diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machine_page_flyout.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machine_page_flyout.png new file mode 100644 index 0000000000..7d83e1545d Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machine_page_flyout.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machines_discoveredvuln.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machines_discoveredvuln.png new file mode 100644 index 0000000000..08e0e2f831 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machines_discoveredvuln.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machineslist.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machineslist.png new file mode 100644 index 0000000000..ea9e800b94 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machineslist.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machinetoinvestigate.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machinetoinvestigate.png new file mode 100644 index 0000000000..864dff2f13 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_machinetoinvestigate.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy.png index 2e93ccc77b..4b1c91c9e4 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_software.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_software.png new file mode 100644 index 0000000000..6589185f64 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_software.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwarecolon.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwarecolon.png new file mode 100644 index 0000000000..eb0c4314c7 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwarecolon.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareflyout.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareflyout.png new file mode 100644 index 0000000000..0b72121e67 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareflyout.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareoptions.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareoptions.png new file mode 100644 index 0000000000..8f61d18462 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_softwareoptions.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vuln.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vuln.png new file mode 100644 index 0000000000..08c0a00cc9 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vuln.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnflyout.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnflyout.png new file mode 100644 index 0000000000..cae0239957 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnflyout.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnoptions.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnoptions.png new file mode 100644 index 0000000000..cf9f274980 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracy_vulnoptions.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyflyout.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyflyout.png index 8b99ca489e..9af2ad6945 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyflyout.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyflyout.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyoptions.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyoptions.png index 66abe22f08..09c4876e1d 100644 Binary files a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyoptions.png and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_report_inaccuracyoptions.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/images/tvm_weaknesses_machinepage.png b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_weaknesses_machinepage.png new file mode 100644 index 0000000000..5c56b70612 Binary files /dev/null and b/windows/security/threat-protection/microsoft-defender-atp/images/tvm_weaknesses_machinepage.png differ diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md index 957ab3bcf7..4326359b13 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-security-recommendation.md @@ -56,23 +56,26 @@ From that page, you can do any of the following depending on what you need to do ## Report inaccuracy -You can report a false positive when you see any vague, inaccurate, incomplete, or already remediated information in the machine page, under **Security recommendation** column. +You can report a false positive when you see any vague, inaccurate, incomplete, or already remediated security recommendation information in the machine page. -1. Click **:** then select **Report inaccuracy**. A flyout pane opens. +1. Select the **Security recommendation** tab. + +2. Click **:** beside the security recommendation that you want to report about, then select **Report inaccuracy**. ![Screenshot of Report inaccuracy control from the machine page under the Security recommendation column](images/tvm_report_inaccuracy.png) +
A flyout pane opens.
![Screenshot of Report inaccuracy flyout pane](images/tvm_report_inaccuracyflyout.png) -2. From the flyout pane, select the inaccuracy category from the drop-down menu. -![Screenshot of Report inaccuracy categories drop-down menu](images/tvm_report_inaccuracyoptions.png) +3. From the flyout pane, select the inaccuracy category from the drop-down menu. +
![Screenshot of Report inaccuracy categories drop-down menu](images/tvm_report_inaccuracyoptions.png)
-3. Include your email address so Microsoft can send you feedback regarding the inaccuracy you reported. +4. Include your email address so Microsoft can send you feedback regarding the inaccuracy you reported. -4. Include your machine name for investigation context. +5. Include your machine name for investigation context. >[!NOTE] > You can also provide details regarding the inaccuracy you reported in the **Tell us more (optional)** field to give the threat and vulnerability management investigators context. -5. Click **Submit**. Your feedback is immediately sent to the Threat & Vulnerability Management experts with its context. +6. Click **Submit**. Your feedback is immediately sent to the Threat & Vulnerability Management experts with its context. diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md index 6954b3f5d6..a3004a88db 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-software-inventory.md @@ -33,6 +33,30 @@ In the field of discovery, we are leveraging the same set of signals in Microsof Since it is real-time, in a matter of minutes, you will see vulnerability information as they get discovered. The engine automatically grabs information from multiple security feeds. In fact, you'll will see if a particular application is connected to a live campaign. It also provides a link to a Threat Analytics report soon as it's available. +## Report inaccuracy + +You can report a false positive when you see any vague, inaccurate version, incomplete, or already remediated software inventory information in the machine page. + +1. Select the **Software inventory** tab. + +2. Click **:** beside the software that you want to report about, and then select **Report inaccuracy**. +![Screenshot of Report inaccuracy control from the machine page under the Software inventory column](images/tvm_report_inaccuracy_software.png) +
A flyout pane opens.
+![Screenshot of Report inaccuracy flyout pane](images/tvm_report_inaccuracy_softwareflyout.png) + +3. From the flyout pane, select the inaccuracy category from the **Software inventory inaccuracy reason** drop-down menu. +
![Screenshot of Report inaccuracy software inventory inaccuracy reason drop-down menu](images/tvm_report_inaccuracy_softwareoptions.png)
+ +4. Include your email address so Microsoft can send you feedback regarding the inaccuracy you reported. + +5. Include your machine name for investigation context. + +>[!NOTE] +> You can also provide details regarding the inaccuracy you reported in the **Tell us more (optional)** field to give the threat and vulnerability management investigators context. + +6. Click **Submit**. Your feedback is immediately sent to the Threat & Vulnerability Management experts with its context. + + ## Related topics - [Risk-based Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md) - [Threat & Vulnerability Management dashboard overview](tvm-dashboard-insights.md) diff --git a/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses.md b/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses.md index 108aef13b2..4bbbfb545d 100644 --- a/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses.md +++ b/windows/security/threat-protection/microsoft-defender-atp/tvm-weaknesses.md @@ -26,7 +26,7 @@ Threat & Vulnerability Management leverages the same signals in Microsoft Defend The **Weaknesses** page lists down the vulnerabilities found in the infected software running in your organization, their severity, Common Vulnerability Scoring System (CVSS) rating, its prevalence in your organization, corresponding breach, and threat insights. ## Navigate through your organization's weaknesses page -You can see the list of vulnerabilities in three ways: +You can see the list of vulnerabilities in four ways: *Vulnerabilities in global search* 1. Click the global search drop-down menu. @@ -48,6 +48,18 @@ You can see the list of vulnerabilities in three ways: 3. Select the **Discovered vulnerabilities** tab. 4. Select the vulnerability that you want to investigate to open up a flyout panel with the vulnerability details, such as: CVE description, CVE ID, exploits available, CVSS V3 rating, severity, publish, and update dates. +*Discovered vulnerabilities in the machine page* +1. Go to the left-hand navigation menu bar, then select the machine icon. The **Machines list** page opens. +
![Screenshot of Machines list page](images/tvm_machineslist.png)
+2. In the **Machines list** page, select the machine that you want to investigate. +
![Screenshot of machine list with selected machine to investigate](images/tvm_machinetoinvestigate.png)
+
A flyout pane opens with machine details and response action options.
+![Screenshot of the flyout pane with machine details and response options](images/tvm_machine_page_flyout.png) +3. In the flyout pane, select **Open machine page**. A page opens with details and response options for the machine you want to investigate. +
![Screenshot of the machine page with details and response options](images/tvm_machines_discoveredvuln.png)
+4. Select **Discovered vulnerabilities**. +5. Select the vulnerability that you want to investigate to open up a flyout panel with the vulnerability details, such as: CVE description, CVE ID, exploits available, CVSS V3 rating, severity, publish, and update dates. + ## How it works When new vulnerabilities are released, you would want know how many of your assets are exposed. You can see the list of vulnerabilities and the details in the **Weaknesses** page. @@ -66,6 +78,29 @@ The threat insights icons are highlighted if there are associated exploits in th >[!NOTE] > Always prioritize recommendations that are associated with ongoing threats. These recommendations are marked with the threat insight ![threat insight](images/tvm_bug_icon.png) icon and possible active alert ![possible active alert](images/tvm_alert_icon.png) icon. +## Report inaccuracy + +You can report a false positive when you see any vague, inaccurate, missing, or already remediated vulnerability information in the machine page. + +1. Select the **Discovered vulnerabilities** tab. + +2. Click **:** beside the vulnerability that you want to report about, and then select **Report inaccuracy**. +![Screenshot of Report inaccuracy control from the machine page in the Discovered vulnerabilities tab](images/tvm_report_inaccuracy_vuln.png) +
A flyout pane opens.
+![Screenshot of Report inaccuracy flyout pane](images/tvm_report_inaccuracy_vulnflyout.png) + +3. From the flyout pane, select the inaccuracy category from the **Discovered vulnerability inaccuracy reason** drop-down menu. +
![Screenshot of discovered vulnerability inaccuracy reason drop-down menu](images/tvm_report_inaccuracy_vulnoptions.png)
+ +4. Include your email address so Microsoft can send you feedback regarding the inaccuracy you reported. + +5. Include your machine name for investigation context. + +>[!NOTE] +> You can also provide details regarding the inaccuracy you reported in the **Tell us more (optional)** field to give the threat and vulnerability management investigators context. + +6. Click **Submit**. Your feedback is immediately sent to the Threat & Vulnerability Management experts with its context. + ## Related topics - [Risk-based Threat & Vulnerability Management](next-gen-threat-and-vuln-mgt.md)