mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-20 21:03:42 +00:00
Updated investigate-incidents-windows-defender-advanced-threat-protection.md
This commit is contained in:
@ -33,6 +33,15 @@ You can investigate the alerts and see how they were linked together in the inci
|
|||||||

|

|
||||||

|

|
||||||
|
|
||||||
|
Alerts are grouped into incidents for the following reasons:
|
||||||
|
Automated investigation -
|
||||||
|
File characteristics -
|
||||||
|
Manual association -
|
||||||
|
Proximate time -
|
||||||
|
Same file -
|
||||||
|
|
||||||
|
|
||||||
|
|
||||||
You can also manage an alert and see alert metadata along with other information. For more information, see [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md).
|
You can also manage an alert and see alert metadata along with other information. For more information, see [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md).
|
||||||
|
|
||||||
### Machines
|
### Machines
|
||||||
|
Reference in New Issue
Block a user