h=PKGnF-~OF(er4HW~a-HmO*m0^ETAyElr6Yh-RN z9FW~eBCg69X{iZUpN9+e+WPvux;mWBVAKG>6%9DjfqP+Lf%w-v@M6G5fR2+y{)T6{ zt%VT-$$0>+mW-0|zaPq?LN%&6zfD0QB_$=^ zj}K;i_OrXW?F1D3MoFII_*Z41$~Fp@0RI2yRsfm_Dz2zF-2Q^Wlk~S&ok{kNN#mFP zD}d{=o}QogvP`P4Zf?Q?uLG8Fzv)$&Ug;S7;rxeRnb`B22BqZQ%5Nr5turV-3 zg?pb}syUv5&P)dji;K@S6QqL@6LFvCtfmI*xfU?JWs?s&MwIhXzAui?&jW#$n_F6* z%L1c%@IETX{V%t^WYfw%bS^NoXE*-d-e>6o;NII-!kks$5-bS`fd__iE_5!{w8n@0 z?^Y4@W7c4JsBda&Y89u~P8c&V;kQq*DGu{F0*-|KzF=Yi*UN-Ook;t{&=4vxbGPIr zkQlS-IG37fSPAD2IhDuaX$_Fr~J_%@$O*7=F0 zJDVQ$eNTttZd(Syf8{GN!p5YNXi)BOJ~8$8n890yKiv`&6D9k1AYx+w eW6%3Nq4Re0R2-c!)dF9lgQUde#VX$!eExsi=qsxL literal 0 HcmV?d00001 diff --git a/windows/security/threat-protection/windows-defender-atp/images/specify-collect-package.png b/windows/security/threat-protection/windows-defender-atp/images/specify-collect-package.png new file mode 100644 index 0000000000000000000000000000000000000000..facef23f13e8e2069b75bef8e0acd5ae5b264fd9 GIT binary patch literal 16850 zcmdUXWmFu|wr1n*1a}A!Ttaa71Pc&Ca1B8kcXtU6!JXjl?(Ptzk;WYwcV{~H-Z$&5 zS?j%-d28N}`BB|#?K)L;&OZC>`o6vQsW25KSqxMXQ~&^gAulJT3IM=_Lk}rrM5qL$ zhkFS9L$Q_n<^TX-_WeCz5|}Ybp+Y1_c|~cYEqDq7*mrh7gRy^zq%|GIog9DI*aM0y z#^j(PbVsO2%GANw-rUyF+{PM!heAyYm81TZOWN4F*_)gFa0HZLjR`=dnE#O4n;QOY zO66z{GzIY7Vxd6Kp!_|fX7kjEBZf@>iY-I>-Y7c1as*8q-k^hRn z8roZ%Tblv8NOwb^GNgZA?__Um3b=j^fc#rCNgE*0)Y=hnGnUv1l_CCZrf%+NWeO-d znPvb0r~vX(;_9yH$16UX>ZYrrXN~5XOTXBftPFOmPH59uxy}&E#TBMBW_j`yO({d) z_b*AQm9lEHbAans`qmn#mvE0t>X?69Za$R0N%>%kms}IfU>pH&YN}yOq4>>f;x?L_ zJ3WP;+YHf9+_ke}v^2SSFa5D&lK&R^m!6``E{+Y4jf3N6o7TxJCMBgy8GwL;^UkP> ziiSoSoj^(|FSOe~G!&mx6B{R%1`&;hMzzmCTuSOE5ld*O9M1oJE%4)PBus(ixTV9nErY_#X9WI??spyb(QNX2A{e5q!cn= zvf}l-HykZ3ro$4GhK?QS$pq88v-z^b@ZJ@V;0UEx+lG$+h#^B4>rn1HnV@D=a$Wn> zYT<>8sXNOnLO3EhL0$#?F5!9?-iFF`VjC|N>{1TSl+v~Kv9&*O0hXdzODE({_gFoj z{lM$E)qN5U;-{i4OL1}t>=?bl-OTdD%XXoGVX*a%{d=L$zM|ttyE6(>j`3Pk%j>5C zG5XfFjh<}?HX0LMm6?%e{3^+!Y<;Dj3f;7yNu*@W&*VnXG;7z8MTm9B-KREm$s0ZIVBKuEMX4lc5&)7_i@To?Kssf6XD8lrQe6j`$ORKTZJI^Ne3f zfU(Sduc`Ld{P%IeHU=8{X=4Q>_7`DQy@Y+~h3Y%Kh*babtX6Z-3n8}fTS}g|4o;u+ zXhOBk{+73S>;0?@2F?eq1j#ph4T-glIAXss(Q@C1X6hnmW7n2}sogW`6S%Ml79PgW zUYIXR$)h1*{yAcKn4Hz55I9VaIh=D;mLL z4E4Gy`@0XDo&tGvNUjywaN}KZV>dgVT*%8R6h>wnb+4a!$d#ELTE!>gz}A^kf(v> z-bQlGEfCEDwWiOVVOvmScJtWPP&*N*&9HFz4LJZv>ZKONGpXH}1vV}u#e2$j2bOWT z1M8!+TIkhnGT%i|B)!|FEPs>A_5p32FfFJyK`?Os`v9u3{t`oaJKHkVK@Gsy73~__{|{}N~L1>8`ZBz z*d>s@YuR-DF$aDTwI+oT1sq7SZ8s;=XUu4Tq^&Pc>Ep3pSQ{|`|r<*fRQQlf+ z;qUH{6He$^K^tbiDQTP_l(8&8xtGx%{=RX>9NRN_(Gl~_x>n^uHSbLQd=d1bEvOip znn-(8CS+OuXlFQ6rfGQ9gB#MpZJj|crKtVxS8A%x5~EHheTTDSK6d`McfYh7B`-~H zpV@RonSZfFypfswRne-o&}>u?(_-5ZQf zfs6}o_6ZDE`|c$`Pjb{F2MYwF%6NLr6%Dr=VdKiEzw0l9;@pE?T95ut|1qxN>UX=x z_ZcPi4fU*B{T~fyb`>`2SM)=7ASFRPNdw5AXBv5xf)X z_;RuU$$Y|QNezsH(&Eq`Uhzy4bBT-;`&n| zo4s=Bhq~K`*n+}qqI8gaCYRyS6!T)PlWLVr`vKV31Dqb@6$zF2xpk#MhY%&{$t2`& zsSH6GP9Xb)(x9y2>#X`yjpyEmJ`2P652{1LIV!;B?uBuPS$LKsIexzu3d3qDixfXn zI0WRQ6yX+6zQl%XtpxC_2%*Y+&xZieZwSza-iT4LjN|5QVfQy|_zm~+s>@-yjdRi2 zk9v4*R;@0Nza?Lx^Gi07xl6+6303V@4->E~rXJj^3~xy(fDmpuCvjrZe6iU;`Mhhl zBjV_y@TGzv_kDcO;Czd9NJAuHY>yh)GGpYgu^I&<{4Ieo8|AycAh6D8{=J zVqWC_ULE#OML*N7CfjpT34O#BbC{aT<~Cf~UW@3)N96>3xy|!-p+LDW9ew_wY6@jI z`Oe%8l7F%Hb^$a{T-%W1N351^vtNvjM~ReP(x}W0-$!R4;JjHi;wfxqQE~3e}pw z|D2d4-m(Jrs+2GwP@yM+L19RAQz&S2#rez%d)kbFcD7lueNN6(2(uu7!JwuS@pS3r z@?`$O(Yp^A_JTV@)ILoL4v?suV$ySSZwOnmVQPk>PYo$*wr zJ&}zC(;jS{@mBgncKMbx83k#fGm{`L=Q(RtA04fE(Ux{eC|{orXKq7?XVM@RZ_^iK z64Ye2#;(VZe8r+wtOzi{NkgE35aQi2VUcXyeDqSPWyxpC_|Po$n9^M;_#CnV2Y^3J z{07G%gJ?)>h7+$IX_Re>6GCu_-y}pEDbiPyP8eoP&=z)5dO*vgj^d#mQ9%KWd@e3& z`Pxpq<|8g{QKt^-i9m*@fsJm*56NO52k4CqT*hZ)s$V871|9}$(n&SBZJ$qcAjf$; z%b*=vDrM*9k`&A!s;9r87LagfD_Us_lSCF-hf4Ynto%-bL8inBNepQ4uDWm*bp7QU zYIt!9j~V+diV%1U^l1xT(*0Dm{)23lRf~m^rCs;*ptq~Z1U+em0XExStKr~M)nHlh zVh0J{a6iFf_5%z~_iCM_5{=Bu)O~$J6rn|6^Q>f0wgCV+Xf$)C)y!+97pt2FSzOXL zH&sgv;%)4l`g13lq<;ArYz}(WB8e31Y;E11z~MAxLo}rjzrL&vMFH3rkhN5PH~6DD zxYGI~6H)qvfQA@bqR_f)^>okp{sLX-0?eV1-ijPPV}!Gim~Hn=;tN=;)o3L7cy6?$ zs=k~QIEZV6Bj|=6H)m1jc?avAVur}K8SSOn5ygB|6PlnBN(JT9`VNzSm zSH#72k*HL3Lh_1orJXngel2mA4q5!^P`dDJG@*a!k6jUah3`9BvcoifOCS~}`!IvMWFeBwqD&PBM` zX$Pj6lHcz=1Fr)zO_6!SZElN`Y79_w{YA-e&#&T zKO>2Wg6GG)ezdYb{(g{uIyum4;}b-)3??x69C5k7)a@nW0QZu~KYa}L;$K+9eY)7U zGVtW0&s+@Ud2Da*%^nyE6ASvY-4Hme38O%UQV+)Ex+cn%5o<>v%Jv@_?*u^BizpJ2 zJ%8A`qSue^lSc*Cap3#7!m{#4Fs>ntrBFqp=BQZu?ONJ`l@dOBtEdRaM3`!SHC9z* zyQ$x~b@i9X9zd}ZP>yOwG0XGe)yRID;iLPZyVsXSvSQ;S-Mv9XtQwU%b8^yO*X3G5 zmXjKF*AIvXyB(*N&~|OdA|rWPv{pWDt;B{`TT2r;PmXq_G8KxP8Mgb~_QMuht}K(* zWp^JuV&@$4txxk*MpfU;aBfK}?`2WqlEsAfSN7!^E$Xxt-_jctVe`5nDv&zl#6Q|k zB;ZZGnKOEr<*c~;nfYXbyK8{v=*|llx-F(2sW@=;NxSL*Zbv)S>rq_D_(;kE$VIct zF55qBe}t(p*oTyNib!K;Pjf?f95B4HZr^**srq~}pgU1{eFCLp^S=;FS7SrdQ1F3s zIjhY_k?#8!4ScI~Co_a%cv>9}Odk1UEwCvarx@7?Dk6iJvJzVGKfl@pZu}erV?0(} zJ|pKT?uQotvBy8==rU!uoHA5{iAgkRpWl`Qdo5A|B^Ww`M0W#oU0-nVKLr$EK`3tv zwUjF4QN-O%LI+-Pp8=MJOKAV1oir~;39~J02&|a;f940paa|X=dhq-VnGnx?55T|} z%<~rf+ythx4v}#wM;BArC6yDYCqw&s6u3dE-I-u)seu@Uo&{50=W0L}#{e=Kw@gzx zk8~tGmFlX~Ov*>Xj1Fqq6vp?l3WjRq`unZ2U2&Ex+-UGoUt3|)@1~NDdaRL)bA_dk zRC^c-oyyInUPc-eUT7FNmAB6x=l2bh;k{Gp?C*Abx z*}!9;hY;e0AMvRR@caMdns8h()ny z3p!6ZR4BdqgNaNywY7yC^UP{zLlCASLhHUP?&UgrF`C5VRm_!v1XpUOH)CJRz{iUj znxfl81Xi(1gherD5c0dZ7P7X~RIJN4Z)UgRs`nd7vGr1da=Dd8DL%k;eshKW#vUPy z1Ix+j!Qjo^J>D@Th(BD4wK0g)NcCE;-sUy{E2i_3-iT$mc@`xwsZMR@O@ZrD-e+0- z$*>8&D42e;dQA6jMyh_BzTO6SYwhDm;2V06a3{=lrm%$8^n0IG0sS1<-pk!!e0t_t z_5ehr5H_wprR`iyg&$4yv~toi-k-%-@UWq_UrQuw>>Z?fcg^1>)co6()UzXb-t6?2zp<}ph7@wXP6 z3)+^qn&>-4$iyg4F6j8e;~2E)l&~nhuHYs?Xl&uN*+|TL)lkZWuGu?0&6@w3(n{hb zpIDA!6g;pJ`^vrZxzTL36SX;#mebgZWfl$=P?tSig>`RZ(-%vzVPrw z4PT%jp&-S0f(Qsl32_1TEcv4)cL3{0Z#{}U463p*3x9_84#ARZ2&d7mzHeMvA7kwD zL*c!5pqU+>4gItqe(TKAzqHq%c1V;h6X8ta{WUcz`NOLfl9N+gw<0vm;X3&@`r%Y- zu#xIi0m0@zSmbVQcIXW)e@F841Wd7cddT+nvD9cmAiwHopgH7soy;vg5Jt|S?a9GZ zt-mL<)-JI>KZ0D#jeSAQ^h(G#7q8{?cFAa(~+!0#x)9!=d~fhdjSqQl8k= zAzJ=rpyFTgfkJV|SwuY&QIAQMsm<&^S$`Jvn|dGwS)_(YY%l zG-gob`s67uf{qI3^63kkH$?)?eX;W`Z_ha89{7<-fEt0_njfZin;~=DqXwIthl2Ua zSH!GMlZ^?jh5ggH(Ja2zvrY$Q;xjvy`^OGr>%aj#%xBz;7=Oa~gdSiLZ)O+h?K@Yg z=^IoVd%Ss~Gs8}mK+LOL7M%O&b*#VKWZWXhIzkU2YoL>JT`{GZVNxVj1T@Cs9GKI<(TRJd~RJ@2L4CD#Ha=P__Nepebr| zYiUp|l&tTDkM}H&uu3F;&=^_*Z>ztXxy-u5g)8jQvzF8kR7Gg4xE z+K!<_5*iFC|pRT;v?q@)GCYFxgef5uq(H(KjUupyS=cZcCjz3 zI;5Nz^45bAN3Hvh)E`^5ikz)a?{TR=UFKEQPH3DpRgJv$T}+}$ceSkHcu0`+7f#nN zC9r20O=wK?nsFixcdC5j%tl6=XYIUFAvJq_cb+NDH%$@k?R zUfN$A{)DmI?esmY);>$zJf-=jqNjswBDA+u;9Z^kiwn7BOQ!z|;=ib(n#Jrx4ema} zm{c6kLG(@$W-@BA%r(lN}GzRB-~iRuc;WSY_4KAGie zw&VD?f}C1$KhJLs8sG$+<#4h4h~je=4F-j8X6>e0%ntT#Fu<9NlpsFX402HNui?2~y8FI+y#+@qge>;(`NRrPm2P{}0hA5;#Xl8?HXQVr`_ z4~{-6x>mHo;-L*c89RLAq~n(3YA{rszvE6u)mtaf^BzW=$h|*siGDCin+f%Nx4-{x z#S;-VSG&LbeBY|yULjKJO%@sy%4bg~8uRC{9-d3r@`THYNn;SiDc;ej$ z6@u}Z?4gykC8^59f5*Hw*#k1)g`AWUYdY47zIz^Y3w`rF77A^1*KEAFYlId=~C;y&EJn&eY zeYod#Ua~QK_eGqGfG1sS1H!&e7@g5|>TF6YZvW-|Rq>qbN*#PH!LEdE6%nT%$m?N= z>uFl|f>VC#;)g4gl*jndG7!>!cLZ2O;rCqik@CLAPjmCGpQg~RbR4&N!JeqYL=yJB z&*p8mpgAPdeeodhlbl5^Y6QTkt2Eyet~&->lsIs|Q#0-gNe+(fh3N{tAZH~?+IL^; zv+oe!?OjDf4(p#GMXh3#Lefof&^?jqd&0OIk9KsWrzH$#{`d(kNDJ+~egOEUR9!FX z1`3N~2!c1Ul(Tn&adujL`SHkTV;=nIvNzF^msw!VI>Zp-IHn&mI#ry=Y!6bE!LmFX z7@j>gR(LC_EuK|f%Jhbq4Pu2Z4zykOyYB$cl&CsL8>H7$J3tsN`o+n-#~U~;HbK_g zV3d3?)}x;Cp8Hh?sY~K#(gjT`FGNp-8;0y#(rOv_l#bNYwOEk`k8C0 za;*{dvMgJ_V*B+iTHsgep{(o~@n5FcTV=N5Uwf0L}5_#m2h zPUx#Ts88QBo{U>zV#Ck(rup!J%Ykmuqy`Jg-2<)^_4+enb$2s92xk+mdsx$lt2rKY zqGxs^&I|{V0{XQ$!o>v$nniZh&!DeBMsrp*!meXS@&%=#-Hfx~+}kz^^-zH)$SAvV z$QOt*%s{+9l++aEnbHkYS_=`-{o4uH!knVCq7ZpXr0e#V3Z&1sv!($-jx845nIH(p z-l#^1IcsCm;^tMv<*%d+uZLVGuV5zj&b8^T}M`t;r)?UuR_xS#V}F_>mz zq3yhg`uvugZ6PCm5zF*J-VOb%!^@lDPBC7EOH_5J+|k|X)|2`pty{Z&J$C*-@*QoR z4K3I0_irWQk82a=ZeCq%JEVqIfb4I7jYZ?vSovhJlyNb3)xyAw0;~eK3=Vxbn{}n1~pZd zesZ&1Yq^T;eVm3yt!=c;AUC)W_Df<9Vu-+7(~@}swp#aclSe^T{pH5I$B?a?&r3er z4a$jyBBeU4Zpz-@qMTe#L=SG9SG_C1Yxj4hdXPJ}uN^0n6OY-1kBuhZ<}7K+A1B=& zT@TqCxBP7$4Luqr*IITHq-De*UJ*m+EHjC{juX&SHS1ydD=85%%;Mtox(Q3oL9<)Q-!BXL)fkU`orrHA7l$cxx{-eFQ8H zL0QyHG-S3Ms16Y8VYE5SS6M5J*M4NQ=Ug3+!9Sl;wr&PyK^|ZWC#1Eyb3nBmzz>;M z2QLz2iO)+7ZDMqy8JOu637x4{Lcz2Tj%}?~PLR-R=03xNFA4)XN%xl^Ac!xQ$9ZwxA2<%aoL7~FRv!T9 zvRqb0C>};Ho7Q{17gmoie=Bu%uT(&td^~W|lm|P+l)^fl7!;N?>`d$cll<9(L?s$H zN@bNn`&z$M3dIgx-CD_SC4F5aazF%|wsS^O>(~l-Tvb2h1ahNEs`gj4$i!)CYz_;u zJ-sr9Z`HKtk?;?A80}q!F%M<#mIXxwzoNB&KwrdUN2IYLvdx=7mvV0$mz=YkqM7yb zlOZRdV+~pTt3$VXlbz?m+jdpYA12b4rrG1?Dnfkd7PCLI%D7>A2L#Kx@h!kzyV0c6 zdlose)K{N_qAD$W+aOsUz1ed;yqeO_+1yY=tj`C;p01DH^lt!*QScpAbGJUUp7 zBr6@iRo`<2<;UpypOId__bljsD&94tv99!;n?*2T9Mp#2sj!78%xkf_IS8g&$%cR% zI{N3?zFJSCUZVBVjI&F8ERXeRfRmGt)$Plqh~?KG$D7w?C6^93>O_y#!>$2V%8#zH zZm;KxkeQ$?D{OtvvKgwi8CeobLvY(kz%NQlk|thsE#QY5UOJbqu7l!E>+d>e;vo%{ z&raj!jO;15+YPI7XqdH;ZWH-^weXJsYP}b*RD@!P2!pJ>vPyt=BoeGOc)U!dT7!B{k9G8kxM%)X;E4`pLZOM&g@I(k>jUQSF6yqIbQl_%uS#HzcMb&16L2z<4T>Rs)U31>*Fdm3)I9(au!qytvh|8T@(TM zI_8=3z4`N9(n~#He-YHljd~X5)gc5Mu0&vuzEj`!^mLX5wc4rA%9wE;Ua4;5Rm^+jM>L%%X!xe|` z(w&Yx;jxr`t5x6+IU64S2QY;_~C#*W?FV&Cc?&ko3WtoqUK5a5Qy`qO~u_CVg^*tPpc4wRMra5NO5@5izS_ zzn|CvRU0UmTcWt!SL+s>_PLiA+w0tH|(`-SUY%+&hdXjn%9tb8xlX3Zg1C1 zT6Qel=1EGwptx~6z%ReNO7OIHpSD?3#6do+6zl;~&uGJy2ffZ8C z?sgq`1?^9`#fw%~T11;hQ;yU+9GacVoW|WwL_`~wo$V)j+q7!1+!jK1>?=KnNKfAF zH5x@ZndxmGIe)cT1MRp!$=~YEFCSezR#_=Ihjg5KMzm5eqk{W;tLO2Yo(pq?wyB)c z80M3f8zKd^3Hf#{Fw;{bkO9HJgQf&n^mU?M);Wj2Rnt-0oDtFefGKCqiLj!8@Ubu_ z>;e;q(SUC&M0=}QmiMG?G*?rNn|b!?le5H_I~iqTiKAu$zJ#dc)zkNzpDvGoLC}O5 z+>utOzo}G>GPk+R7}Z&kVPT2c&Q%$SX0`qbZW(u?&)YGPv>ff#aYB|R-qIF@04ad% z7s0KQ_s7!z98_XuVu8q<`B0Bw}3_^p2Kvw65WX)OKOMPa|`H zfHJy0GyBrV2_)I_sY{p5fS=-G`ymdj@!@N2$c{%@XL8h^ZM7vOh}m+PzW#bL5dvV^ z#DT_x?bNGtWd2X$h0|vfcyw8`*c-?EWPyeZ2VReg!f5`26}#4PVB1i%uoT8K$e2T! zJir)fPHve4u^!36wv3b55PHc6XFI{U(RclY;PkcC9Zi>6(94yVt`SYOBnL}`m=yGl zYdY4?Aac?hiXNcVi7-eK&$)YNSTtzeMRaY*B5Eyjfz2t#e$nxf;?Di(8a;!O#ea}W zyp=4Zlz_Hpho#GTU{g_x56jKoYZwS|KD({*G-n!5`#v5Z47zu+dp6f&pjTyLk2k*8 zVZ8$Ey4GGnUHUGWzae!WcT*5(9?b7j`?yn2Jy<7b4_;1<)>0UUNP8a*oy*PGbXPO2 z4^^GZ$xul!07j!peP`@cCantHzZHkTGi^U5mev|aImz=9xiO zw+9K3DrmK_B!OP6w(2ytwrEic;1kPs{EJ|Zv3pib+Y^T}!Pb0EV*=xZLWn4Q5l;az86XR0eW-DDi4I5m$5+3YB;U~mZ<_)qsO6Om z*j^2c~I1sP(!H@^ZuKQQy;GMQJ0dd~$)v)Wpf zw&(|2EGd^2d>$IuN}=&QeWv)Jf!Gy846 z5=hrN`09V%jE_&a%X?2+uo&0fe285&{;)a>nK{L zE(D~<2OIvewwh|#L1foOG0wBsH<{2qXK&eFN@^vDGLEudiQ8$h%o1c?!p}g+oJaDO z=8*UJQ@ch^qJAjG@R;9N!lPz`3b5`^%f6#HeH_!^!wtYmu;_zj}@O?4tTjfHNQ5e12>MC4zndo6Kb=FdGShNnPlN+CPo?aT( zZXA363xS%5e#HaHJm+|uGv^=pZ|QA+!Ib*BOXHlt6Ixj;BUca&I6o>u2f64L#6~<`s5paelAKz) z8kT1_itI9BXNqhOufztOh;C^r(UsIND%3trB;A#pX^4Yr&c#y7E6QhpP%RXZQK{MN z9r&ZUTd_AIN7hj&CEX}e0tYK5k1*`_vF5oQv1W{KL~3pVM)Ccx%0PCcd{(p&`_0oz z$&_-vfb!#(?7^EjwW=X6CFe&N>Km_q^9+hYe=DcCb)zuL*H4c<9qj1Nt5K31n_x9Q z)9Mr2gmTMk*yW(AOws3}rX8Upm9=|h5$#M4s4#6r54 zLcfW1I?kKp(`e4SuSv_;WmYzj2-;@w2UFE1ZPwGAF``vJL&pLT$L=>r{?m zT8NXC67~+{{EK|r*tLXU!;qS>v`l=aR~!U46*^<~g@|*!m=_Ua5POa-y`daeY$nO6 z3LPW|8-#kEQVeP#sphpIyz#EYxc%4@LY-GuPnp_L7Jxu7>$M1foK1B;ro{vQ8wrLZ z(|HNe^lqUDs9U&$&lKxFHbw>MQVnh&uvI{rr{UqA+EV{`m!|;V49{;zo`|Ft^Nt+8 z5rVUgZ>9Ckwj{6q)o?kyEv_ATEZyH0lKsV{6X>?NW<*|2DXNX6Fe+70AGMUD z7t9&eO|AwXd^+M~7Ct9=KM8?nNR^`1^NFr@ z(Xn+36bcniN_`hnNlXf9^HTCCvw&Bn6V!GcLoS-g48{RO6#mI3@%wYr*vt7Ko_#V( zzwS?wU?z#pes49^tHr)+*>9R&QZ*+@))ewIyYN%_XU_#@=S&k^rK(&yS&Eh1 zFKt#~RL$>6AMV4W3o9c;1Uvc`lG<4YcS6aAIkurj*Ud=QiwKwK z^QouC0-k;WaZFt6NBY`rf>WzQHDAfr-kj^*v9+bW>8%;Vw7MMD*$<6l z2|>Dd_$I-l8IkalhDE>9eSIWb$`y^#K0c~L-V@s z1JNY2hVb-(aAJ6DTIxhZ`*qu=#lDr}KSrm>-irm*XwhP0roT8N%P6Dv^|#G%&>-(t z`cZEIc^os90P1i{RTAtx&tTYP?y+JYe~zgSF|JM^;=nEssuTI$@TzPWQ#Uupc!JLu zS2b&?1}_9ELHxk#F25T**vcD8NXN>zTXCrCg?+q;N%~4Jh_EoSa^o~(Z8JoXwfUj= zv2k8l=6D^1MgXu1*e(7<;hc!}{c-un)UA4#0dG<>;aCTGk!sul#q0+vy0MiQ$|%Et zQI-3AoI9-`Lo7IP!eBs%g+ZVV@3=M`ejjt3{K>~9&|=_55!^|Z0Wd41`yx{;6c3}L zdVUyL^Mo>z3f^#Goh$vr2N;4k!SV&#Y!+HsKe$guCG(>p7sYyUfc=HuitcG)yKFcr z%)=7DL$I5`EAY)Zx2*i>cTI4!PNHZmVPbR63!5FV#$>Wt5;)2K3aFBUi z^rRs$zQZKM0-spP{Mluaqgn}SRLF-a_dF(r70V=fLEmlRm>R$K7+GeuIt@esIz&PP zvWm$Hl!DhPB_tR14nFTC2QKN)vMoQ=O|lxzxWkbR0ms~Dp*9oL2Z*- zua0g@;ykc$mX|SRX_Q1{Hl4*NfyN{6Yp)TTpW#3ZO#a!5iZBhQxa_s%qaR~EJ9~bg z86v-94%iV73Ruy?Bmq-UK+TJV@A?=S3oa>5Iw&Z+Y|J0$qxgV8QwB+y9Ws+RRv`@n zxcU=U1}=@)G>a$drsd_)3~LF}7N^9Q?-{f4c!3+YaD^R-=skXLFrVNgj*c+~_mP)62yG1=3g|-%6nWS+dq%4FBd5Ag=#0yqh5)tLQdu<*!)VxjT~3w?2}$PLVYW4-a1@N?eW?Q0m^T` z^$`{DfZCDMmjN%+A1bb}1sU^B;C}bwqvHHgY;r2dX(0gYJ77=`oXMmd{&_<<)^VZ$qYnRW8m!` zt^OMUd>_)E$X#=%9g@=hb~-IrtcYtalrr$IfceT-q}L8t9Dl01Q2{pnjtFH8#3FSj zp(|T5>(=8Bp5N30d^^0Tkzw7h59in*2QL+yciQjd#zlS#su8T`A1@LKtm96QJ(E`G zUAwHbup^=!p2Lg#{<%ZwcsyYm=!@?6g@HRdUE$q+an_!UB;~c;8o+=@Li+9V`U3F1 zlcg|k+_}a78qFeW(ST!osl2f=n{zWiI3T*)`SBW%9-K=tX;i)bbbpEbxPe6u8&o@* z#J-jF=FOeKss8!=iU1k&qu|T)sSg~WLbo-THUulDr3P2u%ZY^Y=$ZK@$=lcFumchB z1kr!(SrZlVPfR56d^jlNv%kY;AwY{F6M>g>;sIngHxoa8y4|>(6zLTenHKz2Tv68d z`lO5@vheuz>DVU!heeBTK>-?cZfx!#nJYyV6+PFGdBKj_rwSa8Ro&89In~Q)C3OHT;J_9;oMAu z3mab=5&J6(sF=z`A3~&?Ju3u_tFkFh59dmMn45R6xU6k;jJd3BWW8aqy*_jy;(4I% z>yMVM)NA}JGBCGpNV5DIdC%qV?|)YH0TTwMacfZ28(=)p zM@vN|=B#T5ncN)2iV&07boEFH4t8JubBif-HPyTC;i3Ojy9sa6`GCq<{W}{IO>!lL z`$vmyj+bD;CxHO&RzL*mpbD00Ne4xk{&O=fMm?pWgVh_5Xf=NS^)y%KU<=U2XmypA z??Qv61XN(~++hO)h;047k&{=?CwhfwKq-zb$>)~qP*cuiAfZlN`lEj?;xB2?xN$)Kz91a&B{_CyJ zYsl+E<;GuCHNC#%An$_-*SrSFaC2jm8=2sKpL8PK!beNV>~aH~w<08~l0)6tl?I2_ zbBL~wxQ75|QQgSdB!WI)BL>XY2D0>A(P>Yy2F_#&4czg42sWC&-1@NYgB#gT+AftIEgRP;d_}w- z)(>6EUA{abF8hJ4@g}?7uPwmM3mGoU8yBgL&5gGQ0bpxLB-s6y078lF3%2QOSA?`& z!_)G?bfsM05%@mUuQwJg*24KLG?LEgXN6Rk$rOyKJW*9$vp;G8g#tdpoh{_b@!13o z%zXJF#iQp|B&uiU%0Mi<(IHUDQZ(55DZj_p5AO5h+*fPvwiTx&)cFeCUY9uEi>%kW zb*QIPDLy$YE5QvmI=ae&4YDx;E;iP@oxq=vP(S>$EtcWRaln&y^A)dWkNqDeiv`7Kx2qmft%E z(_zq$>ql?G$=cOf@uKQw1YI-u*^rh30A8m}cugi!-3@DxRadch2f3erctVnr+nsq! zI<2L~{jM2BP}cpjHd7Y1G#^`C&g{0n0KVG2++pIAC1Gi;U_f`4`(|fTMTA8UW}hN$ zLAdp|`ogyEj%JkqJT|O09XEh&=XG5+49f|i=GP7NB3qh^pRW$*(6B7)n;>j@-yBN> zWsFvDd<@pKhnu$Uw8m0Dpv1=|=4M+{K@E=Rz7MQ<_JfB&6hAm5OZ4ZNJh2F?w}}Rd z$iuU;-F0;M*%_Rn+&6Rlz19<=u%s7H_(`ObK_f*X2?+{`!$gwhOSoGs8Apcpz?+8w zoX<#tE+^^s)Q8yrd`+z=?)@1*n6J!Q1C2BP-|m^m_J0S0ekma6?{@+Iwb}m8f%5+- kjQd~MkN=-RkE>Uh@55WRfE^iaXompu(n?Yl5(fVN1N^#h5C8xG literal 0 HcmV?d00001 diff --git a/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md index 700d7a21a2..43749ca596 100644 --- a/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/respond-machine-alerts-windows-defender-advanced-threat-protection.md @@ -23,10 +23,19 @@ ms.topic: article - [Windows Defender Advanced Threat Protection (Windows Defender ATP)](https://go.microsoft.com/fwlink/p/?linkid=2069559) ->Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-respondmachine-abovefoldlink) +>Want to experience Windows Defender ATP? [Sign up for a free trial.](https://www.microsoft.com/en-us/WindowsForBusiness/windows-atp?ocid=docs-wdatp-respondmachine-abovefoldlink) Quickly respond to detected attacks by isolating machines or collecting an investigation package. After taking action on machines, you can check activity details on the Action center. +Response actions run along the top of a specific machine page, which you can find from any of the following views: + +- **Security operations dashboard** - Select a machine name from the Machines at risk card. +- **Alerts queue** - Select the machine name beside the machine icon from the alerts queue. +- **Machines list** - Select the heading of the machine name from the machines list. +- **Search box** - Select Machine from the drop-down menu and enter the machine name. + +![Image of response actions](images/response-actions.png) + >[!IMPORTANT] > - These response actions are only available for machines on Windows 10, version 1703 or later. > - For non-Windows platforms, response capabilities (such as Machine isolation) are dependent on the third-party capabilities. @@ -35,7 +44,21 @@ Quickly respond to detected attacks by isolating machines or collecting an inves As part of the investigation or response process, you can collect an investigation package from a machine. By collecting the investigation package, you can identify the current state of the machine and further understand the tools and techniques used by the attacker. -You can download the package (Zip file) and investigate the events that occurred on a machine. +To download the package (Zip file) and investigate the events that occurred on a machine + +1. Select **Collect investigation package** from the row of response actions at the top of the machine page. +2. Specify in the text box why you want to perform this action. Select **Confirm**. +3. The zip file will download + +Alternate way: + +1. Select **Action center** from the response actions section of the machine page. + + ![Image of action center button](images/action-center-package-collection.png) + +3. In the Action center fly-out, select **Package collection package available** to download the zip file. + + ![Image of download package button](images/collect-package.png) The package contains the following folders: @@ -56,23 +79,6 @@ The package contains the following folders: |WdSupportLogs| Provides the MpCmdRunLog.txt and MPSupportFiles.cab | | CollectionSummaryReport.xls| This file is a summary of the investigation package collection, it contains the list of data points, the command used to extract the data, the execution status, and the error code in case of failure. You can use this report to track if the package includes all the expected data and identify if there were any errors. | -### Step by step - -1. Select the machine that you want to investigate. You can select or search for a machine from any of the following views: - - - **Security operations dashboard** - Select the machine name from the Top machines with active alerts section. - - **Alerts queue** - Select the machine name beside the machine icon from the alerts queue. - - **Machines list** - Select the heading of the machine name from the machines list. - - **Search box** - Select Machine from the drop-down menu and enter the machine name. - -2. Select **Action center** from the response actions section of the machine page. - - ![Image of action center button](images/action-center-package-collection.png) - -3. In the Action center fly-out, select **Package collection package available** to download the zip file. - - ![Image of download package button](images/collect-package.png) - ## Run Windows Defender Antivirus scan on machines As part of the investigation or response process, you can remotely initiate an antivirus scan to help identify and remediate malware that might be present on a compromised machine.