From fd5786fae1f9c834fd16c6120e6aa257634a6174 Mon Sep 17 00:00:00 2001 From: Chris Jackson Date: Mon, 11 Nov 2019 22:23:48 -0600 Subject: [PATCH] Updated "threats" to "evidence" to match UI The UI was updated to change the name of the tab from "Threats" to "Evidence" - this update will align the docs again. --- .../microsoft-defender-atp/automated-investigations.md | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md index 00a8b85828..a8e4541750 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md +++ b/windows/security/threat-protection/microsoft-defender-atp/automated-investigations.md @@ -44,13 +44,13 @@ The Automated investigation starts by analyzing the supported entities from the ### Details of an Automated investigation -As the investigation proceeds, you'll be able to view the details of the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Threats**, **Entities**, and **Log** tabs. +As the investigation proceeds, you'll be able to view the details of the investigation. Selecting a triggering alert brings you to the investigation details view where you can pivot from the **Investigation graph**, **Alerts**, **Machines**, **Evidence**, **Entities**, and **Log** tabs. In the **Alerts** tab, you'll see the alert that started the investigation. The **Machines** tab shows where the alert was seen. -The **Threats** tab shows the entities that were found to be malicious during the investigation. +The **Evidence** tab shows the entities that were found to be malicious during the investigation. During an Automated investigation, details about each analyzed entity is categorized in the **Entities** tab. You'll be able to see the determination for each entity type, such as whether it was determined to be malicious, suspicious, or clean.