mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 10:53:43 +00:00
Merge branch 'master' into v-gmoor-fixes-pr-4822
This commit is contained in:
Binary file not shown.
After Width: | Height: | Size: 69 KiB |
Binary file not shown.
After Width: | Height: | Size: 39 KiB |
Binary file not shown.
After Width: | Height: | Size: 69 KiB |
Binary file not shown.
After Width: | Height: | Size: 151 KiB |
@ -52,18 +52,18 @@ Select the specific *Attack technique* to open the related ATT&CK technique page
|
|||||||
|
|
||||||
You can copy an entity's details when you see a blue icon on the right. For instance, to copy a related file's SHA1, select the blue page icon.
|
You can copy an entity's details when you see a blue icon on the right. For instance, to copy a related file's SHA1, select the blue page icon.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
You can do the same for command lines.
|
You can do the same for command lines.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
|
|
||||||
## Investigate related events
|
## Investigate related events
|
||||||
|
|
||||||
To use [advanced hunting](advanced-hunting-overview.md) to find events related to the selected Technique, select **Hunt for related events**. This leads to the advanced hunting page with a query to find events related to the Technique.
|
To use [advanced hunting](advanced-hunting-overview.md) to find events related to the selected Technique, select **Hunt for related events**. This leads to the advanced hunting page with a query to find events related to the Technique.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
>[!NOTE]
|
>[!NOTE]
|
||||||
>Querying using the **Hunt for related events** button from a Technique side pane displays all the events related to the identified technique but does not include the Technique itself in the query results.
|
>Querying using the **Hunt for related events** button from a Technique side pane displays all the events related to the identified technique but does not include the Technique itself in the query results.
|
||||||
@ -78,7 +78,7 @@ You can customize which columns to expose. You can also filter for flagged event
|
|||||||
### Choose columns to expose
|
### Choose columns to expose
|
||||||
You can choose which columns to expose in the timeline by selecting the **Choose columns** button.
|
You can choose which columns to expose in the timeline by selecting the **Choose columns** button.
|
||||||
|
|
||||||

|

|
||||||
|
|
||||||
From there you can select which information set to include.
|
From there you can select which information set to include.
|
||||||
|
|
||||||
|
Reference in New Issue
Block a user