Update automated-investigations.md

This commit is contained in:
Denise Vangel-MSFT
2021-01-27 15:56:18 -08:00
parent 55efa3697e
commit c161a55cad

View File

@ -58,9 +58,11 @@ During and after an automated investigation, you can view details about the inve
|Tab |Description | |Tab |Description |
|:--|:--| |:--|:--|
|**Alerts**| The alert(s) that started the investigation.| |**Alerts**| The alert(s) that started the investigation. |
|**Devices** |The device(s) where the threat was seen.| |**Devices** |The device(s) that are impacted by the threat. |
|**Evidence** |The entities that were found to be malicious during an investigation.| |**Mailboxes** |The mailbox(s) that are impacted by the threat |
|**Users** | The user account(s) that are impacted by the threat |
|**Evidence** |The evidences raised by alerts/investigations, with verdicts (*Malicious*, *Suspicious*, or *No threats found*, along with remediation status. |
|**Entities** |Details about each analyzed entity, including a determination for each entity type (*Malicious*, *Suspicious*, or *No threats found*). | |**Entities** |Details about each analyzed entity, including a determination for each entity type (*Malicious*, *Suspicious*, or *No threats found*). |
|**Log** |The chronological, detailed view of all the investigation actions taken on the alert.| |**Log** |The chronological, detailed view of all the investigation actions taken on the alert.|
|**Pending actions** |If there are any actions awaiting approval as a result of the investigation, the **Pending actions** tab is displayed. On the **Pending actions** tab, you can approve or reject each action. | |**Pending actions** |If there are any actions awaiting approval as a result of the investigation, the **Pending actions** tab is displayed. On the **Pending actions** tab, you can approve or reject each action. |