mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-28 05:07:23 +00:00
add mitre techniques
This commit is contained in:
parent
056585768a
commit
d50829cb32
@ -87,6 +87,7 @@ The table below lists the current categories and how they generally map to previ
|
||||
| Suspicious activity | General, None, NotApplicable, EnterprisePolicy, SuspiciousNetworkTraffic | Atypicaly activity that could be malware activity or part of an attack |
|
||||
| Unwanted software | UnwantedSoftware | Low-reputation apps and apps that impact productivity and the user experience; detected as potentially unwanted applications (PUAs) |
|
||||
|
||||
|
||||
### Status
|
||||
You can choose to limit the list of alerts based on their status.
|
||||
|
||||
@ -115,6 +116,11 @@ If you have specific machine groups that you're interested in checking the alert
|
||||
### Associated threat
|
||||
Use this filter to focus on alerts that are related to high profile threats. You can see the full list of high-profile threats in [Threat analytics](threat-analytics.md).
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
|
||||
## Related topics
|
||||
- [Manage Microsoft Defender Advanced Threat Protection alerts](manage-alerts.md)
|
||||
- [Investigate Microsoft Defender Advanced Threat Protection alerts](investigate-alerts.md)
|
||||
|
@ -32,7 +32,11 @@ Investigate alerts that are affecting your network, understand what they mean, a
|
||||
|
||||
Click an alert to see the alert details view and the various tiles that provide information about the alert.
|
||||
|
||||
You can also manage an alert and see alert metadata along with other information that can help you make better decisions on how to approach them. You'll also see a status of the automated investigation on the upper right corner. Clicking on the link will take you to the Automated investigations view. For more information, see [Automated investigations](automated-investigations.md).
|
||||
From the alert details view, you can manage an alert and see alert data such as severity, category, technique, along with other information that can help you make better decisions on how to approach them.
|
||||
|
||||
The techniques reflected in the card are based on [MITRE enterprise techniques](https://attack.mitre.org/techniques/enterprise/).
|
||||
|
||||
You'll also see a status of the automated investigation on the upper right corner. Clicking on the link will take you to the Automated investigations view. For more information, see [Automated investigations](automated-investigations.md).
|
||||
|
||||

|
||||
|
||||
|
Loading…
x
Reference in New Issue
Block a user