mirror of
https://github.com/MicrosoftDocs/windows-itpro-docs.git
synced 2025-05-14 22:37:22 +00:00
Merge branch 'master' into repo_sync_working_branch
This commit is contained in:
commit
f3beb64355
@ -32,6 +32,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
|
@ -32,6 +32,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
|
@ -32,6 +32,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
|
@ -35,6 +35,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
|
@ -36,6 +36,7 @@
|
|||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
"feedback_system": "GitHub",
|
"feedback_system": "GitHub",
|
||||||
|
@ -33,6 +33,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
|
@ -33,6 +33,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
"manager": "dansimp",
|
"manager": "dansimp",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
|
@ -2,7 +2,7 @@
|
|||||||
title: Manage indicators
|
title: Manage indicators
|
||||||
ms.reviewer:
|
ms.reviewer:
|
||||||
description: Manage indicators for a file hash, IP address, URLs, or domains that define the detection, prevention, and exclusion of entities.
|
description: Manage indicators for a file hash, IP address, URLs, or domains that define the detection, prevention, and exclusion of entities.
|
||||||
keywords: import, indicator, list, ioc, csv, manage, allowed, blocked, whitelist, blacklist, block, clean, malicious, file hash, ip address, urls, domain
|
keywords: import, indicator, list, ioc, csv, manage, allowed, blocked, block, clean, malicious, file hash, ip address, urls, domain
|
||||||
search.product: eADQiWindows 10XVcnh
|
search.product: eADQiWindows 10XVcnh
|
||||||
search.appverid: met150
|
search.appverid: met150
|
||||||
ms.prod: w10
|
ms.prod: w10
|
||||||
@ -65,8 +65,13 @@ expirationTime | DateTimeOffset | The expiration time of the indicator in the fo
|
|||||||
severity | Enum | The severity of the indicator. Possible values are: "Informational", "Low", "Medium" and "High". **Optional**
|
severity | Enum | The severity of the indicator. Possible values are: "Informational", "Low", "Medium" and "High". **Optional**
|
||||||
recommendedActions | String | TI indicator alert recommended actions. **Optional**
|
recommendedActions | String | TI indicator alert recommended actions. **Optional**
|
||||||
rbacGroupNames | String | Comma-separated list of RBAC group names the indicator would be applied to. **Optional**
|
rbacGroupNames | String | Comma-separated list of RBAC group names the indicator would be applied to. **Optional**
|
||||||
|
category | String | Category of the alert. Examples include: Execution and credential access. **Optional**
|
||||||
|
mitretechniques| String | MITRE techniques code/id (comma separated). For more information, see [Enterprise tactics](https://attack.mitre.org/tactics/enterprise/). **Optional** It is recommended to add a value in category when a MITRE technique.
|
||||||
|
|
||||||
## Related topics
|
For more information, see [Microsoft Defender ATP alert categories are now aligned with MITRE ATT&CK!](https://techcommunity.microsoft.com/t5/microsoft-defender-for-endpoint/microsoft-defender-atp-alert-categories-are-now-aligned-with/ba-p/732748).
|
||||||
|
|
||||||
|
|
||||||
|
## See also
|
||||||
- [Create indicators](manage-indicators.md)
|
- [Create indicators](manage-indicators.md)
|
||||||
- [Create indicators for files](indicator-file.md)
|
- [Create indicators for files](indicator-file.md)
|
||||||
- [Create indicators for IPs and URLs/domains](indicator-ip-domain.md)
|
- [Create indicators for IPs and URLs/domains](indicator-ip-domain.md)
|
||||||
|
@ -32,6 +32,7 @@
|
|||||||
"externalReference": [],
|
"externalReference": [],
|
||||||
"globalMetadata": {
|
"globalMetadata": {
|
||||||
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
"breadcrumb_path": "/windows/windows-10/breadcrumb/toc.json",
|
||||||
|
"uhfHeaderId": "MSDocsHeader-M365-IT",
|
||||||
"ms.technology": "windows",
|
"ms.technology": "windows",
|
||||||
"ms.topic": "article",
|
"ms.topic": "article",
|
||||||
"audience": "ITPro",
|
"audience": "ITPro",
|
||||||
|
Loading…
x
Reference in New Issue
Block a user