Loading...

The power of incidents in Microsoft 365 Defender

The power of incidents in Microsoft 365 Defender

Incidents in Microsoft 365 Defender are powerful tools allowing SecOps to triage, investigate and response to cyber-attacks in one place.

 

Incidents provide the full attack picture due to advanced signals correlation capabilities. Our algorithms automatically correlate signals from all Microsoft security & compliance solutions, like an experienced analyst would. It gathers related telemetry and other alerts that belong to the same attack. Microsoft 365 Defender also uses AI to continually analyze the vast amount of available data and, if necessary, suggest more evidence for the analyst to add to the incident from a variety of sources such as:

  • Microsoft Defender for Endpoint
  • Microsoft Defender for Identity
  • Microsoft Defender for Office 365
  • Microsoft Defender for Cloud Applications
  • Microsoft Data Loss Prevention
  • Azure AD Identity Protection (limited preview)

Today, unlike before, all the alerts are part of incidents. Alerts from all these products, are correlated into incidents to help expedite the response time of your SecOps team.

 

For an even more effective exploration of the incidents queue, we recently added new features that will further streamline your investigations:

 

  • Use the summary to quickly understand how the queue is being filtered
  • Search incidents by ID, name and impacted assets such as user, device, mailbox, or application name.
  • Specify a custom time range that includes both dates and times

Idan_Pelleg_0-1655383139340.png

New filters in incident queue

 

Once you identify an incident to research, you can investigate an attack across stages - from

 

Some of the powerful incident investigation capabilities include:

  • Understand the progress of an attack against the MITRE attack kill-chain
  • Identify the attack scope and review all involved entities and assets, enriched with all relevant Microsoft 365 Defender data
  • Investigate using a visual graph to
  • Take action and respond to the attack
  • Easily assign the incident to other analysts in the SOC

Idan_Pelleg_1-1655383139353.png

Play the attack over the incident graph

 

Learn how Microsoft 365 Defender can help your organization stop attacks with coordinated defenses. Read these blog posts in the Inside Microsoft 365 Defender series:

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.