mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-06-16 10:53:43 +00:00
Merge branch 'master' into v-gmoor-fixes-pr-4822
This commit is contained in:
Binary file not shown.
After Width: | Height: | Size: 69 KiB |
Binary file not shown.
After Width: | Height: | Size: 39 KiB |
Binary file not shown.
After Width: | Height: | Size: 69 KiB |
Binary file not shown.
After Width: | Height: | Size: 151 KiB |
@ -52,18 +52,18 @@ Select the specific *Attack technique* to open the related ATT&CK technique page
|
||||
|
||||
You can copy an entity's details when you see a blue icon on the right. For instance, to copy a related file's SHA1, select the blue page icon.
|
||||
|
||||

|
||||

|
||||
|
||||
You can do the same for command lines.
|
||||
|
||||

|
||||

|
||||
|
||||
|
||||
## Investigate related events
|
||||
|
||||
To use [advanced hunting](advanced-hunting-overview.md) to find events related to the selected Technique, select **Hunt for related events**. This leads to the advanced hunting page with a query to find events related to the Technique.
|
||||
|
||||

|
||||

|
||||
|
||||
>[!NOTE]
|
||||
>Querying using the **Hunt for related events** button from a Technique side pane displays all the events related to the identified technique but does not include the Technique itself in the query results.
|
||||
@ -78,7 +78,7 @@ You can customize which columns to expose. You can also filter for flagged event
|
||||
### Choose columns to expose
|
||||
You can choose which columns to expose in the timeline by selecting the **Choose columns** button.
|
||||
|
||||

|
||||

|
||||
|
||||
From there you can select which information set to include.
|
||||
|
||||
|
Reference in New Issue
Block a user