From 658e15166df1d33f559f9faa13a3b73089b2ec4d Mon Sep 17 00:00:00 2001 From: Dolcita Montemayor Date: Wed, 19 Sep 2018 11:28:49 +0000 Subject: [PATCH] Updated investigate-incidents-windows-defender-advanced-threat-protection.md --- ...ate-incidents-windows-defender-advanced-threat-protection.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md b/windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md index 0697856ae0..e107fcbcae 100644 --- a/windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md +++ b/windows/security/threat-protection/windows-defender-atp/investigate-incidents-windows-defender-advanced-threat-protection.md @@ -30,7 +30,7 @@ Click an incident to see the **Incident pane**. Select **Open incident page** to ### Alerts You can investigate the alerts and see how they were linked together in the incident. Alerts are grouped into incidents based on the following reasons: -- Automated investigation - The automated investigation trigerred the linked alert while investigating the original alert +- Automated investigation - The automated investigation triggered the linked alert while investigating the original alert - File characteristics - The files associated with the alert have similar characteristics - Manual association - A user manually linked the alerts - Proximate time - The alerts were triggered on the same machine within a certain timeframe