diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Application-Guard-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Application-Guard-events-icon.png new file mode 100644 index 0000000000..9cf3188628 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Application-Guard-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Device-Guard-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Device-Guard-events-icon.png new file mode 100644 index 0000000000..d59adf2674 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Device-Guard-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-ETW--event-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-ETW--event-icon.png new file mode 100644 index 0000000000..4f4b6bb921 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-ETW--event-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Exploit-Guard-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Exploit-Guard-events-icon.png new file mode 100644 index 0000000000..7e8dbce304 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Exploit-Guard-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-File-location-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-File-location-icon.png new file mode 100644 index 0000000000..40838935be Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-File-location-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Firewall-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Firewall-events-icon.png new file mode 100644 index 0000000000..c38cf8c7fe Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Firewall-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Other-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Other-events-icon.png new file mode 100644 index 0000000000..ea972f9868 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Other-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-Smart-Screen-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-Smart-Screen-events-icon.png new file mode 100644 index 0000000000..7cb8349b62 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-Smart-Screen-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-access-token-modification-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-access-token-modification-icon.png new file mode 100644 index 0000000000..4155bbfd03 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-access-token-modification-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-cprompt-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-cprompt-icon.png new file mode 100644 index 0000000000..7569e5d4ad Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-cprompt-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-file-creation-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-file-creation-icon.png new file mode 100644 index 0000000000..411303a0c0 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-file-creation-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-file-observed-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-file-observed-icon.png new file mode 100644 index 0000000000..42da4ee738 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-file-observed-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-memory-allocation-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-memory-allocation-icon.png new file mode 100644 index 0000000000..7028eb5a25 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-memory-allocation-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-module-load-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-module-load-icon.png new file mode 100644 index 0000000000..6e071edb03 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-module-load-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-network-communications-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-network-communications-icon.png new file mode 100644 index 0000000000..7af075b0d7 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-network-communications-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-powershell-command-run-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-powershell-command-run-icon.png new file mode 100644 index 0000000000..31840dffea Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-powershell-command-run-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-process-event-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-process-event-icon.png new file mode 100644 index 0000000000..c48ea6e880 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-process-event-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-process-injection.png b/windows/threat-protection/windows-defender-atp/images/atp-process-injection.png new file mode 100644 index 0000000000..f4788b5833 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-process-injection.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-registry-event-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-registry-event-icon.png new file mode 100644 index 0000000000..12f8d99c9b Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-registry-event-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-respond-action-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-respond-action-icon.png new file mode 100644 index 0000000000..0ceed7cfc6 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-respond-action-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-signer-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-signer-icon.png new file mode 100644 index 0000000000..44f431e3f7 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-signer-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-av-events-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-av-events-icon.png new file mode 100644 index 0000000000..5a5e4bb762 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-av-events-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-not-detected-icon.png b/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-not-detected-icon.png new file mode 100644 index 0000000000..bc8c7f0320 Binary files /dev/null and b/windows/threat-protection/windows-defender-atp/images/atp-windows-defender-not-detected-icon.png differ diff --git a/windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md b/windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md index 9e98297388..afcf94174d 100644 --- a/windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md +++ b/windows/threat-protection/windows-defender-atp/portal-overview-windows-defender-advanced-threat-protection.md @@ -69,7 +69,24 @@ Icon | Description ![Remediated icon](images/remediated-icon.png)| Remediated – Threat removed from the machine ![Not remediated icon](images/not-remediated-icon.png)| Not remediated – Threat not removed from the machine. ![Thunderbolt icon](images/atp-thunderbolt-icon.png) | Indicates events that triggered an alert in the **Alert process tree**. - +![Windows Defender AV events icon](images\atp-windows-defender-av-events-icon.png)| Windows Defender AV events +![Application Guard events icon](images\atp-Application-Guard-events-icon.png)| Application Guard events +![Device Guard events icon](images\atp-Device-Guard-events-icon.png)| Device Guard events +![Exploit Guard events icon](images\atp-Exploit-Guard-events-icon.png)| Exploit Guard events +![Smart Screen events icon](images\atp-Smart-Screen-events-icon.png)| Smart Screen events +![Firewall events icon](images\atp-Firewall-events-icon.png)| Firewall events +![Response action icon](images\atp-respond-action-icon.png)| Response action +![Process events icon](images\atp-process-event-icon.png)| Process events +![Network communication events icon](images\atp-network-communications-icon.png)| Network events +![File observed events icon](images\atp-file-observed-icon.png)| File events +![Registry events icon](images\atp-registry-event-icon.png)| Registry events +![Module load DLL events icon](images\atp-module-load-icon.png)| Load DLL events +![Other events icon](images\atp-Other-events-icon.png)| Other events +![Access token modification icon](images\atp-access-token-modification-icon.png)| Access token modification +![File creation icon](images\atp-file-creation-icon.png)| File creation +![Memory allocation icon](images\atp-memory-allocation-icon.png)| Memory allocation +![Process injection icon](images\atp-process-injection.png)| Process injection +![Powershell command run icon](images\atp-powershell-command-run-icon.png)| Powershell command run ## Related topic -[Use the Windows Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) +[Use the Windows Defender Advanced Threat Protection portal](use-windows-defender-advanced-threat-protection.md) \ No newline at end of file