diff --git a/windows/keep-secure/TOC.md b/windows/keep-secure/TOC.md index d25365f5f2..27a87376bf 100644 --- a/windows/keep-secure/TOC.md +++ b/windows/keep-secure/TOC.md @@ -738,13 +738,16 @@ #### [Use the Windows Defender ATP portal](use-windows-defender-advanced-threat-protection.md) #### [Alerts queue overview](alerts-queue-windows-defender-advanced-threat-protection.md) #### [Investigate alerts](investigate-alerts-windows-defender-advanced-threat-protection.md) +##### [Alert process tree](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-process-tree) +##### [Incident graph](investigate-alerts-windows-defender-advanced-threat-protection.md#incident-graph) +##### [Alert timeline](investigate-alerts-windows-defender-advanced-threat-protection.md#alert-timeline) #### [Consume alerts and create custom indicators](configure-siem-windows-defender-advanced-threat-protection.md) ##### [Configure an Azure Active Directory application for SIEM integration](configure-aad-windows-defender-advanced-threat-protection.md) ##### [Configure Splunk to consume Windows Defender ATP alerts](configure-splunk-windows-defender-advanced-threat-protection.md) ##### [Configure HP ArcSight to consume Windows Defender ATP alerts](configure-arcsight-windows-defender-advanced-threat-protection.md) -##### [Understand threat indicators](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) -###### [Create custom threat indicators using REST API](custom-ti-api-windows-defender-advanced-threat-protection.md) -##### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) +#### [Understand threat indicators](threat-indicator-concepts-windows-defender-advanced-threat-protection.md) +##### [Create custom threat indicators using REST API](custom-ti-api-windows-defender-advanced-threat-protection.md) +#### [Manage alerts](manage-alerts-windows-defender-advanced-threat-protection.md) #### [Machines view overview](machines-view-overview-windows-defender-advanced-threat-protection.md) #### [Investigate machines](investigate-machines-windows-defender-advanced-threat-protection.md) ##### [Isolate machines from the network](investigate-machines-windows-defender-advanced-threat-protection.md#isolate-machines-from-the-network)