mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-20 12:53:38 +00:00
Added image and updated text
This commit is contained in:
Binary file not shown.
After Width: | Height: | Size: 81 KiB |
Binary file not shown.
After Width: | Height: | Size: 70 KiB |
@ -52,14 +52,23 @@ Note the detection status for your alert.
|
||||
- Blocked – Suspicious behavior was executed and then blocked. For example, a process was executed but because it subsequently exhibited suspicious behaviors, the process was terminated.
|
||||
- Detected – An attack was detected and is possibly still active.
|
||||
|
||||
|
||||
|
||||

|
||||
|
||||
Blocked or prevented means actions were already taken by Defender for Endpoint.
|
||||
|
||||
Start by reviewing the *automated investigation details* in your alert's details pane, to see which actions were already taken, as well as reading the alert's description for recommended actions.
|
||||
You can then also review the *automated investigation details* in your alert's details pane, to see which actions were already taken, as well as reading the alert's description for recommended actions.
|
||||
|
||||

|
||||
|
||||
Other information available in the details pane when the alert opens includes MITRE techniques, source, and additional contextual details.
|
||||
|
||||
For alerts from Mac and Linux devices, remediation actions can be seen within the alert story as well as in the details pane.
|
||||
|
||||

|
||||
|
||||
|
||||
## Review affected assets
|
||||
|
||||
Selecting a device or a user card in the affected assets sections will switch to the details of the device or user in the details pane.
|
||||
|
Reference in New Issue
Block a user