Files
windows-itpro-docs/windows/security/threat-protection/microsoft-defender-atp/overview-custom-detections.md
2019-09-13 15:08:53 -07:00

1.9 KiB

title, ms.reviewer, description, keywords, search.product, search.appverid, ms.prod, ms.mktglfcycl, ms.sitesec, ms.pagetype, ms.author, author, ms.localizationpriority, manager, audience, ms.collection, ms.topic
title ms.reviewer description keywords search.product search.appverid ms.prod ms.mktglfcycl ms.sitesec ms.pagetype ms.author author ms.localizationpriority manager audience ms.collection ms.topic
Overview of custom detections in Microsoft Defender ATP Understand how you can leverage advanced hunting to create custom detections and generate alerts custom detections, alerts, detection rules, advanced hunting, hunt, query, response actions, intervals, mdatp, microsoft defender atp eADQiWindows 10XVcnh met150 w10 deploy library security lomayor lomayor medium dansimp ITPro M365-security-compliance conceptual

Custom detections overview

Applies to:

With custom detections, you can proactively monitor for various events and system states, including suspected breach activity and misconfigured machines. You can create rules that automatically trigger alerts. You can also configure these rules such that specific response actions are automatically performed in response to a detection.

Custom detections leverage Advanced hunting, which provides a powerful, flexible query language that covers a broad set of event and system information from your network. The queries run regularly based on your preferred intervals, generating alerts and taking response actions whenever there are matches.

Custom detections provide:

  • Alerts from rule-based detections that leverage Advanced hunting queries
  • Configurable query intervals from 1 hour to 24 hours
  • Automatic response actions that apply to files and machines

Note

To create and manage custom detections, your role needs to have the manage security settings permission.