Loading...

New Incident Graph view in Microsoft 365 Defender

New Incident Graph view in Microsoft 365 Defender

The new incident graph helps you quickly understand and visualize the full timeline and related entities of an attack by connecting the different suspicious entities with their related assets such as users, devices, mailboxes and applications. The graph presents a holistic view of how an attack spread through an environment over time, where it started and how far the attacker went. 

 

 

Animation1.gif

 Play the attack over time

 

Now you will be able to:

  • See how the incident’s alerts are connected
    With one glance you can see the connection of alerts to the impacted assets in your organization. 
  • Pivot to alerts directly from the graph
    You can view the alerts right from the graph page and quickly drill down to view more details. 
  • Open the entity details directly from the graph
    You can view the entities details without losing orientation directly from the graph and act on them with response options like file delete, device isolation, etc.
  • Highlight the entities related to an alert
    Easily see which entities are related to which alerts and how they are part of the story of the attack. 

To easily investigate the incident and to help get you oriented, you can select specific alerts for which you want to highlight relevant entities.

 

Idan_Pelleg_0-1630571753395.png

 Highlight specific nodes on the graph based on the alert

 

You can drill down to each alert directly from the graph as well as open the entity side pane.

This will allow you to review the entity details and take remediation actions, such as deleting a file or isolating a device.

 

Idan_Pelleg_1-1630571863612.png

 

So now you can review, investigate and remediate attacks while seeing the full story of the attack right away and understand how the entites are connected to each other.

The incident graph in Microsoft 365 Defender is available from the new Graph tab of an incident .

 

See also

 

 

 

Published on:

Learn more
Microsoft 365 Defender Blog articles
Microsoft 365 Defender Blog articles

Microsoft 365 Defender Blog articles

Share post:

Related posts

Monthly news - November 2024

Microsoft Defender XDRMonthly newsNovember 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and v...

1 year ago

Monthly news - August 2024

Microsoft Defender XDRMonthly newsAugust 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and var...

1 year ago

Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

New Security Copilot skill: Identity Summary

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Demystify potential data leaks with Insider Risk Management insights in Defender XDR

In today's complex security landscape, understanding and mitigating data exfiltration risks is more critical than ever. Earlier this year, we ...

1 year ago

Monthly news - October 2024

Microsoft Defender XDRMonthly newsOctober 2024 Edition This is our monthly "What's new" blog post, summarizing product updates and va...

1 year ago

AI-Driven Guided Response for SOCs with Microsoft Copilot for Security

In today's evolving cybersecurity landscape, security operation centers (SOCs) are constantly bombarded with incidents ranging from minor aler...

1 year ago

Identity Summary: New Security Copilot skill within Defender XDR

“Can you summarize Defender insights about this user over the last two days?” Microsoft’s latest innovation for Copilot for Security, sim...

1 year ago

Detecting browser anomalies to disrupt attacks early

Detecting browser anomalies is crucial for early identification and prevention of cyber threats, preventing data breaches and attacks by monit...

1 year ago

Microsoft Defender for Identity: the critical role of identities in automatic attack disruption

In today's digital landscape, cyber-threats are becoming increasingly sophisticated and frequent. Advanced attacks are often multi-workload an...

1 year ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.